As we know, google has been effective at automating a lot of their systems, to the point where it can feel like there isn't any help available from a human. So what is supposed to be the plan when this type of…
Basically I have a situation that after my phone was stolen, I can't get into any of my accounts that are either connected to google, or connected to the phone via 2FA. This has made it complicated/impossible not only to get info about my phone, but also my banking, email, drive, etc.
Of course they offer you "multiple options" to recover an account, but not if you forgot your old email's password. At that point the options you get are,
a) Use old phone (obviously the phone is long gone)
b) Use current phone (the phone is gone)
c) Use old email (I haven't used it in like 12 years)
Does anyone know if their is a process to appeal 2FA or anything to deal with this type of situation?I'd imagine that this has happened to people many many times, and given how phones and particularly, google auth have become so critical to accomplishing essential tasks within society, there must be some way. Or maybe it's just like, once your phone is gone, you are completely over with society? If anyone has any experience with this or inside knowledge please share it!
I'm sure people here have heard of this, and maybe experienced it themselves.
Is there a secret option that exists that allows us to use passwords instead of rigamarole? I would love an account that let me simply log in with a password, like google used to be.
131 comments
> once you're phone is gone, you are completely over with society?
yes, I'm waiting for the Black-Mirror episode where someone drops their phone and basically dies, can't contact anyone, can't unlock or start their car, can't get an uber, can't pay for anything, can't navigate without gps, can't log into anything etc.
I was a CyanogenMod user before switching to Pixel, and that experience was a monumental shove towards moving to Graphene.
Just be glad your phone number is tied to your account, if you lose the number itself you are royally screwed, and basically anyone who gets your old number owns all your accounts now.
Imagine being on vacation and you lose your phone, or it breaks. You offloaded your payments to digital and have no cards or cash, you can't get in your hotel room because you used a digital key like hotels all want you to, maybe you brought a car but oops it's a Tesla and you're depending on your phone as the key because it's less stuff to carry!
I have a separate sleeve wallet, which I can attach to the back of the phone magnetically that contains my physical debit card + drivers license. If I lost the phone, there's probably about a 50/50 chance that I'd still have the wallet sleeve in my pocket, so I'd at least have my ID and a way to pay for things...but if I lost them both, I'd be pretty screwed.
Convenience is nice, but switching to a shitty phone made me realise I can live without a lot of convenient things, and it's safer not to keep all your eggs in one black rectangle.
Yes, even writing the most important ones on a piece of paper and keeping it somewhere safe (like a safe in your house) is an option, as long as you have a low threat model, of course.
You can get a replacement SIM though and use it with a new phone, so the phone number recovery option should work.
Google sucks, they are randomly denying access because their dumb model can't figure out not everyone is trying to steal account.
If I wake up in a bathtub missing a kidney I can still get to my passwords and 2fa sources stored with it. Some accounts require SMS (annoyingly) so I'd have to buy a phone but the auth and credit card numbers I need to do that are in Vaultwarden, too.
I don't have good solutions now for OP (other than buy a new phone through your carrier and transfer the number). But everyone else do think through your personal DRP. Generate backup codes and put them somewhere safe, too.
So for me to lose my vault, not only would my server have to get hit by a bus, but also my phone, my desktop, my HTPC, both laptops...
Consider it a learning experience.
We've all been reduced to a passphrase.
When I've lobbed this scenario to the security managers/employees at these companies, they all give me a really great answer:
Q: What happens if a sitting senator gets mugged and they have their printed 2fa codes sitting in their wallet?
A: They have a special number they can call.
Read the full thread on Hacker News →
Related stories
- The Verge · 0 points · 5 days ago
- The Verge · 0 points · 3 days ago
- Can John Ternus find Apple’s next big thing?theverge.comThe Verge · 0 points · 10 days ago
- Hacker News · 3 points · 3 days ago
- Lobsters · 86 points · about 1 year ago
- The Verge · 0 points · 12 days ago