Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Fujitsu launches made-in-Japan next-generation CPU FUJITSU-MONAKA(global.fujitsu ↗)
    129comments
  2. Rate limits on GitLab.com are changing(about.gitlab.com ↗)
    61comments
  3. Whoisinspace.com/(whoisinspace.com ↗)
    22comments
  4. CrowdSec Source Code Leak(crowdsec.net ↗)
    19comments
  5. hister(github.com/asciimoo ↗)
    4comments
  6. Launch HN: Skillsync (YC W26) – AI chat sessions made portable across agents
    3comments
  7. Zettascale (YC S24) Is Hiring ASIC/FPGA Engineers to Build Chips for ASI(zscc.ai ↗)
    discuss
  8. One Year of Sponsored Servo Development(servo.org ↗)
    124comments
  9. Grand MS-DOS Gaming General MIDI Showdown(johnnovak.net ↗)
    discuss
  10. How GLM built its own inference infrastructure(z.ai ↗)
    210comments
  11. Why I didn’t sign the Fields medallists’ letter(gowers.wordpress.com ↗)
    103comments
  12. Show HN: Share your AI Setup, Learn from others(mysetup.ai ↗)
    41comments
  13. CCC invites all model citizens to 40C3(ccc.de ↗)
    85comments
  14. LLM Classification Is Feature Engineering(minimallysufficient.com ↗)
    10comments
  15. The American Religion of Self-Storage Facilities(newyorker.com ↗)
    115comments
  16. The Return of Sail Power: Cargo Ships Are Turning Back to the Wind(gcaptain.com ↗)
    88comments
  17. Mastering Layout Engines in Graphviz: Dot vs. Neato vs. Twopi vs. Circo(visual-paradigm.com ↗)
    3comments
  18. Show HN: Aclif – Agent CLI framework: one grammar, canonical names across SaaS(aclif.ai ↗)
    1comments
  19. Running Ubuntu on the Lenovo IdeaPad Duet(vhaudiquet.fr ↗)
    discuss
  20. Artificial intelligence now beats some of the best human forecasters(economist.com ↗)
    54comments
  21. Show HN: I built a new version of my fun spatial 3D online meeting app(flat.social ↗)
    49comments
  22. Vinix – A modern operating system written in V(vinix-os.org ↗)
    23comments
  23. My temporary PHP fix from 2014 has nearly 20M installs. Today I'm deprecating it(jakeasmith.com ↗)
    76comments
  24. Ask HN: How to recover Google auth after phone stolen?
    27comments
  25. Show HN: AutoBot – live voice control for long-running AI work(github.com/demeyer1 ↗)
    discuss
  26. The Relation Between Mathematics and Physics by Paul Dirac (1939)(cam.ac.uk ↗)
    44comments
  27. Keys Not Included: recovering the signing keys for US driver's license barcodes(ryan.science ↗)
    137comments
  28. Better Vector Search for Long Documents: Chunking Inside Manticore Search(manticoresearch.com ↗)
    11comments
  29. Lucasart's Afterlife(togameforlife.wordpress.com ↗)
    41comments
  30. Nvidia announces native GPU programming in Rust(nvidia.com ↗)
    354comments

Ask HN: How to recover Google auth after phone stolen?

36 pointsby 1h ago
27 comments
As we know, google has been effective at automating a lot of their systems, to the point where it can feel like there isn't any help available from a human. So what is supposed to be the plan when this type of situation happens?

Basically I have a situation that after my phone was stolen, I can't get into any of my accounts that are either connected to google, or connected to the phone via 2FA. This has made it complicated/impossible not only to get info about my phone, but also my banking, email, drive, etc.

Of course they offer you "multiple options" to recover an account, but not if you forgot your old email's password. At that point the options you get are,

  a) Use old phone (obviously the phone is long gone)
  b) Use current phone (the phone is gone)
  c) Use old email (I haven't used it in like 12 years)
Does anyone know if their is a process to appeal 2FA or anything to deal with this type of situation?

I'd imagine that this has happened to people many many times, and given how phones and particularly, google auth have become so critical to accomplishing essential tasks within society, there must be some way. Or maybe it's just like, once your phone is gone, you are completely over with society? If anyone has any experience with this or inside knowledge please share it!

I'm sure people here have heard of this, and maybe experienced it themselves.

Is there a secret option that exists that allows us to use passwords instead of rigamarole? I would love an account that let me simply log in with a password, like google used to be.

1h agoHN ↗

The only secret option I know of is to have a popular social media account and complain online.

Other than that, I copy/pasted your post into Claude and it had some good ideas.

1h agoHN ↗

need to save your recovery keys (text file) before you lost the phone

1h agoHN ↗

There's no way, no human contact. That's why I de-googled myself.

1h agoHN ↗

No human contact is a plus for security, as the human is the weakest link that can give up your authentication to someone that isn’t you.

52m agoHN ↗

"I am permanently locked out of my account with no recourse" is also a security issue.

29m agoHN ↗

The human factor is walking into your local branch with your face and an ID - something that can’t be done on a large scale by bots.

1h agoHN ↗

If you don't have the authenticator backup codes and you didn't turn on cloud sync in the app, you might be out of luck.

You can get a replacement SIM though and use it with a new phone, so the phone number recovery option should work.

1h agoHN ↗

This. Can't you get your number moved to a new phone? I have never don't anything magic when upgrading my phone other than move contacts.

1h agoHN ↗

You were supposed to save your backup codes.

1h agoHN ↗

Isn't there an SMS option? buy a new phone and have them send you an OTP via SMS.

once you're phone is gone, you are completely over with society?

yes, I'm waiting for the Black-Mirror episode where someone drops their phone and basically dies, can't contact anyone, can't unlock or start their car, can't get an uber, can't pay for anything, can't navigate without gps, can't log into anything etc.

42m agoHN ↗

Pretty similar to how my life feels right now.

1h agoHN ↗

The same way you recover any other deleted data for which you didn't make a backup: you don't. You eat the loss & make new accounts. Then you remember to make and test backups for the future.

Even if they had customer support, if that customer support had a backdoor to unlock your account it would be regularly used by malicious parties to steal people's accounts & data.

51m agoHN ↗

Everything you listed, plus a recovery email option, plus backup codes, plus SMS.

That's already a lot and anything easier would allow people to just take over accounts that they don't have a right to.

49m agoHN ↗

You're going to have more success working with the providers of the other accounts and services rather than Google. That means a lot more legwork on your part but banks and other online services all have processes to deal with lost passwords and 2FA devices. In some cases you may have to physically go somewhere with ID and other documents.

Consider it a learning experience.

44m agoHN ↗

Going forward, consider using an authenticator that securely syncs across multiple devices to remove the single point of failure risk.

I use Proton Authenticator now [0]

Authy used to do this, then they enshittified their app and bricked the desktop version.

[0]: https://proton.me/authenticator

36m agoHN ↗

Google authenticator supports syncing across multiple devices.

10m agoHN ↗

is that new? I migrated at the time from GA to Authy and from Authy to Ente because it was not supported.

43m agoHN ↗

Does your browser have the email password saved?

41m agoHN ↗

Man, passwords sure are nice aren't they! All you have to do is remember one because your password manager remembers all the rest of your randomly generated passwords for you and as long as you keep a backup of the password database you never have to worry about this bullshit.

27m agoHN ↗

Honestly.... This is why I have everything in Bitwarden. All 2FA runs through it so even if my phone got stolen, I could still access everything. I honestly don't understand why more people don't pay the $10 a year and just use Bitwarden.

15m agoHN ↗

Having your passwords and 2FA with the same provider carries some risk. If someone can access your Bitwarden account they will have full access to all your accounts.

16m agoHN ↗

It's a good reminder to everyone who uses 2FA. Be sure you have multiple ways in for when your phone becomes unusable.

12m agoHN ↗

This is why my self-hosted Vaultwarden is my one password that I have to remember and requires no 2fa, which is the only important account that doesn't have 2fa.

If I wake up in a bathtub missing a kidney I can still get to my passwords and 2fa sources stored with it. Some accounts require SMS (annoyingly) so I'd have to buy a phone but the auth and credit card numbers I need to do that are in Vaultwarden, too.

I don't have good solutions now for OP (other than buy a new phone through your carrier and transfer the number). But everyone else do think through your personal DRP. Generate backup codes and put them somewhere safe, too.

6m agoHN ↗

You can add a passkey (preferably a physical one) to authenticate. You can also add a software passkey but that kind of defeats the purpose.

Actually keeping your recovery options recent is the trick. Print out your recovery codes or store them somewhere safe. Check regularly (yearly, maybe more often) that there's a way to access your critical accounts.

For Google, you can also grab the cheapest Android phone you can find, sign in, and maybe boot it once a month or so to keep the tokens active.

If you've set up your account to only accept one source of 2FA and you lose thst source of 2FA, you lose your account. Same happens when you set up your account to only accept your password and then lose your password. If you lose your recovery email/2FA backup codes, you lose access, unless you're special enough to convince customer support that you are who you claim you are and not just a bot trying to hack you.

If you've lost your account and haven't set up any recovery mechanisms, you're probably out of luck. Your best bet will be looking for an old browser session with enough trust from Google's side to get access without reconfirming your 2FA trust.