LmCast :: Stay tuned in

Ask HN: How to recover Google auth after phone stolen?

Recorded: Sept. 17, 2026, 5 p.m.

Original Summarized

Ask HN: How to recover Google auth after phone stolen? | Hacker NewsHacker Newsnew | past | comments | ask | show | jobs | submitloginAsk HN: How to recover Google auth after phone stolen?23 points by keymasta 51 minutes ago | hide | past | favorite | 21 commentsAs we know, google has been effective at automating a lot of their systems, to the point where it can feel like there isn't any help available from a human. So what is supposed to be the plan when this type of situation happens?Basically I have a situation that after my phone was stolen, I can't get into any of my accounts that are either connected to google, or connected to the phone via 2FA. This has made it complicated/impossible not only to get info about my phone, but also my banking, email, drive, etc.Of course they offer you "multiple options" to recover an account, but not if you forgot your old email's password. At that point the options you get are, a) Use old phone (obviously the phone is long gone)
b) Use current phone (the phone is gone)
c) Use old email (I haven't used it in like 12 years)

Does anyone know if their is a process to appeal 2FA or anything to deal with this type of situation?I'd imagine that this has happened to people many many times, and given how phones and particularly, google auth have become so critical to accomplishing essential tasks within society, there must be some way. Or maybe it's just like, once your phone is gone, you are completely over with society? If anyone has any experience with this or inside knowledge please share it!I'm sure people here have heard of this, and maybe experienced it themselves.Is there a secret option that exists that allows us to use passwords instead of rigamarole? I would love an account that let me simply log in with a password, like google used to be. help

sampullman 39 minutes ago | next [–]
If you don't have the authenticator backup codes and you didn't turn on cloud sync in the app, you might be out of luck.You can get a replacement SIM though and use it with a new phone, so the phone number recovery option should work.replyuberman 36 minutes ago | parent | next [–]
This. Can't you get your number moved to a new phone? I have never don't anything magic when upgrading my phone other than move contacts.replySoftTalker 22 minutes ago | prev | next [–]
You're going to have more success working with the providers of the other accounts and services rather than Google. That means a lot more legwork on your part but banks and other online services all have processes to deal with lost passwords. In some cases you may have to physically go somewhere with ID and other documents.Consider it a learning experience.replyticulatedspline 36 minutes ago | prev | next [–]
Isn't there an SMS option? buy a new phone and have them send you an OTP via SMS.> once you're phone is gone, you are completely over with society?yes, I'm waiting for the Black-Mirror episode where someone drops their phone and basically dies, can't contact anyone, can't unlock or start their car, can't get an uber, can't pay for anything, can't navigate without gps, can't log into anything etc.replykeymasta 15 minutes ago | parent | next [–]
Pretty similar to how my life feels right now.replywccrawford 24 minutes ago | prev | next [–]
Everything you listed, plus a recovery email option, plus backup codes, plus SMS.That's already a lot and anything easier would allow people to just take over accounts that they don't have a right to.replythrownaway561 0 minutes ago | prev | next [–]
Honestly.... This is why I have everything in Bitwarden. All 2FA runs through it so even if my phone got stolen, I could still access everything. I honestly don't understand why more people don't pay the $10 a year and just use Bitwarden.replyautoexec 14 minutes ago | prev | next [–]
Man, passwords sure are nice aren't they! All you have to do is remember one because your password manager remembers all the rest of your randomly generated passwords for you and as long as you keep a backup of the password database you never have to worry about this bullshit.replymococa 41 minutes ago | prev | next [–]
There's no way, no human contact. That's why I de-googled myself.replylotsofpulp 34 minutes ago | parent | next [–]
No human contact is a plus for security, as the human is the weakest link that can give up your authentication to someone that isn’t you.replyks2048 2 minutes ago | root | parent | next [–]
The human factor is walking into your local branch with your face and an ID - something that can’t be done on a large scale by bots.replymococa 26 minutes ago | root | parent | prev | next [–]
Have you heard about Meta AI doing support?replytempfile 25 minutes ago | root | parent | prev | next [–]
"I am permanently locked out of my account with no recourse" is also a security issue.replyrunjake 43 minutes ago | prev | next [–]
The only secret option I know of is to have a popular social media account and complain online.Other than that, I copy/pasted your post into Claude and it had some good ideas.replyphildougherty 43 minutes ago | prev | next [–]
need to save your recovery keys (text file) before you lost the phonereplymixmastamyk 16 minutes ago | prev | next [–]
Does your browser have the email password saved?replySAI_Peregrinus 33 minutes ago | prev | next [–]
The same way you recover any other deleted data for which you didn't make a backup: you don't. You eat the loss & make new accounts. Then you remember to make and test backups for the future.Even if they had customer support, if that customer support had a backdoor to unlock your account it would be regularly used by malicious parties to steal people's accounts & data.replydvngnt_ 15 minutes ago | parent | next [–]
They could do ID verificationreplypards 17 minutes ago | prev | next [–]
Going forward, consider using an authenticator that securely syncs across multiple devices to remove the single point of failure risk.I use Proton Authenticator now [0]Authy used to do this, then they enshittified their app and bricked the desktop version.[0]: https://proton.me/authenticatorreplyflowerlad 9 minutes ago | parent | next [–]
Google authenticator supports syncing across multiple devices.replyApreche 36 minutes ago | prev | next [–]
You were supposed to save your backup codes.reply

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
Search:

The discussion centers on the significant security challenges and practical difficulties encountered when attempting to recover access to accounts, particularly those secured by Google authentication and two-factor authentication (2FA), following the theft of a mobile phone. The core frustration expressed is the perceived lack of automated recourse when dealing with these situations, prompting a search for undocumented processes or secret options to appeal 2FA or regain control of locked accounts.

The inherent difficulty described stems from the nature of recovery options; standard methods for account recovery, such as using an old device, the current device, or an old recovery email, are rendered impossible in this scenario, creating a complete digital lockout. This situation extends beyond personal accounts, impacting access to critical services like banking, email, and cloud storage, emphasizing that the loss of the primary device severs access to essential societal functions.

Participants engaged in a dialogue regarding potential solutions for mitigating this risk. One suggestion highlighted the necessity of having comprehensive recovery measures in place, including backup codes, recovery email access, and SMS options. The consensus was that while these features are desirable, their absence exacerbates the difficulty in recovery. Advice shifted focus from relying solely on Google for recovery to leveraging the established recovery processes of external service providers, such as banks and other online services, which typically possess their own procedures for handling lost passwords and access recovery, often requiring physical verification.

Furthermore, the conversation evolved to encompass proactive security strategies rather than reactive recovery. Several contributors stressed the importance of employing robust password management systems, noting that using tools that manage and secure multiple two-factor authentications, such as password managers, can mitigate such catastrophic single points of failure. The concept was introduced that securing data through layers of security, like those offered by applications like Bitwarden, provides a critical safety net.

A major theme emerged concerning the architecture of human-based security. It was argued that the human element—the necessity for human contact during verification—represents the weakest link in security, as a compromised human can bypass automated defenses. This led to considerations about minimizing reliance on direct human interaction, with some suggesting that minimizing these contact points enhances security.

Technological solutions were also explored in relation to multi-device authentication. There was a focus on using authenticator applications that support synchronization across multiple devices, thereby eliminating the vulnerability associated with a single lost device. Specific examples were cited, including the use of applications like Proton Authenticator or Authy, which allow for cross-device synchronization of authentication keys. The necessity of saving recovery keys and backup codes before losing access was emphasized as a crucial preventative step.

Ultimately, the discussion underscored that while true, seamless recovery protocols for lost devices remain elusive, the practical approach involves acknowledging the limitations of centralized authentication systems and shifting reliance toward decentralized security practices. The prevailing sentiment is that users should prioritize implementing layered security—including redundant backups, strong password practices, and multi-device synchronization of authentication mechanisms—to avoid being completely disenfranchised when a single piece of hardware is compromised.