Ask HN: How to recover Google auth after phone stolen?
Posted by keymasta 2 days ago
As we know, google has been effective at automating a lot of their systems, to the point where it can feel like there isn't any help available from a human. So what is supposed to be the plan when this type of situation happens?
Basically I have a situation that after my phone was stolen, I can't get into any of my accounts that are either connected to google, or connected to the phone via 2FA. This has made it complicated/impossible not only to get info about my phone, but also my banking, email, drive, etc.
Of course they offer you "multiple options" to recover an account, but not if you forgot your old email's password. At that point the options you get are,
a) Use old phone (obviously the phone is long gone)
b) Use current phone (the phone is gone)
c) Use old email (I haven't used it in like 12 years)
Does anyone know if their is a process to appeal 2FA or anything to deal with this type of situation?I'd imagine that this has happened to people many many times, and given how phones and particularly, google auth have become so critical to accomplishing essential tasks within society, there must be some way. Or maybe it's just like, once your phone is gone, you are completely over with society? If anyone has any experience with this or inside knowledge please share it!
I'm sure people here have heard of this, and maybe experienced it themselves.
Is there a secret option that exists that allows us to use passwords instead of rigamarole? I would love an account that let me simply log in with a password, like google used to be.
Comments
Comment by ticulatedspline 2 days ago
> once you're phone is gone, you are completely over with society?
yes, I'm waiting for the Black-Mirror episode where someone drops their phone and basically dies, can't contact anyone, can't unlock or start their car, can't get an uber, can't pay for anything, can't navigate without gps, can't log into anything etc.
Comment by ryanhecht 2 days ago
Comment by dogmatism 2 days ago
Comment by washadjeffmad 2 days ago
I was a CyanogenMod user before switching to Pixel, and that experience was a monumental shove towards moving to Graphene.
Comment by keymasta 2 days ago
Comment by ticulatedspline 2 days ago
Just be glad your phone number is tied to your account, if you lose the number itself you are royally screwed, and basically anyone who gets your old number owns all your accounts now.
Comment by kxrm 2 days ago
If your product or service requires a phone, I just don't do business with you. I know I sound archaic recommending this, but we (as a society) need to push back on your phone being the key to your life.
My phone is no more special than my laptop, however this requires an incredible amount of inconvenience for most people along with the constant social pressure to carry a cellphone. As you can imagine, I do not have many friends these days.
Comment by jurgenburgen 2 days ago
Have you considered having backups instead? Carry a physical credit card, make sure you have a backup phone uncharged at home ready for a swap?
Comment by kxrm 1 day ago
Perhaps, but frankly I have been more on the lookout for people like me. Natural filter for compatibility?
> Have you considered having backups instead? Carry a physical credit card, make sure you have a backup phone uncharged at home ready for a swap?
I mean, I carry a wallet. Most vendors and society still take cash or card. Where the real friction comes in is staying connected to a community. Everyone wants to keep social connections virtual for some odd reason. As a remote worker I definitely get the virtues of remote interaction, but sometimes meeting people in person has benefits. It does not have to be all-or-nothing and it feels like we are moving to an all-or-nothing digital way of life.
Comment by memcg 1 day ago
Comment by foobarchu 2 days ago
Imagine being on vacation and you lose your phone, or it breaks. You offloaded your payments to digital and have no cards or cash, you can't get in your hotel room because you used a digital key like hotels all want you to, maybe you brought a car but oops it's a Tesla and you're depending on your phone as the key because it's less stuff to carry!
Comment by hexapus 2 days ago
I have a separate sleeve wallet, which I can attach to the back of the phone magnetically that contains my physical debit card + drivers license. If I lost the phone, there's probably about a 50/50 chance that I'd still have the wallet sleeve in my pocket, so I'd at least have my ID and a way to pay for things...but if I lost them both, I'd be pretty screwed.
Convenience is nice, but switching to a shitty phone made me realise I can live without a lot of convenient things, and it's safer not to keep all your eggs in one black rectangle.
Comment by pid0x17 2 days ago
Yes, even writing the most important ones on a piece of paper and keeping it somewhere safe (like a safe in your house) is an option, as long as you have a low threat model, of course.
Comment by lyfeninja 2 days ago
Comment by sampullman 2 days ago
You can get a replacement SIM though and use it with a new phone, so the phone number recovery option should work.
Comment by dz0ny 2 days ago
Comment by cute_boi 2 days ago
Google sucks, they are randomly denying access because their dumb model can't figure out not everyone is trying to steal account.
Comment by tornado134 2 days ago
Comment by kaycey2022 1 day ago
Comment by uberman 2 days ago
Comment by jwr 2 days ago
Comment by john_strinlai 2 days ago
Comment by b112 2 days ago
Comment by mrguyorama 2 days ago
That's why they had powerful and effective account takeover protection even 15 years ago. The kind that will prevent the hacker from taking over your account even though they got access to all your factors, because it shouldn't take expertise to know that if you logged in from Oregon twenty minutes ago, you definitely aren't also logging in from Ecuador.
Which of course makes it all the more stupid that your credit card company, all your medical service providers, and Facebook don't meet that absurdly low bar. Facebook will happily hand control to the scammer in Laos who got one of your factors and somehow that gave them access to change your password and recovery email
Comment by Dylan16807 2 days ago
Comment by cwillu 2 days ago
Denial of service is a security issue.
Comment by hedora 2 days ago
One reason to strongly prefer Apple over Google is that (as I understand it) you can still walk into a store with ID and recover your online identity.
Comment by jwr 2 days ago
Is this true? If so, in what countries? (Poland has no Apple stores, for example, for inexplicable reasons Apple has been giving the middle finger to this market)
That would be a huge difference.
Comment by kaycey2022 1 day ago
Comment by john_strinlai 2 days ago
Comment by chinathrow 2 days ago
Comment by jwr 1 day ago
Comment by chinathrow 15 hours ago
Comment by mrj 2 days ago
If I wake up in a bathtub missing a kidney I can still get to my passwords and 2fa sources stored with it. Some accounts require SMS (annoyingly) so I'd have to buy a phone but the auth and credit card numbers I need to do that are in Vaultwarden, too.
I don't have good solutions now for OP (other than buy a new phone through your carrier and transfer the number). But everyone else do think through your personal DRP. Generate backup codes and put them somewhere safe, too.
Comment by bazmattaz 2 days ago
Comment by nyx 2 days ago
So for me to lose my vault, not only would my server have to get hit by a bus, but also my phone, my desktop, my HTPC, both laptops...
Comment by 627467 2 days ago
Edit: this "feature" did save me when my home hosted vaultwarden died due to hdd failure.
Comment by SoftTalker 2 days ago
Consider it a learning experience.
Comment by joshmn 2 days ago
We've all been reduced to a passphrase.
When I've lobbed this scenario to the security managers/employees at these companies, they all give me a really great answer:
Q: What happens if a sitting senator gets mugged and they have their printed 2fa codes sitting in their wallet?
A: They have a special number they can call.
Comment by bshaughn 2 days ago
Comment by beej71 2 days ago
Comment by teekert 2 days ago
Also frees me up to experiment a bit more on the Phone side (just got a Pixel 10 with GrapheneOS), although, so far it all just works (with Google Services of course).
It's annoying that you really do need either Android or iOS nowadays. If only we could virtualize one of those platforms properly (and free as in freedomly).
Comment by bentcorner 1 day ago
Well through an unfortunate sequence of button clicks I wiped my 2FA state and had a hell of a time getting into the apps that I removed my SMS from.
In theory yes SMS is an attack vector but personally the safety and convenience of SMS is more valuable than the odds that someone impersonates me at my mobile provider.
(Also I stopped using that 2FA app and just use a keepass db stored in onedrive).
Comment by emaro 2 days ago
Comment by varispeed 2 days ago
Comment by croon 1 day ago
I can highly recommend Ente Auth though.
Comment by happyopossum 2 days ago
I'm sorry you're dealing with this - hopefully everyone else here can take it as a cautionary tale.
Comment by luka 2 days ago
Comment by dgunay 2 days ago
Comment by senordevnyc 2 days ago
Comment by asdff 2 days ago
Comment by ihg5000mrtnav 2 days ago
Comment by luka 2 days ago
Comment by ihg5000mrtnav 2 days ago
I know the email, password, (wrong) phone number on file, and associated YouTube channel. I am logging in from a different IP address but on the same ASN and approximate geolocation that I always logged in and used the account from.
Comment by luka 2 days ago
Comment by ihg5000mrtnav 2 days ago
Comment by luka 2 days ago
Comment by ihg5000mrtnav 2 days ago
Attempt 2: Entered email, got captcha, completed captcha, got enter last password screen, clicked "try another way". Form asked to confirm phone number. Entered phone number, sent code (which I can't get), clicked "I don't have my phone". Site asked for alternate email, which I provided and supplied the code. Result: "Reply to your Google support email or contact to let the team know you've successfully completed your account recovery request. To try signing in again, follow the steps in our Help Center on how to recover your account."
Attempt 3: Entered email, got captcha, completed captcha, got enter last password screen, entered password, got asked to confirm phone number, clicked "I don't have my phone". Site asked for alternate email, which I provided and supplied the code. Result: "Reply to your Google support email or contact to let the team know you've successfully completed your account recovery request. To try signing in again, follow the steps in our Help Center on how to recover your account."
All attempts were done with new Chrome Incognito windows and no other Incognito windows open. I still can't sign in at all. Is this account just permanently locked?
Comment by luka 1 day ago
The form is now asking me for details that we best talk non-publicly about. What's the best place to contact you privately, other than HN?
Comment by ihg5000mrtnav 1 day ago
Comment by luka 1 day ago
Comment by j1elo 2 days ago
This kind of posts are a valuable trigger for all others who are reading it. To the author: good luck, I hope you sort your situation soon! I'm now headed to check my accounts for what recovery options I left in there.
Comment by splitwheel 2 days ago
Comment by wccrawford 2 days ago
That's already a lot and anything easier would allow people to just take over accounts that they don't have a right to.
Comment by karim79 2 days ago
I got burned by Google authenticator in the past and had to jump through hoops to regain access to my accounts (non Google ones). It was painful. I learned the hard way I suppose.
Comment by runjake 2 days ago
Other than that, I copy/pasted your post into Claude and it had some good ideas.
Comment by tamimio 2 days ago
Comment by throw7 2 days ago
"For your security, you can't call Google for help to sign into your account. We don’t work with any service that claims to provide account or password support. Do not give out your passwords or verification codes."
for the future: https://support.google.com/accounts/answer/7684753
Comment by TacticalCoder 2 days ago
As a techie you should have known better: you first learn how 2FA using TOTP works. You understand what happens when you create an entry in Google Authenticator (or whatever app). You reproduce the procedure: you verify that you end up with the same 6-digit numbers.
If you've got a partner, you register your secret keys for each service on your partner's device and vice-versa.
Then you've got backups of your secret keys on paper, in a safe at your bank. Next to each secret key there's a checkbox: "Successfully initialized from this secret key?".
When those TOTP became ubiquitous (way, way, way before Yubikeys or passkeys were a thing), 2FA was a godsend compared to just passwords.
I understood they were here to stay for years, and years. And then more years.
So I learned how they worked.
When later on QR code generalized to initialize those (IIRC it wasn't a thing in the early days of 2FA TOTP: you'd just always get the secret key as characters, not as a QR code), I refused to ever scan a QR code: I always first decode the QR code (for the services only showing the secret key as a QR code, without also showing it as text), extract a copy of the secret key and then register it from my copy.
Stuff like that.
Now... As most services are deeply broken and have completely insecure practices you just say "I lost my 2FA, I want to reset it" and because they're clueless when it comes to security, they'll allow you to reset it. If someone hacks your email, they pretty much can reset every single of your account (at least those tied to that email).
Comment by jeroenhd 2 days ago
Actually keeping your recovery options recent is the trick. Print out your recovery codes or store them somewhere safe. Check regularly (yearly, maybe more often) that there's a way to access your critical accounts.
For Google, you can also grab the cheapest Android phone you can find, sign in, and maybe boot it once a month or so to keep the tokens active.
If you've set up your account to only accept one source of 2FA and you lose thst source of 2FA, you lose your account. Same happens when you set up your account to only accept your password and then lose your password. If you lose your recovery email/2FA backup codes, you lose access, unless you're special enough to convince customer support that you are who you claim you are and not just a bot trying to hack you.
If you've lost your account and haven't set up any recovery mechanisms, you're probably out of luck. Your best bet will be looking for an old browser session with enough trust from Google's side to get access without reconfirming your 2FA trust.
Comment by jakub_g 2 days ago
If you're not into cloud-based password/2FA syncing, Google Authenticator supports local export/import across devices via a QR code. For passwords, I use KeePass Portable / Keepass2Android + syncing between devices from time to time through a USB-C pendrive (The source of truth KP DB is on pendrive, and both phones work off a local on-device cache).
You don't need to have your phone stolen for things to get messed up. If your screen breaks, you can't type in a PIN anymore, can't unblock with a fingerprint, and you effectively can't access anything on the phone. ADB won't connect because screen is off, and you can't unlock / accept a new external connection etc.
Comment by cj 2 days ago
Sadly this is why I never end up trading in my phone. Always feels too risky to not have an overlap period.
Comment by SAI_Peregrinus 2 days ago
Even if they had customer support, if that customer support had a backdoor to unlock your account it would be regularly used by malicious parties to steal people's accounts & data.
Comment by dvngnt_ 2 days ago
Comment by mococa 2 days ago
Comment by lotsofpulp 2 days ago
Comment by ks2048 2 days ago
Comment by vel0city 2 days ago
Comment by tempfile 2 days ago
Comment by mococa 2 days ago
Comment by rationalist 2 days ago
Comment by stefan_ 2 days ago
Using the iPhone backup to setup a new phone is a good reminder every time that not half of the stuff comes back correctly..
Comment by asdff 2 days ago
Comment by phildougherty 2 days ago
Comment by pixl97 2 days ago
Comment by Telaneo 2 days ago
Comment by tornado134 2 days ago
Comment by thrownaway561 2 days ago
Comment by phainopepla2 2 days ago
Comment by ectoloph 2 days ago
Using my password manager to store 2FA codes is convenient, but it adds a layer of indirection if they are elsewhere.
But if you've compromised my password manager, you almost certainly have enough access to my machines to get to the alternatives.
Comment by vel0city 2 days ago
What happens when your Bitwarden gets compromised?
Comment by patshead 2 days ago
I hope that isn't true, because I sure can't think of a good way to use Bitwarden's TOTP as 2FA for Bitwarden! :)
Comment by vablings 2 days ago
I have 3 FIDO2 USB Security keys, One I carry with my persons at all times, one that stays with my main machine at all times and an offsite backup that is sitting in a friend's server, if my house burns down, I can either physically collect the key or use USB-IP to authenticate back into bitwarden and enroll a new key. (Actually all 3 are at home right now but that's ok)
My phone is logged into Bitwarden so even then I can recover my passwords and data in case of a serious incident immediately.
Even if both my house and my friend's house burn down at the same time, I can still recover my data from my phone unless my phone is left in the house, all of which to say I still have the recovery phrase written down in a box somewhere in a different country
Comment by bshaughn 2 days ago
Comment by thesuitonym 2 days ago
Comment by bshaughn 2 days ago
Ive always said, the number one reason I will stick with an iphone - despite any present for future dumb ux changes - is that I will always be able to physically go to an apple store and get someone to help me.
Comment by ifh-hn 2 days ago
Comment by croon 1 day ago
Comment by snowwrestler 2 days ago
Comment by mqtx 2 days ago
Comment by MotoriX 1 day ago
Comment by lyfeninja 2 days ago
Comment by autoexec 2 days ago
Comment by Freak_NL 2 days ago
Additional benefit: I can generate an OTP for any service protected like this without having to get my phone from wherever it is.
Comment by Gengar 2 days ago
Comment by xpct 1 day ago
Comment by pards 2 days ago
I use Proton Authenticator now [0]
Authy used to do this, then they enshittified their app and bricked the desktop version.
Comment by flowerlad 2 days ago
Comment by kwanbix 2 days ago
Comment by flakiness 2 days ago
So relatively new, and I didn't know this and moved to proton for this reason recently.
Comment by flowerlad 2 days ago
Comment by adi_kurian 2 days ago
Comment by trinsic2 1 day ago
Comment by protocolture 2 days ago
After that we both created a set of one time codes and stored them offline.
Comment by haellsigh 2 days ago
Comment by sharts 1 day ago
Comment by ezfe 2 days ago
Comment by mixmastamyk 2 days ago
Comment by tonymet 2 days ago
I would send a paper letter to the Google legal contact. It's the only way to get escalated support.
I agree the covenant for account recovery has been broken. Every 6 months, a new artifact is expected to access the account, without adequate preparation for the recovery.
Comment by flerchin 2 days ago
Comment by Apreche 2 days ago
Comment by ck2 2 days ago
your only hope to get your google account back is to convince your phone carrier to transfer your old phone number to a new phone that you control
Comment by cute_boi 2 days ago
Google Employee, can you please fix your shit? Losing phone number doesn't mean you have to lose everything....
Comment by vasemkhan328 2 days ago
Comment by anothereng 2 days ago
Comment by dailyfreetools 1 day ago
Comment by laurennorthwood 2 days ago
Comment by Transformanshen 1 day ago
Comment by agentwang 2 days ago
Comment by xyst 2 days ago
call sergey brin \s
Comment by pholypilz 2 days ago