As we know, google has been effective at automating a lot of their systems, to the point where it can feel like there isn't any help available from a human. So what is supposed to be the plan when this type of…

124 points•keymasta•13 days ago•131 comments•
As we know, google has been effective at automating a lot of their systems, to the point where it can feel like there isn't any help available from a human. So what is supposed to be the plan when this type of situation happens?

Basically I have a situation that after my phone was stolen, I can't get into any of my accounts that are either connected to google, or connected to the phone via 2FA. This has made it complicated/impossible not only to get info about my phone, but also my banking, email, drive, etc.

Of course they offer you "multiple options" to recover an account, but not if you forgot your old email's password. At that point the options you get are,

  a) Use old phone (obviously the phone is long gone)
  b) Use current phone (the phone is gone)
  c) Use old email (I haven't used it in like 12 years)
Does anyone know if their is a process to appeal 2FA or anything to deal with this type of situation?

I'd imagine that this has happened to people many many times, and given how phones and particularly, google auth have become so critical to accomplishing essential tasks within society, there must be some way. Or maybe it's just like, once your phone is gone, you are completely over with society? If anyone has any experience with this or inside knowledge please share it!

I'm sure people here have heard of this, and maybe experienced it themselves.

Is there a secret option that exists that allows us to use passwords instead of rigamarole? I would love an account that let me simply log in with a password, like google used to be.

131 comments

ticulatedspline13 days ago
Isn't there an SMS option? buy a new phone and have them send you an OTP via SMS.

> once you're phone is gone, you are completely over with society?

yes, I'm waiting for the Black-Mirror episode where someone drops their phone and basically dies, can't contact anyone, can't unlock or start their car, can't get an uber, can't pay for anything, can't navigate without gps, can't log into anything etc.

ryanhecht13 days ago
Something I learned the hard way: it's a bad time if you are a Google Fi customer and your Android phone with an eSim becomes inoperable while traveling :)
dogmatism13 days ago
just in general, it's difficult if your phone with an esim dies/lost/stolen (ie no access) to move the esim over. It's especially annoying if it just died, because instead of just popping the sim over you end up in a maze with the carrier (unless you are lucky enough to other lines on the account you have access to)
washadjeffmad13 days ago
Went through the same last month. I had to both buy a new phone and still have my old one repaired to be able to authenticate to set up the new one.

I was a CyanogenMod user before switching to Pixel, and that experience was a monumental shove towards moving to Graphene.

keymasta13 days ago
Pretty similar to how my life feels right now.
ticulatedspline13 days ago
As an old curmudgeon I recoil at any service I can't interact with sans-phone. I hardly use mine for anything.

Just be glad your phone number is tied to your account, if you lose the number itself you are royally screwed, and basically anyone who gets your old number owns all your accounts now.

foobarchu13 days ago
My wife recently had this happen to a work acquaintance. They are a recent immigrant who has only lived in New York since moving here, who was sent out to the Midwest where there is no public transportation and driving is mandatory, and is staying at a hotel. She lost her phone, and thus could not get anywhere or communicate with anyone, and couldn't pay for anything due to her phone being where all her money is stored (no physical credit cards or anything). Luckily, my wife was able to get her around and help her out until they eventually discovered it was in a lost and found. If she had been alone, I don't know what she would have done.

Imagine being on vacation and you lose your phone, or it breaks. You offloaded your payments to digital and have no cards or cash, you can't get in your hotel room because you used a digital key like hotels all want you to, maybe you brought a car but oops it's a Tesla and you're depending on your phone as the key because it's less stuff to carry!

hexapus13 days ago
I recently switched to a Minimal Phone with an e-ink screen, and it sucks (which is the point, obviously). One of the things that sucks is NFC. The payment terminals constantly have a hard time grabbing it, and when they do, they often throw a bizaare "multiple cards detected" error, which is extra strange, since I only have one card stored.

I have a separate sleeve wallet, which I can attach to the back of the phone magnetically that contains my physical debit card + drivers license. If I lost the phone, there's probably about a 50/50 chance that I'd still have the wallet sleeve in my pocket, so I'd at least have my ID and a way to pay for things...but if I lost them both, I'd be pretty screwed.

Convenience is nice, but switching to a shitty phone made me realise I can live without a lot of convenient things, and it's safer not to keep all your eggs in one black rectangle.

pid0x1713 days ago
We need to better educate non-technical users about making multiple local backups of things like password managers, TOTP seeds, etc.

Yes, even writing the most important ones on a piece of paper and keeping it somewhere safe (like a safe in your house) is an option, as long as you have a low threat model, of course.

sampullman13 days ago
If you don't have the authenticator backup codes and you didn't turn on cloud sync in the app, you might be out of luck.

You can get a replacement SIM though and use it with a new phone, so the phone number recovery option should work.

dz0ny13 days ago
Happened to me, I was able to get SMS and recovery codes, but Google still required additional verification on now lost phone :D. On the end I acutely found the phone and was able to restore access. So what they do after couple of days of failed attempts the require additional verification, lets call it 3 step.
cute_boi13 days ago
I have passkeys, authenticator etc... and everything except phone number, and now i am unable to login my account in other device.

Google sucks, they are randomly denying access because their dumb model can't figure out not everyone is trying to steal account.

kaycey202212 days ago
This feels objectively worse than writing down a password somewhere
uberman13 days ago
This. Can't you get your number moved to a new phone? I have never don't anything magic when upgrading my phone other than move contacts.
jwr13 days ago
How would moving your number to a new phone help? We're talking TOTP here, not SMS "auth".
mrj13 days ago
This is why my self-hosted Vaultwarden is my one password that I have to remember and requires no 2fa, which is the only important account that doesn't have 2fa.

If I wake up in a bathtub missing a kidney I can still get to my passwords and 2fa sources stored with it. Some accounts require SMS (annoyingly) so I'd have to buy a phone but the auth and credit card numbers I need to do that are in Vaultwarden, too.

I don't have good solutions now for OP (other than buy a new phone through your carrier and transfer the number). But everyone else do think through your personal DRP. Generate backup codes and put them somewhere safe, too.

bazmattaz13 days ago
Welll yeh until a Hargrove fails on your self hosted server
nyx13 days ago
One of my favorite things about self-hosted Vaultwarden is that you get distributed backups for free. Every client keeps an offline copy of your entire password vault, kept in sync when the client is online.

So for me to lose my vault, not only would my server have to get hit by a bus, but also my phone, my desktop, my HTPC, both laptops...

mrj4 days ago
I "self host" on Hetzner for Hargrove avoidance
SoftTalker13 days ago
You're going to have more success working with the providers of the other accounts and services rather than Google. That means a lot more legwork on your part but banks and other online services all have processes to deal with lost passwords and 2FA devices. In some cases you may have to physically go somewhere with ID and other documents.

Consider it a learning experience.

joshmn13 days ago
I had similar issues: https://news.ycombinator.com/item?id=45451567 (including my personal domain, Dropbox; my Apple account is still MIA...)

We've all been reduced to a passphrase.

When I've lobbed this scenario to the security managers/employees at these companies, they all give me a really great answer:

Q: What happens if a sitting senator gets mugged and they have their printed 2fa codes sitting in their wallet?

A: They have a special number they can call.

bshaughn13 days ago
After they go get a second phone

Read the full thread on Hacker News →

Related stories