As we know, google has been effective at automating a lot of their systems, to the point where it can feel like there isn't any help available from a human. So what is supposed to be the plan when this type of situation happens?
Basically I have a situation that after my phone was stolen, I can't get into any of my accounts that are either connected to google, or connected to the phone via 2FA. This has made it complicated/impossible not only to get info about my phone, but also my banking, email, drive, etc.
Of course they offer you "multiple options" to recover an account, but not if you forgot your old email's password. At that point the options you get are,
a) Use old phone (obviously the phone is long gone)
b) Use current phone (the phone is gone)
c) Use old email (I haven't used it in like 12 years)
Does anyone know if their is a process to appeal 2FA or anything to deal with this type of situation?
I'd imagine that this has happened to people many many times, and given how phones and particularly, google auth have become so critical to accomplishing essential tasks within society, there must be some way. Or maybe it's just like, once your phone is gone, you are completely over with society? If anyone has any experience with this or inside knowledge please share it!
I'm sure people here have heard of this, and maybe experienced it themselves.
Is there a secret option that exists that allows us to use passwords instead of rigamarole? I would love an account that let me simply log in with a password, like google used to be.
This has often been abused with mobile phone carriers to get SIM cards issued for targets by just knowing enough customer details. This then allowed them to intercept SMS 2FA challenges and access even more sensitive accounts.
Google actually puts effort into security for "normal" people who don't want to earn a PhD in cryptography just to have a damn free email account or watch Mr. Beast
That's why they had powerful and effective account takeover protection even 15 years ago. The kind that will prevent the hacker from taking over your account even though they got access to all your factors, because it shouldn't take expertise to know that if you logged in from Oregon twenty minutes ago, you definitely aren't also logging in from Ecuador.
Which of course makes it all the more stupid that your credit card company, all your medical service providers, and Facebook don't meet that absurdly low bar. Facebook will happily hand control to the scammer in Laos who got one of your factors and somehow that gave them access to change your password and recovery email
Happened to me, I was able to get SMS and recovery codes, but Google still required additional verification on now lost phone :D. On the end I acutely found the phone and was able to restore access. So what they do after couple of days of failed attempts the require additional verification, lets call it 3 step.
Isn't there an SMS option? buy a new phone and have them send you an OTP via SMS.
once you're phone is gone, you are completely over with society?
yes, I'm waiting for the Black-Mirror episode where someone drops their phone and basically dies, can't contact anyone, can't unlock or start their car, can't get an uber, can't pay for anything, can't navigate without gps, can't log into anything etc.
As an old curmudgeon I recoil at any service I can't interact with sans-phone. I hardly use mine for anything.
Just be glad your phone number is tied to your account, if you lose the number itself you are royally screwed, and basically anyone who gets your old number owns all your accounts now.
Same, it is kind of strange. Back in 2005 I was one of the first to carry the full internet on my phone and now I am leading the charge to avoid having to carry the internet in my pocket.
If your product or service requires a phone, I just don't do business with you. I know I sound archaic recommending this, but we (as a society) need to push back on your phone being the key to your life.
My phone is no more special than my laptop, however this requires an incredible amount of inconvenience for most people along with the constant social pressure to carry a cellphone. As you can imagine, I do not have many friends these days.
The same way you recover any other deleted data for which you didn't make a backup: you don't. You eat the loss & make new accounts. Then you remember to make and test backups for the future.
Even if they had customer support, if that customer support had a backdoor to unlock your account it would be regularly used by malicious parties to steal people's accounts & data.
You're going to have more success working with the providers of the other accounts and services rather than Google. That means a lot more legwork on your part but banks and other online services all have processes to deal with lost passwords and 2FA devices. In some cases you may have to physically go somewhere with ID and other documents.
Another thing to know: in the hamburger menu there is a "require face id option". Turn it on, otherwise if your phone is snatched from you (while unlocked), they can access your 2-factor codes.
Man, passwords sure are nice aren't they! All you have to do is remember one because your password manager remembers all the rest of your randomly generated passwords for you and as long as you keep a backup of the password database you never have to worry about this bullshit.
OTP works with a password manager too. I have Authy on my Android, and Pass on my Linux computers. The second is backed up properly. This approach just means that enabling 2FA (which is mostly OTP in any case) just means registering the OTP URI in two locations instead of one.
Additional benefit: I can generate an OTP for any service protected like this without having to get my phone from wherever it is.
Honestly.... This is why I have everything in Bitwarden. All 2FA runs through it so even if my phone got stolen, I could still access everything. I honestly don't understand why more people don't pay the $10 a year and just use Bitwarden.
Having your passwords and 2FA with the same provider carries some risk. If someone can access your Bitwarden account they will have full access to all your accounts.
FIDO2 USB Security key -> Bitwarden (With master password) -> Every other 2FA method
I have 3 FIDO2 USB Security keys, One I carry with my persons at all times, one that stays with my main machine at all times and an offsite backup that is sitting in a friend's server, if my house burns down, I can either physically collect the key or use USB-IP to authenticate back into bitwarden and enroll a new key. (Actually all 3 are at home right now but that's ok)
My phone is logged into Bitwarden so even then I can recover my passwords and data in case of a serious incident immediately.
Even if both my house and my friend's house burn down at the same time, I can still recover my data from my phone unless my phone is left in the house, all of which to say I still have the recovery phrase written down in a box somewhere in a different country
Yeah I lost my phone some months ago. Quite the panick because I am also MS365 admin for 2 orgs... 3 hr later a trucker called my wife using the iPhone emergency contact feature (what a hero). Now I bought an iPad that stays at home and has all the apps. Honestly, I should also put a second phone somewhere else.
Also frees me up to experiment a bit more on the Phone side (just got a Pixel 10 with GrapheneOS), although, so far it all just works (with Google Services of course).
It's annoying that you really do need either Android or iOS nowadays. If only we could virtualize one of those platforms properly (and free as in freedomly).
This is why my self-hosted Vaultwarden is my one password that I have to remember and requires no 2fa, which is the only important account that doesn't have 2fa.
If I wake up in a bathtub missing a kidney I can still get to my passwords and 2fa sources stored with it. Some accounts require SMS (annoyingly) so I'd have to buy a phone but the auth and credit card numbers I need to do that are in Vaultwarden, too.
I don't have good solutions now for OP (other than buy a new phone through your carrier and transfer the number). But everyone else do think through your personal DRP. Generate backup codes and put them somewhere safe, too.
One of my favorite things about self-hosted Vaultwarden is that you get distributed backups for free. Every client keeps an offline copy of your entire password vault, kept in sync when the client is online.
So for me to lose my vault, not only would my server have to get hit by a bus, but also my phone, my desktop, my HTPC, both laptops...
You can add a passkey (preferably a physical one) to authenticate. You can also add a software passkey but that kind of defeats the purpose.
Actually keeping your recovery options recent is the trick. Print out your recovery codes or store them somewhere safe. Check regularly (yearly, maybe more often) that there's a way to access your critical accounts.
For Google, you can also grab the cheapest Android phone you can find, sign in, and maybe boot it once a month or so to keep the tokens active.
If you've set up your account to only accept one source of 2FA and you lose thst source of 2FA, you lose your account. Same happens when you set up your account to only accept your password and then lose your password. If you lose your recovery email/2FA backup codes, you lose access, unless you're special enough to convince customer support that you are who you claim you are and not just a bot trying to hack you.
If you've lost your account and haven't set up any recovery mechanisms, you're probably out of luck. Your best bet will be looking for an old browser session with enough trust from Google's side to get access without reconfirming your 2FA trust.
Yup, having _two_ active devices which are logged in to Google (and possibly other services that you rely on that opt you in to app-based 2FA) + with backups of 2FA is a must at this point. When I buy a new phone, I make it a "primary", and keep my old phone as "backup".
If you're not into cloud-based password/2FA syncing, Google Authenticator supports local export/import across devices via a QR code. For passwords, I use KeePass Portable / Keepass2Android + syncing between devices from time to time through a USB-C pendrive (The source of truth KP DB is on pendrive, and both phones work off a local on-device cache).
You don't need to have your phone stolen for things to get messed up. If your screen breaks, you can't type in a PIN anymore, can't unblock with a fingerprint, and you effectively can't access anything on the phone. ADB won't connect because screen is off, and you can't unlock / accept a new external connection etc.
can you recover one of the old contact points (phone or email) for a reset code?
I would send a paper letter to the Google legal contact. It's the only way to get escalated support.
I agree the covenant for account recovery has been broken. Every 6 months, a new artifact is expected to access the account, without adequate preparation for the recovery.
All those times you logged in and were prompted to verify your backup email address, and when you set up 2FA and were given recovery codes, and when given the option to sync 2FA codes to another copy of the authenticator app: This Is Why.
I'm sorry you're dealing with this - hopefully everyone else here can take it as a cautionary tale.
This happened to me on my iPhone 8 many years ago. I reset it to let my son use it, and did not have google authenticator in mind. I had to reset each account with the providers. Now I use a cloud account to sync these. I reset most accounts with an SMS or email one time code -- which led me to remove SMS and email as recovery options from google. And, I put a code on t-mobile to prevent sim transfer.
I'll fill out a "help my friend" form internally unless someone beats me to it (I have a 1hr meeting coming up). The gmail address in question is the same one as on your website?
That's nice of you, but I'd urge anyone with influence at Google to consider 1) many many many more people who use Google services probably don't know or run in the same circles as Googlers who can bail them out of such a scenario, and 2) these people, being much less likely to understand 2FA, are also more likely to accidentally lock themselves out. An separate class of people who know how a system works or have connections to its operators become nose blind to its terrible UX because they have access to workarounds.
All true, but I’m guessing the set of people at Google who can fill out that form is about 1000x larger than the ones who have the ability to influence the underlying product decisions that led to this situation.
Sorry to bother, but I have been without access to the account I use for my YouTube channel for months because I stupidly entered a random phone number many years ago and it is now demanding access to it. If you would be willing to fill out that form for me, I would greatly appreciate it. Account is this username at gmail. Thanks!
Did you try going through the normal account recovery procedure?
During that procedure, did you have to provide an alternative email address that you have access to?
The account recovery procedure only asks for the last password I remember (which I know is correct) and then says "You can’t recover your account at this time because Google doesn’t have enough info to be sure this account is yours."
I know the email, password, (wrong) phone number on file, and associated YouTube channel. I am logging in from a different IP address but on the same ASN and approximate geolocation that I always logged in and used the account from.
I have tried all combinations of entering password, entering the phone number, try another way, etc., and it never lets me enter an alternative email address.
I have to click "Try another way" at least twice on g.co/AccountRecoveryRequest to get the option to provide an alternative contact email address. Maybe try a private session to make sure coookies aren't taken into account.
Recovery is similar to leaving a copy of your door keys to a trusted neighbour (a tradition in some places, it comes in handy when someone goes out and realizes they forgot the keys inside...), so in that comparison, having a recovery email unused for 12 years feels like leaving your backup keys to a neighbor that you never saw ever again in more than a decade.
This kind of posts are a valuable trigger for all others who are reading it. To the author: good luck, I hope you sort your situation soon! I'm now headed to check my accounts for what recovery options I left in there.
Well that’s why you should have software 2FA and even backing up the tokens so you can generate that one time code even if you lost access to your main authenticator, having your phone as the only 2FA is like having those yubikey hardware used as 2FA without making a redundant one, losing it, you lost access, which is usually known since no one would use yubikey without being tech savvy to start with, now google or other companies are turning phones as an attestation method for the crowd, you might soon in the future become citizen-less because your digital ID can only be proven in the lost phone.
While we are on this, is there a comprehensive guide on how to "theft-proof" your iPhone? Not in the sense of preventing the theft, but rather the fallout on all our various online service access.
Using the iPhone backup to setup a new phone is a good reminder every time that not half of the stuff comes back correctly..
I'm not sure you'd really need a guide. Just use the phone as a phone and pretend like it isn't a smartphone. Suddenly you are teleported back into 2005: physical credit cards, physical transit passes, online banking via a desktop website. It is still up to you what era you decide to live in technologically today.
I've had this issue before, and the only thing that saved me was SMS (phone number) backup.
I believe Google is slightly easier than Meta to contact by phone so this should help.
I had some experience similar to this and found that after some months, when logging in on an extremely familiar to Google setup, that there was an additional prompt where it asked for some old passwords IIRC and then let me in.
I mistakenly changed my phone number due to spam call, then i tried to login Google account in another device. Now, this fucking google don't allow me to login at all. It keep saying "Google can't verify you". I have accepted prompts, given them passkeys from 1password, have recovery code and everything. But no lock. I am now scared if my google account gets logged out, i will be in very problematic situation.
Google Employee, can you please fix your shit? Losing phone number doesn't mean you have to lose everything....
Dumb question, does backing up my iphone to icloud help solve this? Assuming im willing and able to get a brand new phone? What 2fa would the Apple store need, if hypothetically my lost iphone was my only apple product?
It's not a dumb question, but there isn't any single answer. It depends on what protections you have on your iCloud account. For most users, if you've lost your phone, but remember your iCloud password and have a new phone with the same number, you can get in. It's made even easier if you have another device already signed in, such as a laptop.
Luckily I do have a macbook, and try to put all my passwords in a "neutral" password manager, but this post has made me think about the edge cases of this sort of thing.
Ive always said, the number one reason I will stick with an iphone - despite any present for future dumb ux changes - is that I will always be able to physically go to an apple store and get someone to help me.
honestly a piece of paper that has your password without saying it is your password and use that password for your most important thing (email) or password manager
It's a "feature" that you can't call google to help with getting "locked out":
"For your security, you can't call Google for help to sign into your account. We don’t work with any service that claims to provide account or password support. Do not give out your passwords or verification codes."
Doesn't help obviously if you already lost your phone, but I recommend anyone to use a third party authenticator app. Most services offer to scan a QR code to set up MFA, which can easily be backed up. Don't use Google/Microsoft authenticator apps directly. Personally I use Stratum, but any that allows export/import will do.
This situation is why I don't use authenticator apps, or passkeys linked to a device. Single point of failure, and obviously with any of the big tech companies, zero recourse.
I can't help you but my comment may help others...
As a techie you should have known better: you first learn how 2FA using TOTP works. You understand what happens when you create an entry in Google Authenticator (or whatever app). You reproduce the procedure: you verify that you end up with the same 6-digit numbers.
If you've got a partner, you register your secret keys for each service on your partner's device and vice-versa.
Then you've got backups of your secret keys on paper, in a safe at your bank. Next to each secret key there's a checkbox: "Successfully initialized from this secret key?".
When those TOTP became ubiquitous (way, way, way before Yubikeys or passkeys were a thing), 2FA was a godsend compared to just passwords.
I understood they were here to stay for years, and years. And then more years.
So I learned how they worked.
When later on QR code generalized to initialize those (IIRC it wasn't a thing in the early days of 2FA TOTP: you'd just always get the secret key as characters, not as a QR code), I refused to ever scan a QR code: I always first decode the QR code (for the services only showing the secret key as a QR code, without also showing it as text), extract a copy of the secret key and then register it from my copy.
Stuff like that.
Now... As most services are deeply broken and have completely insecure practices you just say "I lost my 2FA, I want to reset it" and because they're clueless when it comes to security, they'll allow you to reset it. If someone hacks your email, they pretty much can reset every single of your account (at least those tied to that email).
Basically I have a situation that after my phone was stolen, I can't get into any of my accounts that are either connected to google, or connected to the phone via 2FA. This has made it complicated/impossible not only to get info about my phone, but also my banking, email, drive, etc.
Of course they offer you "multiple options" to recover an account, but not if you forgot your old email's password. At that point the options you get are,
Does anyone know if their is a process to appeal 2FA or anything to deal with this type of situation?I'd imagine that this has happened to people many many times, and given how phones and particularly, google auth have become so critical to accomplishing essential tasks within society, there must be some way. Or maybe it's just like, once your phone is gone, you are completely over with society? If anyone has any experience with this or inside knowledge please share it!
I'm sure people here have heard of this, and maybe experienced it themselves.
Is there a secret option that exists that allows us to use passwords instead of rigamarole? I would love an account that let me simply log in with a password, like google used to be.
The only secret option I know of is to have a popular social media account and complain online.
Other than that, I copy/pasted your post into Claude and it had some good ideas.
need to save your recovery keys (text file) before you lost the phone
Excellent idea... shit my house just burned down with my phone.
Backups, backups, backups.
Now on to how to keep those backups secure.
need to save your recovery keys (text file) before you lost the backups
There's no way, no human contact. That's why I de-googled myself.
No human contact is a plus for security, as the human is the weakest link that can give up your authentication to someone that isn’t you.
Have you heard about Meta AI doing support?
Only if you can log in. I am Meta Verified, but I cannot log in to get support.
"I am permanently locked out of my account with no recourse" is also a security issue.
The human factor is walking into your local branch with your face and an ID - something that can’t be done on a large scale by bots.
This has often been abused with mobile phone carriers to get SIM cards issued for targets by just knowing enough customer details. This then allowed them to intercept SMS 2FA challenges and access even more sensitive accounts.
If you don't have the authenticator backup codes and you didn't turn on cloud sync in the app, you might be out of luck.
You can get a replacement SIM though and use it with a new phone, so the phone number recovery option should work.
This. Can't you get your number moved to a new phone? I have never don't anything magic when upgrading my phone other than move contacts.
How would moving your number to a new phone help? We're talking TOTP here, not SMS "auth".
does google not offer a backup via sms? it's a common enough recovery flow elsewhere. (i dont use google stuff, so i am genuinely asking)
Any less secure backup method, means others are less secure.
yes, i understand. i was asking specifically whether google has sms recovery flow, not how secure sms recovery flow is compared to other options.
Google actually puts effort into security for "normal" people who don't want to earn a PhD in cryptography just to have a damn free email account or watch Mr. Beast
That's why they had powerful and effective account takeover protection even 15 years ago. The kind that will prevent the hacker from taking over your account even though they got access to all your factors, because it shouldn't take expertise to know that if you logged in from Oregon twenty minutes ago, you definitely aren't also logging in from Ecuador.
Which of course makes it all the more stupid that your credit card company, all your medical service providers, and Facebook don't meet that absurdly low bar. Facebook will happily hand control to the scammer in Laos who got one of your factors and somehow that gave them access to change your password and recovery email
You can export from Google Authenticator to another device just fine.
Happened to me, I was able to get SMS and recovery codes, but Google still required additional verification on now lost phone :D. On the end I acutely found the phone and was able to restore access. So what they do after couple of days of failed attempts the require additional verification, lets call it 3 step.
I have passkeys, authenticator etc... and everything except phone number, and now i am unable to login my account in other device.
Google sucks, they are randomly denying access because their dumb model can't figure out not everyone is trying to steal account.
You were supposed to save your backup codes.
Isn't there an SMS option? buy a new phone and have them send you an OTP via SMS.
yes, I'm waiting for the Black-Mirror episode where someone drops their phone and basically dies, can't contact anyone, can't unlock or start their car, can't get an uber, can't pay for anything, can't navigate without gps, can't log into anything etc.
Pretty similar to how my life feels right now.
As an old curmudgeon I recoil at any service I can't interact with sans-phone. I hardly use mine for anything.
Just be glad your phone number is tied to your account, if you lose the number itself you are royally screwed, and basically anyone who gets your old number owns all your accounts now.
Same, it is kind of strange. Back in 2005 I was one of the first to carry the full internet on my phone and now I am leading the charge to avoid having to carry the internet in my pocket.
If your product or service requires a phone, I just don't do business with you. I know I sound archaic recommending this, but we (as a society) need to push back on your phone being the key to your life.
My phone is no more special than my laptop, however this requires an incredible amount of inconvenience for most people along with the constant social pressure to carry a cellphone. As you can imagine, I do not have many friends these days.
The same way you recover any other deleted data for which you didn't make a backup: you don't. You eat the loss & make new accounts. Then you remember to make and test backups for the future.
Even if they had customer support, if that customer support had a backdoor to unlock your account it would be regularly used by malicious parties to steal people's accounts & data.
They could do ID verification
Everything you listed, plus a recovery email option, plus backup codes, plus SMS.
That's already a lot and anything easier would allow people to just take over accounts that they don't have a right to.
You're going to have more success working with the providers of the other accounts and services rather than Google. That means a lot more legwork on your part but banks and other online services all have processes to deal with lost passwords and 2FA devices. In some cases you may have to physically go somewhere with ID and other documents.
Consider it a learning experience.
Going forward, consider using an authenticator that securely syncs across multiple devices to remove the single point of failure risk.
I use Proton Authenticator now [0]
Authy used to do this, then they enshittified their app and bricked the desktop version.
[0]: https://proton.me/authenticator
Google authenticator supports syncing across multiple devices.
is that new? I migrated at the time from GA to Authy and from Authy to Ente because it was not supported.
https://security.googleblog.com/2023/04/google-authenticator...
So relatively new, and I didn't know this and moved to proton for this reason recently.
Another thing to know: in the hamburger menu there is a "require face id option". Turn it on, otherwise if your phone is snatched from you (while unlocked), they can access your 2-factor codes.
Does your browser have the email password saved?
Man, passwords sure are nice aren't they! All you have to do is remember one because your password manager remembers all the rest of your randomly generated passwords for you and as long as you keep a backup of the password database you never have to worry about this bullshit.
OTP works with a password manager too. I have Authy on my Android, and Pass on my Linux computers. The second is backed up properly. This approach just means that enabling 2FA (which is mostly OTP in any case) just means registering the OTP URI in two locations instead of one.
Additional benefit: I can generate an OTP for any service protected like this without having to get my phone from wherever it is.
Honestly.... This is why I have everything in Bitwarden. All 2FA runs through it so even if my phone got stolen, I could still access everything. I honestly don't understand why more people don't pay the $10 a year and just use Bitwarden.
Having your passwords and 2FA with the same provider carries some risk. If someone can access your Bitwarden account they will have full access to all your accounts.
What's your plan when you lose access to Bitwarden?
What happens when your Bitwarden gets compromised?
I hope that isn't true, because I sure can't think of a good way to use Bitwarden's TOTP as 2FA for Bitwarden! :)
FIDO2 USB Security key -> Bitwarden (With master password) -> Every other 2FA method
I have 3 FIDO2 USB Security keys, One I carry with my persons at all times, one that stays with my main machine at all times and an offsite backup that is sitting in a friend's server, if my house burns down, I can either physically collect the key or use USB-IP to authenticate back into bitwarden and enroll a new key. (Actually all 3 are at home right now but that's ok)
My phone is logged into Bitwarden so even then I can recover my passwords and data in case of a serious incident immediately.
Even if both my house and my friend's house burn down at the same time, I can still recover my data from my phone unless my phone is left in the house, all of which to say I still have the recovery phrase written down in a box somewhere in a different country
It's a good reminder to everyone who uses 2FA. Be sure you have multiple ways in for when your phone becomes unusable.
Yeah I lost my phone some months ago. Quite the panick because I am also MS365 admin for 2 orgs... 3 hr later a trucker called my wife using the iPhone emergency contact feature (what a hero). Now I bought an iPad that stays at home and has all the apps. Honestly, I should also put a second phone somewhere else.
Also frees me up to experiment a bit more on the Phone side (just got a Pixel 10 with GrapheneOS), although, so far it all just works (with Google Services of course).
It's annoying that you really do need either Android or iOS nowadays. If only we could virtualize one of those platforms properly (and free as in freedomly).
This is why my self-hosted Vaultwarden is my one password that I have to remember and requires no 2fa, which is the only important account that doesn't have 2fa.
If I wake up in a bathtub missing a kidney I can still get to my passwords and 2fa sources stored with it. Some accounts require SMS (annoyingly) so I'd have to buy a phone but the auth and credit card numbers I need to do that are in Vaultwarden, too.
I don't have good solutions now for OP (other than buy a new phone through your carrier and transfer the number). But everyone else do think through your personal DRP. Generate backup codes and put them somewhere safe, too.
Welll yeh until a Hargrove fails on your self hosted server
One of my favorite things about self-hosted Vaultwarden is that you get distributed backups for free. Every client keeps an offline copy of your entire password vault, kept in sync when the client is online.
So for me to lose my vault, not only would my server have to get hit by a bus, but also my phone, my desktop, my HTPC, both laptops...
Have a look at: https://github.com/muquit/twofa-rescue
You can add a passkey (preferably a physical one) to authenticate. You can also add a software passkey but that kind of defeats the purpose.
Actually keeping your recovery options recent is the trick. Print out your recovery codes or store them somewhere safe. Check regularly (yearly, maybe more often) that there's a way to access your critical accounts.
For Google, you can also grab the cheapest Android phone you can find, sign in, and maybe boot it once a month or so to keep the tokens active.
If you've set up your account to only accept one source of 2FA and you lose thst source of 2FA, you lose your account. Same happens when you set up your account to only accept your password and then lose your password. If you lose your recovery email/2FA backup codes, you lose access, unless you're special enough to convince customer support that you are who you claim you are and not just a bot trying to hack you.
If you've lost your account and haven't set up any recovery mechanisms, you're probably out of luck. Your best bet will be looking for an old browser session with enough trust from Google's side to get access without reconfirming your 2FA trust.
Yup, having _two_ active devices which are logged in to Google (and possibly other services that you rely on that opt you in to app-based 2FA) + with backups of 2FA is a must at this point. When I buy a new phone, I make it a "primary", and keep my old phone as "backup".
If you're not into cloud-based password/2FA syncing, Google Authenticator supports local export/import across devices via a QR code. For passwords, I use KeePass Portable / Keepass2Android + syncing between devices from time to time through a USB-C pendrive (The source of truth KP DB is on pendrive, and both phones work off a local on-device cache).
You don't need to have your phone stolen for things to get messed up. If your screen breaks, you can't type in a PIN anymore, can't unblock with a fingerprint, and you effectively can't access anything on the phone. ADB won't connect because screen is off, and you can't unlock / accept a new external connection etc.
Sadly this is why I never end up trading in my phone. Always feels too risky to not have an overlap period.
can you recover one of the old contact points (phone or email) for a reset code?
I would send a paper letter to the Google legal contact. It's the only way to get escalated support.
I agree the covenant for account recovery has been broken. Every 6 months, a new artifact is expected to access the account, without adequate preparation for the recovery.
All those times you logged in and were prompted to verify your backup email address, and when you set up 2FA and were given recovery codes, and when given the option to sync 2FA codes to another copy of the authenticator app: This Is Why.
I'm sorry you're dealing with this - hopefully everyone else here can take it as a cautionary tale.
This happened to me on my iPhone 8 many years ago. I reset it to let my son use it, and did not have google authenticator in mind. I had to reset each account with the providers. Now I use a cloud account to sync these. I reset most accounts with an SMS or email one time code -- which led me to remove SMS and email as recovery options from google. And, I put a code on t-mobile to prevent sim transfer.
I'll fill out a "help my friend" form internally unless someone beats me to it (I have a 1hr meeting coming up). The gmail address in question is the same one as on your website?
That's nice of you, but I'd urge anyone with influence at Google to consider 1) many many many more people who use Google services probably don't know or run in the same circles as Googlers who can bail them out of such a scenario, and 2) these people, being much less likely to understand 2FA, are also more likely to accidentally lock themselves out. An separate class of people who know how a system works or have connections to its operators become nose blind to its terrible UX because they have access to workarounds.
All true, but I’m guessing the set of people at Google who can fill out that form is about 1000x larger than the ones who have the ability to influence the underlying product decisions that led to this situation.
Consider the fact that they have made this difficult a sign that they have no interest in making it easy.
Sorry to bother, but I have been without access to the account I use for my YouTube channel for months because I stupidly entered a random phone number many years ago and it is now demanding access to it. If you would be willing to fill out that form for me, I would greatly appreciate it. Account is this username at gmail. Thanks!
Did you try going through the normal account recovery procedure? During that procedure, did you have to provide an alternative email address that you have access to?
The account recovery procedure only asks for the last password I remember (which I know is correct) and then says "You can’t recover your account at this time because Google doesn’t have enough info to be sure this account is yours."
I know the email, password, (wrong) phone number on file, and associated YouTube channel. I am logging in from a different IP address but on the same ASN and approximate geolocation that I always logged in and used the account from.
"Try another way" until you can give an alternative email address that you have access to.
I have tried all combinations of entering password, entering the phone number, try another way, etc., and it never lets me enter an alternative email address.
I have to click "Try another way" at least twice on g.co/AccountRecoveryRequest to get the option to provide an alternative contact email address. Maybe try a private session to make sure coookies aren't taken into account.
Recovery is similar to leaving a copy of your door keys to a trusted neighbour (a tradition in some places, it comes in handy when someone goes out and realizes they forgot the keys inside...), so in that comparison, having a recovery email unused for 12 years feels like leaving your backup keys to a neighbor that you never saw ever again in more than a decade.
This kind of posts are a valuable trigger for all others who are reading it. To the author: good luck, I hope you sort your situation soon! I'm now headed to check my accounts for what recovery options I left in there.
Well that’s why you should have software 2FA and even backing up the tokens so you can generate that one time code even if you lost access to your main authenticator, having your phone as the only 2FA is like having those yubikey hardware used as 2FA without making a redundant one, losing it, you lost access, which is usually known since no one would use yubikey without being tech savvy to start with, now google or other companies are turning phones as an attestation method for the crowd, you might soon in the future become citizen-less because your digital ID can only be proven in the lost phone.
While we are on this, is there a comprehensive guide on how to "theft-proof" your iPhone? Not in the sense of preventing the theft, but rather the fallout on all our various online service access.
Using the iPhone backup to setup a new phone is a good reminder every time that not half of the stuff comes back correctly..
I'm not sure you'd really need a guide. Just use the phone as a phone and pretend like it isn't a smartphone. Suddenly you are teleported back into 2005: physical credit cards, physical transit passes, online banking via a desktop website. It is still up to you what era you decide to live in technologically today.
The passkey I use for Google syncs to multiple devices, so that's how I handle it. That and a backup code stored in a separate location.
it's too late now but there's an app called Google Authenticator that you could have setup on alternate android devices
your only hope to get your google account back is to convince your phone carrier to transfer your old phone number to a new phone that you control
I've had this issue before, and the only thing that saved me was SMS (phone number) backup. I believe Google is slightly easier than Meta to contact by phone so this should help.
I had similar issues: https://news.ycombinator.com/item?id=45451567 (including my personal domain, Dropbox; my Apple account is still MIA...)
We've all been reduced to a passphrase.
When I've lobbed this scenario to the security managers/employees at these companies, they all give me a really great answer:
Q: What happens if a sitting senator gets mugged and they have their printed 2fa codes sitting in their wallet?
A: They have a special number they can call.
After they go get a second phone
I had some experience similar to this and found that after some months, when logging in on an extremely familiar to Google setup, that there was an additional prompt where it asked for some old passwords IIRC and then let me in.
Too late for you now, but I set my backup email to my work email. Granted, I have to change it when I change jobs.
I mistakenly changed my phone number due to spam call, then i tried to login Google account in another device. Now, this fucking google don't allow me to login at all. It keep saying "Google can't verify you". I have accepted prompts, given them passkeys from 1password, have recovery code and everything. But no lock. I am now scared if my google account gets logged out, i will be in very problematic situation.
Google Employee, can you please fix your shit? Losing phone number doesn't mean you have to lose everything....
call sergey brin \s
Dumb question, does backing up my iphone to icloud help solve this? Assuming im willing and able to get a brand new phone? What 2fa would the Apple store need, if hypothetically my lost iphone was my only apple product?
It's not a dumb question, but there isn't any single answer. It depends on what protections you have on your iCloud account. For most users, if you've lost your phone, but remember your iCloud password and have a new phone with the same number, you can get in. It's made even easier if you have another device already signed in, such as a laptop.
Luckily I do have a macbook, and try to put all my passwords in a "neutral" password manager, but this post has made me think about the edge cases of this sort of thing.
Ive always said, the number one reason I will stick with an iphone - despite any present for future dumb ux changes - is that I will always be able to physically go to an apple store and get someone to help me.
honestly a piece of paper that has your password without saying it is your password and use that password for your most important thing (email) or password manager
It's a "feature" that you can't call google to help with getting "locked out":
"For your security, you can't call Google for help to sign into your account. We don’t work with any service that claims to provide account or password support. Do not give out your passwords or verification codes."
for the future: https://support.google.com/accounts/answer/7684753
Doesn't help obviously if you already lost your phone, but I recommend anyone to use a third party authenticator app. Most services offer to scan a QR code to set up MFA, which can easily be backed up. Don't use Google/Microsoft authenticator apps directly. Personally I use Stratum, but any that allows export/import will do.
This. Authy and a throwaway phone added in that sits in a safe place.
This situation is why I don't use authenticator apps, or passkeys linked to a device. Single point of failure, and obviously with any of the big tech companies, zero recourse.
I think many services allow you to set up more than one passkey for this reason.
I can't help you but my comment may help others...
As a techie you should have known better: you first learn how 2FA using TOTP works. You understand what happens when you create an entry in Google Authenticator (or whatever app). You reproduce the procedure: you verify that you end up with the same 6-digit numbers.
If you've got a partner, you register your secret keys for each service on your partner's device and vice-versa.
Then you've got backups of your secret keys on paper, in a safe at your bank. Next to each secret key there's a checkbox: "Successfully initialized from this secret key?".
When those TOTP became ubiquitous (way, way, way before Yubikeys or passkeys were a thing), 2FA was a godsend compared to just passwords.
I understood they were here to stay for years, and years. And then more years.
So I learned how they worked.
When later on QR code generalized to initialize those (IIRC it wasn't a thing in the early days of 2FA TOTP: you'd just always get the secret key as characters, not as a QR code), I refused to ever scan a QR code: I always first decode the QR code (for the services only showing the secret key as a QR code, without also showing it as text), extract a copy of the secret key and then register it from my copy.
Stuff like that.
Now... As most services are deeply broken and have completely insecure practices you just say "I lost my 2FA, I want to reset it" and because they're clueless when it comes to security, they'll allow you to reset it. If someone hacks your email, they pretty much can reset every single of your account (at least those tied to that email).