3 ms·
If you don't have the authenticator backup codes and you didn't turn on cloud sync in the app, you might be out of luck. You can get a replacement SIM though a
by sampullman 16d ago
If you don't have the authenticator backup codes and you didn't turn on cloud sync in the app, you might be out of luck.
You can get a replacement SIM though and use it with a new phone, so the phone number recovery option should work.
- uberman 16d agoThis. Can't you get your number moved to a new phone? I have never don't anything magic when upgrading my phone other than move contacts.
- jwr 16d agoHow would moving your number to a new phone help? We're talking TOTP here, not SMS "auth".
- john_strinlai 16d agodoes google not offer a backup via sms? it's a common enough recovery flow elsewhere. (i dont use google stuff, so i am genuinely asking)
- b112 16d agoAny less secure backup method, means others are less secure.
- john_strinlai 16d agoyes, i understand. i was asking specifically whether google has sms recovery flow, not how secure sms recovery flow is compared to other options.
- mrguyorama 16d agoGoogle actually puts effort into security for "normal" people who don't want to earn a PhD in cryptography just to have a damn free email account or watch Mr. Beast That's why they had powerful and effective account takeover protection even 15 years ago. The kind that will prevent the hacker from taking over your account even though they got access to all your factors, because it shouldn't take expertise to know that if you logged in from Oregon twenty minutes ago, you definitely aren't also logging in from Ecuador. Which of course makes it all the more stupid that your credit card company, all your medical service providers, and Facebook don't meet that absurdly low bar. Facebook will happily hand control to the scammer in Laos who got one of your factors and somehow that gave them access to change your password and recovery email
- Dylan16807 16d agoThe best backup method doesn't need any computer knowledge, it's writing down or printing a few passwords and putting that piece of paper in the same box as your taxes or birth certificate.
- cwillu 16d agoA required “more secure” method is less secure if it means you can be locked out by not-exactly-uncommon real-life situations. Denial of service is a security issue.
- hedora 16d agoI’ve repeated it a hundred times security = confidentiality, integrity and availability. One reason to strongly prefer Apple over Google is that (as I understand it) you can still walk into a store with ID and recover your online identity.
- jwr 16d ago> One reason to strongly prefer Apple over Google is that (as I understand it) you can still walk into a store with ID and recover your online identity. Is this true? If so, in what countries? (Poland has no Apple stores, for example, for inexplicable reasons Apple has been giving the middle finger to this market) That would be a huge difference.
- kaycey2022 15d agoI think Google’s own textbook on SRE has an example in its very first chapter where everyone gets locked out of their bus fleet WiFi thanks to their secure system reaching an unforeseen state
- chinathrow 16d agoYou can export from Google Authenticator to another device just fine.
- jwr 14d agoHow do you export from a phone you no longer have?
- chinathrow 14d agoI misread your comment, you're right.
- dz0ny 16d agoHappened to me, I was able to get SMS and recovery codes, but Google still required additional verification on now lost phone :D. On the end I acutely found the phone and was able to restore access. So what they do after couple of days of failed attempts the require additional verification, lets call it 3 step.
- cute_boi 16d agoI have passkeys, authenticator etc... and everything except phone number, and now i am unable to login my account in other device. Google sucks, they are randomly denying access because their dumb model can't figure out not everyone is trying to steal account.
- tornado134 16d ago[dead]
- kaycey2022 15d agoThis feels objectively worse than writing down a password somewhere