I have 2FA set up on three dozen different and important online accounts, and it's all through the Google Authenticator app on that iPhone.
Is there a recommended way to go about this problem?
Or have I locked myself out of my entire life?
1–10 of 112 posts
I have 2FA set up on three dozen different and important online accounts, and it's all through the Google Authenticator app on that iPhone.
Is there a recommended way to go about this problem?
Or have I locked myself out of my entire life?
There are two possible outcomes from contacting support for a service, asking to regain control over a 2FA-protected account, both which sucks, but on different levels.
1. You write them, proving who you are, and they tell you to get lost unless you have the 2FA proper codes, or backup codes. This sucks because you still didn't get access.
2. You write them, proving who you are, and they give you access to your account, so you can reset 2FA. This sucks because this means the service is not secure and you/others can be "hacked" because customer support can be exploited.
With adequate proof and justification I think you should be able to get back your accounts, that is if your service does allow you to get back your account. One tip is to have multiple phones for 2fa and then just not using the other phone, if you don't use it how can you lose it? (that's what I did since I lost it once).
If not, you can try reaching out to customer service after you get a new SIM card.
For banking and everything else IRL, you can just walk up to the teller with your ID.
Also: Didn't you backup the 2FA codes somewhere else where you can "sync" them in?
I use Bitwarden Authenticator for 2FA (part of Bitwarden Pro) and it syncs my 2FA codes to all devices where I log on to Bitwarden. That way I avoid a single point of failure. Consider that the next time around :)
As a meta-comment on this thread itself... That even people here on HN can enable and make use of 2FA incorrectly is the reason it will never be a viable way to protect accounts for "everyone and their grandmother".
It's too complex, and we need something better.
Without those options, now that you lost the only second factor, you have to reach out and convince the service providers that you're you. Good luck.
You can prevent this for the future by pretend you can read the QR codes and getting the secret string allowing you to set up across multiple devices.
Your best best would be contacting support for individual accounts and hoping you have enough historical information to be approved access.