Ask HN: How to recover Google auth after phone stolen?
Losing a phone tied to Google Authenticator can permanently lock users out of Gmail and other services if they haven’t saved backup codes, enabled cloud sync, or kept a second device logged in. Commenters describe how Google’s strong protections and lack of human support make account recovery nearly impossible in some real-world scenarios, highlighting a tension between security and availability. Many advocate practical disaster‑recovery steps: printing or securely backing up 2FA seeds and recovery codes, using authenticators that sync across devices, keeping spare hardware keys or phones, and avoiding a single phone as the sole gateway to one’s digital life.
Overall Consensus: Recovery May Be Impossible
- Many comments state that if you lose your phone and don’t have backup codes, synced authenticators, or other recovery factors, you may be permanently locked out.
- Several argue this is by design: if support could easily override 2FA, attackers would exploit that same path.
- Some suggest in dire cases you may have to abandon the account and recreate identities elsewhere.
Google’s Recovery Flows & Limitations
- Available recovery options mentioned: backup codes, recovery email, SMS/phone number, passkeys, and logged‑in devices.
- Some users report that even with SMS, recovery codes, and correct passwords, Google still blocks access if its risk model flags the attempt.
- Others describe eventually getting back in after repeated attempts from a “familiar” device or setup.
- There is no official phone support for account unlock; this is explicitly framed as a security feature.
- A few mention that insiders can sometimes escalate cases, highlighting an informal “backdoor” of personal connections.
Security vs. Availability Debate
- One camp emphasizes strong security and no human override as necessary to prevent large‑scale account takeovers.
- Another camp argues that denial of access is itself a security failure (availability), especially in common real‑world scenarios like theft, house fires, or lost numbers.
- Concern that non‑technical users are especially at risk of irrecoverable lockouts.
Backup & 2FA Strategies Proposed
- Save and periodically test backup codes; store them offline (paper in a safe, with important documents).
- Use authenticators that sync across multiple devices (Google Authenticator with sync, Proton, Ente, Authy, etc.), or keep a second “backup” device logged in.
- Some prefer password managers (Bitwarden, Vaultwarden, etc.) to hold both passwords and TOTP, with hardware keys protecting the manager. Others warn this creates a single point of failure.
- Print or record TOTP secrets/QR data, and/or store them on multiple devices or with trusted partners.
Phone as Critical Single Point of Failure
- Multiple anecdotes of people essentially “locked out of society” when a phone is lost: can’t pay, travel, or log in.
- Some consciously avoid phone‑dependent services, carry physical cards and backup phones, or keep minimal smartphones.
- Apple is perceived by some as more recoverable due to in‑person store support, though details and coverage are unclear.