Ask HN: How to recover Google auth after phone stolen?
Basically I have a situation that after my phone was stolen, I can't get into any of my accounts that are either connected to google, or connected to the phone via 2FA. This has made it complicated/impossible not only to get info about my phone, but also my banking, email, drive, etc.
Of course they offer you "multiple options" to recover an account, but not if you forgot your old email's password. At that point the options you get are,
a) Use old phone (obviously the phone is long gone)
b) Use current phone (the phone is gone)
c) Use old email (I haven't used it in like 12 years)
Does anyone know if their is a process to appeal 2FA or anything to deal with this type of situation?I'd imagine that this has happened to people many many times, and given how phones and particularly, google auth have become so critical to accomplishing essential tasks within society, there must be some way. Or maybe it's just like, once you're phone is gone, you are completely over with society? If anyone has any experience with this or inside knowledge please share it!
I'm sure people here have heard of this, and maybe experienced it themselves.
76 comments
[ 4.1 ms ] story [ 33.5 ms ] threadOther than that, I copy/pasted your post into Claude and it had some good ideas.
You can get a replacement SIM though and use it with a new phone, so the phone number recovery option should work.
Google sucks, they are randomly denying access because their dumb model can't figure out not everyone is trying to steal account.
> once you're phone is gone, you are completely over with society?
yes, I'm waiting for the Black-Mirror episode where someone drops their phone and basically dies, can't contact anyone, can't unlock or start their car, can't get an uber, can't pay for anything, can't navigate without gps, can't log into anything etc.
Just be glad your phone number is tied to your account, if you lose the number itself you are royally screwed, and basically anyone who gets your old number owns all your accounts now.
If your product or service requires a phone, I just don't do business with you. I know I sound like archaic recommending this, but we (as a society) need to push back on your phone being the key to your life.
My phone is no more special than my laptop, however this requires an incredible amount of inconvenience for most people and the social pressure to carry a cellphone. As you can imagine, I do not have many friends these days.
Even if they had customer support, if that customer support had a backdoor to unlock your account it would be regularly used by malicious parties to steal people's accounts & data.
That's already a lot and anything easier would allow people to just take over accounts that they don't have a right to.
Consider it a learning experience.
I use Proton Authenticator now [0]
Authy used to do this, then they enshittified their app and bricked the desktop version.
[0]: https://proton.me/authenticator
Additional benefit: I can generate an OTP for any service protected like this without having to get my phone from wherever it is.
What happens when your Bitwarden gets compromised?
I hope that isn't true, because I sure can't think of a good way to use Bitwarden's TOTP as 2FA for Bitwarden! :)
I have 3 FIDO2 USB Security keys, One I carry with my persons at all times, one that stays with my main machine at all times and an offsite backup that is sitting in a friend's server, if my house burns down, I can either physically collect the key or use USB-IP to authenticate back into bitwarden and enroll a new key. (Actually all 3 are at home right now but that's ok)
My phone is logged into Bitwarden so even then I can recover my passwords and data in case of a serious incident immediately.
Even if both my house and my friend's house burn down at the same time, I can still recover my data from my phone unless my phone is left in the house, all of which to say I still have the recovery phrase written down in a box somewhere in a different country
Also frees me up to experiment a bit more on the Phone side (just got a Pixel 10 with GrapheneOS), although, so far it all just works (with Google Services of course).
If I wake up in a bathtub missing a kidney I can still get to my passwords and 2fa sources stored with it. Some accounts require SMS (annoyingly) so I'd have to buy a phone but the auth and credit card numbers I need to do that are in Vaultwarden, too.
I don't have good solutions now for OP (other than buy a new phone through your carrier and transfer the number). But everyone else do think through your personal DRP. Generate backup codes and put them somewhere safe, too.
Actually keeping your recovery options recent is the trick. Print out your recovery codes or store them somewhere safe. Check regularly (yearly, maybe more often) that there's a way to access your critical accounts.
For Google, you can also grab the cheapest Android phone you can find, sign in, and maybe boot it once a month or so to keep the tokens active.
If you've set up your account to only accept one source of 2FA and you lose thst source of 2FA, you lose your account. Same happens when you set up your account to only accept your password and then lose your password. If you lose your recovery email/2FA backup codes, you lose access, unless you're special enough to convince customer support that you are who you claim you are and not just a bot trying to hack you.
If you've lost your account and haven't set up any recovery mechanisms, you're probably out of luck. Your best bet will be looking for an old browser session with enough trust from Google's side to get access without reconfirming your 2FA trust.
If you're not into cloud-based password/2FA syncing, Google Authenticator supports local export/import across devices via a QR code. For passwords, I use KeePass Portable / Keepass2Android + syncing between devices from time to time through a USB-C pendrive (The source of truth KP DB is on pendrive, and both phones work off a local on-device cache).
You don't need to have your phone stolen for things to get messed up. If your screen breaks, you can't type in a PIN anymore, can't unblock with a fingerprint, and you effectively can't access anything on the phone. ADB won't connect because screen is off, and you can't unlock / accept a new external connection etc.
Sadly this is why I never end up trading in my phone. Always feels too risky to not have an overlap period.
I would send a paper letter to the Google legal contact. It's the only way to get escalated support.
I agree the covenant for account recovery has been broken. Every 6 months, a new artifact is expected to access the account, without adequate preparation for the recovery.
I'm sorry you're dealing with this - hopefully everyone else here can take it as a cautionary tale.
I know the email, password, (wrong) phone number on file, and associated YouTube channel. I am logging in from a different IP address but on the same ASN and approximate geolocation that I always logged in and used the account from.
This kind of posts are a valuable trigger for all others who are reading it. To the author: good luck, I hope you sort your situation soon! I'm now headed to check my accounts for what recovery options I left in there.
Using the iPhone backup to setup a new phone is a good reminder every time that not half of the stuff comes back correctly..