Rendered at 18:26:42 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
sampullman 2 hours ago [-]
If you don't have the authenticator backup codes and you didn't turn on cloud sync in the app, you might be out of luck.
You can get a replacement SIM though and use it with a new phone, so the phone number recovery option should work.
dz0ny 33 minutes ago [-]
Happened to me, I was able to get SMS and recovery codes, but Google still required additional verification on now lost phone :D. On the end I acutely found the phone and was able to restore access. So what they do after couple of days of failed attempts the require additional verification, lets call it 3 step.
uberman 2 hours ago [-]
This. Can't you get your number moved to a new phone? I have never don't anything magic when upgrading my phone other than move contacts.
jwr 42 minutes ago [-]
How would moving your number to a new phone help? We're talking TOTP here, not SMS "auth".
ticulatedspline 2 hours ago [-]
Isn't there an SMS option? buy a new phone and have them send you an OTP via SMS.
> once you're phone is gone, you are completely over with society?
yes, I'm waiting for the Black-Mirror episode where someone drops their phone and basically dies, can't contact anyone, can't unlock or start their car, can't get an uber, can't pay for anything, can't navigate without gps, can't log into anything etc.
keymasta 2 hours ago [-]
Pretty similar to how my life feels right now.
ticulatedspline 50 minutes ago [-]
As an old curmudgeon I recoil at any service I can't interact with sans-phone. I hardly use mine for anything.
Just be glad your phone number is tied to your account, if you lose the number itself you are royally screwed, and basically anyone who gets your old number owns all your accounts now.
SoftTalker 2 hours ago [-]
You're going to have more success working with the providers of the other accounts and services rather than Google. That means a lot more legwork on your part but banks and other online services all have processes to deal with lost passwords and 2FA devices. In some cases you may have to physically go somewhere with ID and other documents.
Consider it a learning experience.
mrj 1 hours ago [-]
This is why my self-hosted Vaultwarden is my one password that I have to remember and requires no 2fa, which is the only important account that doesn't have 2fa.
If I wake up in a bathtub missing a kidney I can still get to my passwords and 2fa sources stored with it. Some accounts require SMS (annoyingly) so I'd have to buy a phone but the auth and credit card numbers I need to do that are in Vaultwarden, too.
I don't have good solutions now for OP (other than buy a new phone through your carrier and transfer the number). But everyone else do think through your personal DRP. Generate backup codes and put them somewhere safe, too.
bazmattaz 16 minutes ago [-]
Welll yeh until a Hargrove fails on your self hosted server
j1elo 17 minutes ago [-]
Recovery is similar to leaving a copy of your door keys to a trusted neighbour (a tradition in some places, it comes in handy when someone goes out and realizes they forgot the keys inside...), so in that comparison, having a recovery email unused for 12 years feels like leaving your backup keys to a neighbor that you never saw ever again in more than a decade.
This kind of posts are a valuable trigger for all others who are reading it. To the author: good luck, I hope you sort your situation soon! I'm now headed to check my accounts for what recovery options I left in there.
splitwheel 34 minutes ago [-]
This happened to me on my iPhone 8 many years ago. I reset it to let my son use it, and did not have google authenticator in mind. I had to reset each account with the providers. Now I use a cloud account to sync these. I reset most accounts with an SMS or email one time code -- which led me to remove SMS and email as recovery options from google. And, I put a code on t-mobile to prevent sim transfer.
luka 31 minutes ago [-]
I'll fill out a "help my friend" form internally unless someone beats me to it (I have a 1hr meeting coming up). The gmail address in question is the same one as on your website?
dgunay 17 minutes ago [-]
That's nice of you, but I'd urge anyone with influence at Google to consider 1) many many many more people who use Google services probably don't know or run in the same circles as Googlers who can bail them out of such a scenario, and 2) these people, being much less likely to understand 2FA, are also more likely to accidentally lock themselves out. An separate class of people who know how a system works or have connections to its operators become nose blind to its terrible UX because they have access to workarounds.
senordevnyc 7 minutes ago [-]
All true, but I’m guessing the set of people at Google who can fill out that form is about 1000x larger than the ones who have the ability to influence the underlying product decisions that led to this situation.
beej71 1 hours ago [-]
It's a good reminder to everyone who uses 2FA. Be sure you have multiple ways in for when your phone becomes unusable.
happyopossum 47 minutes ago [-]
All those times you logged in and were prompted to verify your backup email address, and when you set up 2FA and were given recovery codes, and when given the option to sync 2FA codes to another copy of the authenticator app: This Is Why.
I'm sorry you're dealing with this - hopefully everyone else here can take it as a cautionary tale.
wccrawford 2 hours ago [-]
Everything you listed, plus a recovery email option, plus backup codes, plus SMS.
That's already a lot and anything easier would allow people to just take over accounts that they don't have a right to.
jeroenhd 58 minutes ago [-]
You can add a passkey (preferably a physical one) to authenticate. You can also add a software passkey but that kind of defeats the purpose.
Actually keeping your recovery options recent is the trick. Print out your recovery codes or store them somewhere safe. Check regularly (yearly, maybe more often) that there's a way to access your critical accounts.
For Google, you can also grab the cheapest Android phone you can find, sign in, and maybe boot it once a month or so to keep the tokens active.
If you've set up your account to only accept one source of 2FA and you lose thst source of 2FA, you lose your account. Same happens when you set up your account to only accept your password and then lose your password. If you lose your recovery email/2FA backup codes, you lose access, unless you're special enough to convince customer support that you are who you claim you are and not just a bot trying to hack you.
If you've lost your account and haven't set up any recovery mechanisms, you're probably out of luck. Your best bet will be looking for an old browser session with enough trust from Google's side to get access without reconfirming your 2FA trust.
jakub_g 51 minutes ago [-]
Yup, having _two_ active devices which are logged in to Google (and possibly other services that you rely on that opt you in to app-based 2FA) + with backups of 2FA is a must at this point. When I buy a new phone, I make it a "primary", and keep my old phone as "backup".
If you're not into cloud-based password/2FA syncing, Google Authenticator supports local export/import across devices via a QR code. For passwords, I use KeePass Portable / Keepass2Android + syncing between devices from time to time through a USB-C pendrive (The source of truth KP DB is on pendrive, and both phones work off a local on-device cache).
You don't need to have your phone stolen for things to get messed up. If your screen breaks, you can't type in a PIN anymore, can't unblock with a fingerprint, and you effectively can't access anything on the phone. ADB won't connect because screen is off, and you can't unlock / accept a new external connection etc.
cj 38 minutes ago [-]
> buy a new phone, I make it a "primary", and keep my old phone as "backup".
Sadly this is why I never end up trading in my phone. Always feels too risky to not have an overlap period.
stefan_ 4 minutes ago [-]
While we are on this, is there a comprehensive guide on how to "theft-proof" your iPhone? Not in the sense of preventing the theft, but rather the fallout on all our various online service access.
Using the iPhone backup to setup a new phone is a good reminder every time that not half of the stuff comes back correctly..
runjake 2 hours ago [-]
The only secret option I know of is to have a popular social media account and complain online.
Other than that, I copy/pasted your post into Claude and it had some good ideas.
mococa 2 hours ago [-]
There's no way, no human contact. That's why I de-googled myself.
lotsofpulp 2 hours ago [-]
No human contact is a plus for security, as the human is the weakest link that can give up your authentication to someone that isn’t you.
ks2048 1 hours ago [-]
The human factor is walking into your local branch with your face and an ID - something that can’t be done on a large scale by bots.
vel0city 43 minutes ago [-]
This has often been abused with mobile phone carriers to get SIM cards issued for targets by just knowing enough customer details. This then allowed them to intercept SMS 2FA challenges and access even more sensitive accounts.
mococa 2 hours ago [-]
Have you heard about Meta AI doing support?
rationalist 23 minutes ago [-]
Only if you can log in. I am Meta Verified, but I cannot log in to get support.
tempfile 2 hours ago [-]
"I am permanently locked out of my account with no recourse" is also a security issue.
phildougherty 2 hours ago [-]
need to save your recovery keys (text file) before you lost the phone
SAI_Peregrinus 2 hours ago [-]
The same way you recover any other deleted data for which you didn't make a backup: you don't. You eat the loss & make new accounts. Then you remember to make and test backups for the future.
Even if they had customer support, if that customer support had a backdoor to unlock your account it would be regularly used by malicious parties to steal people's accounts & data.
Well that’s why you should have software 2FA and even backing up the tokens so you can generate that one time code even if you lost access to your main authenticator, having your phone as the only 2FA is like having those yubikey hardware used as 2FA without making a redundant one, losing it, you lost access, which is usually known since no one would use yubikey without being tech savvy to start with, now google or other companies are turning phones as an attestation method for the crowd, you might soon in the future become citizen-less because your digital ID can only be proven in the lost phone.
autoexec 2 hours ago [-]
Man, passwords sure are nice aren't they! All you have to do is remember one because your password manager remembers all the rest of your randomly generated passwords for you and as long as you keep a backup of the password database you never have to worry about this bullshit.
pards 2 hours ago [-]
Going forward, consider using an authenticator that securely syncs across multiple devices to remove the single point of failure risk.
I use Proton Authenticator now [0]
Authy used to do this, then they enshittified their app and bricked the desktop version.
Google authenticator supports syncing across multiple devices.
kwanbix 1 hours ago [-]
is that new? I migrated at the time from GA to Authy and from Authy to Ente because it was not supported.
mixmastamyk 2 hours ago [-]
Does your browser have the email password saved?
Apreche 2 hours ago [-]
You were supposed to save your backup codes.
thrownaway561 1 hours ago [-]
Honestly.... This is why I have everything in Bitwarden. All 2FA runs through it so even if my phone got stolen, I could still access everything. I honestly don't understand why more people don't pay the $10 a year and just use Bitwarden.
phainopepla2 1 hours ago [-]
Having your passwords and 2FA with the same provider carries some risk. If someone can access your Bitwarden account they will have full access to all your accounts.
vel0city 41 minutes ago [-]
What's your plan when you lose access to Bitwarden?
What happens when your Bitwarden gets compromised?
tonymet 50 minutes ago [-]
can you recover one of the old contact points (phone or email) for a reset code?
I would send a paper letter to the Google legal contact. It's the only way to get escalated support.
I agree the covenant for account recovery has been broken. Every 6 months, a new artifact is expected to access the account, without adequate preparation for the recovery.
You can get a replacement SIM though and use it with a new phone, so the phone number recovery option should work.
> once you're phone is gone, you are completely over with society?
yes, I'm waiting for the Black-Mirror episode where someone drops their phone and basically dies, can't contact anyone, can't unlock or start their car, can't get an uber, can't pay for anything, can't navigate without gps, can't log into anything etc.
Just be glad your phone number is tied to your account, if you lose the number itself you are royally screwed, and basically anyone who gets your old number owns all your accounts now.
Consider it a learning experience.
If I wake up in a bathtub missing a kidney I can still get to my passwords and 2fa sources stored with it. Some accounts require SMS (annoyingly) so I'd have to buy a phone but the auth and credit card numbers I need to do that are in Vaultwarden, too.
I don't have good solutions now for OP (other than buy a new phone through your carrier and transfer the number). But everyone else do think through your personal DRP. Generate backup codes and put them somewhere safe, too.
This kind of posts are a valuable trigger for all others who are reading it. To the author: good luck, I hope you sort your situation soon! I'm now headed to check my accounts for what recovery options I left in there.
I'm sorry you're dealing with this - hopefully everyone else here can take it as a cautionary tale.
That's already a lot and anything easier would allow people to just take over accounts that they don't have a right to.
Actually keeping your recovery options recent is the trick. Print out your recovery codes or store them somewhere safe. Check regularly (yearly, maybe more often) that there's a way to access your critical accounts.
For Google, you can also grab the cheapest Android phone you can find, sign in, and maybe boot it once a month or so to keep the tokens active.
If you've set up your account to only accept one source of 2FA and you lose thst source of 2FA, you lose your account. Same happens when you set up your account to only accept your password and then lose your password. If you lose your recovery email/2FA backup codes, you lose access, unless you're special enough to convince customer support that you are who you claim you are and not just a bot trying to hack you.
If you've lost your account and haven't set up any recovery mechanisms, you're probably out of luck. Your best bet will be looking for an old browser session with enough trust from Google's side to get access without reconfirming your 2FA trust.
If you're not into cloud-based password/2FA syncing, Google Authenticator supports local export/import across devices via a QR code. For passwords, I use KeePass Portable / Keepass2Android + syncing between devices from time to time through a USB-C pendrive (The source of truth KP DB is on pendrive, and both phones work off a local on-device cache).
You don't need to have your phone stolen for things to get messed up. If your screen breaks, you can't type in a PIN anymore, can't unblock with a fingerprint, and you effectively can't access anything on the phone. ADB won't connect because screen is off, and you can't unlock / accept a new external connection etc.
Sadly this is why I never end up trading in my phone. Always feels too risky to not have an overlap period.
Using the iPhone backup to setup a new phone is a good reminder every time that not half of the stuff comes back correctly..
Other than that, I copy/pasted your post into Claude and it had some good ideas.
Even if they had customer support, if that customer support had a backdoor to unlock your account it would be regularly used by malicious parties to steal people's accounts & data.
I use Proton Authenticator now [0]
Authy used to do this, then they enshittified their app and bricked the desktop version.
[0]: https://proton.me/authenticator
What happens when your Bitwarden gets compromised?
I would send a paper letter to the Google legal contact. It's the only way to get escalated support.
I agree the covenant for account recovery has been broken. Every 6 months, a new artifact is expected to access the account, without adequate preparation for the recovery.