Live data from Hacker News

Ask HN: How do you start over with 2FA after losing your phone?

news.ycombinator.com

11–20 of 112 posts

Re: Ask HN: How do you start over with 2FA after losing your phone?

#11
I've never trusted a single device for two factor authentification,

My solution, trust in 1Password and it's encryption, I have access to my 2fa anywhere I need but it a computer, phone, tablette.

Soon it will be passkeys and they'll be safe in the 1Password vault, no worrying about losing the device w/ the keys again.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#14
This is crazy haha. I literally just left my phone in a cab(tuktuk) in Costa Rica a couple weeks ago.

It was in my hand one second and then I got out and it wasn't.

I've had to contact each organization I have 2fa with and get 2fa reset through personal identification measures.

For my company that meant a quick zoom call. For banking that meant driver's license scans and photos of me.

You'll have to work with your 2fa providers.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#15

Use your backup codes that you've downloaded and safe-kept somewhere (you did this right?). If not, I'm afraid you're out of luck. There are two possible outcomes from contacting support for a service, asking to regain control over a 2FA-protected account, both which sucks, but on different levels. 1. You write them, proving who you are, and they tell you to get lost unless you have the 2FA proper codes, or backup co…

This is why phone based 2fa is not secure and not recommended. Sure it is easy, but it isn't secure in important ways

Re: Ask HN: How do you start over with 2FA after losing your phone?

#17
When setting up 2FA, the services typically give a list of recovery codes which you hopefully still have. With those, you can gain access and link other 2FA devices.

If you have the recovery codes and got access again, then you can get a bit more redundancy in your system by also setting up security keys such as a Yubikey. These keys can be added next to your authenticator app(s).

Re: Ask HN: How do you start over with 2FA after losing your phone?

#18
You can back up your 2FA codes to another phone, at least Google Authenticator lets you do this. An old phone is the easiest, most convenient way to do this since it has a camera that you can use to scan the code on your main phone.

If you don't have the backup codes or the one-time codes, you're going to have a problem and you'll need to contact the services to somehow let you in or take off 2FA. Depending on what the service is, it might get very tedious.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#19
post #15

Use your backup codes that you've downloaded and safe-kept somewhere (you did this right?). If not, I'm afraid you're out of luck. There are two possible outcomes from contacting support for a service, asking to regain control over a 2FA-protected account, both which sucks, but on different levels. 1. You write them, proving who you are, and they tell you to get lost unless you have the 2FA proper codes, or backup co…

This is why phone based 2fa is not secure and not recommended. Sure it is easy, but it isn't secure in important ways

What? Where the 2FA codes come from isn't relevant, as long as the device (laptop, phone, desktop, hardware) is protected in some way or another (like password).

Backup codes come from the service which is 2FA protected anyways, not from the 2FA authenticator itself.

Edit: oh, reading your message again, are you referring to SMS-based 2FA? I assumed TOTP 2FA in this submission. If you mean SMS-based 2FA, then yeah I agree, makes your account less secure than not having 2FA at all.

Re: Ask HN: How do you start over with 2FA after losing your phone?

#20
If you have a backup, try to restore it on your new iphone. In the vast Google Authenticator didn’t restore, but I read it may now?

FWIW, this is the reason I use Authy, it works nicely with backup/restore. Beware that Authy has a cloud backup/multi device function that I personally keep off. Another option would be 1password, though I’d personally won’t mix passwords and 2fa codes in the same app.

Assuming the worst case where you can’t recover the codes, and assuming it course you never stored the offline codes, you have to go through the process of recovering 2fa.

This usually requires submitting documents that prove who you are, and waiting 1-2 weeks. So the only recommendation is to begin this process asap.

And while you re-setup 2fa make sure you either keep a backup or use an app that works when you backup+restore your phone, Im sure others will provide more options. Good luck!

Post reply on HN