Recommended Posts

Really just one, but first let me take you back to the biggest mistake of my life. I ended up getting a new cellphone number and SIM card a while back and for some reason decided to do a factory restore on my phone and of course totally forgetting to change the phone number associated with my 2FA app. To make a long story short I'm pretty much locked out of a lot of accounts... I will say that I take full responsibility for this mistake and it was completely my bad. So for my question. Why is getting some of these accounts back as easy as sending an email, maybe with a copy of some official identification, to get your account back while others tell you that it's completely impossible for them to get your account back? Google is the big one that's making me lose my mind. I can't even get a hold of a actual person that works there, I even have a Google Play subscription that I'm still being charged attached to this account I can't use...

Link to comment
https://www.neowin.net/forum/topic/1404949-questions-about-2fa/
Share on other sites

Because some are more secure than others.  My Protonmail account is locked and remains locked I lose 2FA access. The only recourse is a recovery code. Most "unrecoverable" 2FA models give you a collection of recovery codes in the event you lose access.

 

 

  • Like 1
21 minutes ago, adrynalyne said:

Because some are more secure than others.  My Protonmail account is locked and remains locked I lose 2FA access. The only recourse is a recovery code. Most "unrecoverable" 2FA models give you a collection of recovery codes in the event you lose access.

 

 

So is it safe to assume I'll be spending almost six dollars a month for the rest of my life with this Play subscription I can't use? I really can't stress enough I've tried to get a hold of Google to no avail about this...

1 minute ago, SyntheticVirusZ said:

So is it safe to assume I'll be spending almost six dollars a month for the rest of my life with this Play subscription I can't use? I really can't stress enough I've tried to get a hold of Google to no avail about this...

No, of course not. Contact the company if its something you pay for. They will have a way to disable 2FA.

I can relate how much contacting Google sucks.  Its an exercise in futility.

Maybe someone already has your old number. Try calling it and see if they pick up. if they do tell them a code will be sent to their phone and see if they will pass it on to you.

 

Years  ago  (7 or 8 ) I did the same sort of thing you did. I was using Google authenticator on an iPod touch. Had my PayPal 2FA setup on it. without thinking, I factor reset the iPod Touch. I was then locked out my PayPal account. It's been so long ago I can't remember how i finally got back in or if I just created a new account.

 

In the future, use an authenticator app, and save a copy of the QR code you scan into authenticator. Put it on a USB flash drive and print it off if possible. Also add to every device you own. If you get a new phone just reinstall the authenticator app and rescan the saved QR code, BAM! Back in business. That's what I do.

 

There are services like Authy, but I just don't want all my two-factor codes all in one place online.

too bad, nothing can help you now.

 

create 2fa backup with a passwd and keep it on $5 usb stick from walmart

38 minutes ago, adrynalyne said:

No, of course not. Contact the company if its something you pay for. They will have a way to disable 2FA.

I can relate how much contacting Google sucks.  Its an exercise in futility.

Truly insane... And I totally get how they want to write satiations like this off since I'm sure it happens a thousand times a month, but to go so far out of their way to make it so their users can't contact them about it is a little irresponsible.

16 minutes ago, warwagon said:

Maybe someone already has your old number. Try calling it and see if they pick up. if they do tell them a code will be sent to their phone and see if they will pass it on to you.

 

Years  ago  (7 or 8 ) I did the same sort of thing you did. I was using Google authenticator on an iPod touch. Had my PayPal 2FA setup on it. without thinking, I factor reset the iPod Touch. I was then locked out my PayPal account. It's been so long ago I can't remember how i finally got back in or if I just created a new account.

 

In the future, use an authenticator app, and save a copy of the QR code you scan into authenticator. Put it on a USB flash drive and print it off if possible. Also add to every device you own. If you get a new phone just reinstall the authenticator app and rescan the saved QR code, BAM! Back in business. That's what I do.

 

There are services like Authy, but I just don't want all my two-factor codes all in one place online.

I was using Authy, but get this, I had the password to Authy saved in my password manager, that was also protected by 2FA using Authy... And I knew I needed to print off those backup codes but like the fool I was being I didn't...

13 minutes ago, Marujan said:

too bad, nothing can help you now.

 

create 2fa backup with a passwd and keep it on $5 usb stick from walmart

I mean... I have gotten most of the accounts recovered so I feel it's hard to say nothing can help me now... But yeah, I know I need to get those backup codes printed off next time. 

32 minutes ago, SyntheticVirusZ said:

But yeah, I know I need to get those backup codes printed off next time. 

This for sure.. Also - fan of authy.. Which allows you to sync devices with your 2fa.. So I have it on my phone, I have them on my ipad and also have the app running on my pc.  So worse case if I lost my phone with the app on it, or walked into the ocean with it in my pocket of my swim trunks ( I have done this!! )..

 

You can turn off the ability to add devices to the sync, etc.. so you only need to enable it when you want to add a new device.  Makes it real easy to get new phone up and running with your 2fa app that is for sure.

 

I like having it on my PC - so if the phone is in the kitchen and need to auth to something, I don't have to go get my phone ;)

40 minutes ago, SyntheticVirusZ said:

I was using Authy, but get this, I had the password to Authy saved in my password manager, that was also protected by 2FA using Authy... And I knew I needed to print off those backup codes but like the fool I was being I didn't...

This is why I never have and probably never will use Authy, because the thought of getting locked out of Authy (for whatever reason) and in turn getting locked out of all my 2 factor codes and being royally F*cked, scare(s) the Sh*t out of me.

 

So I have just always used authenticator and printed off the QR codes and saved the QR codes to two sperate USB flash drives and two disconnected hard drives (1 USB Flash drive and 1 HDD in a safety deposit box) and added all authenticator codes to 3 devices.

How would you get locked out of authy - other than forgetting your password ;)  It also asks you to do your password now and then, for example if you have it open with face, or fingerprint - so you don't forget it ;) heheh

 

Also you would have such passwords written down somewhere, on a piece of paper where you keep all your other important docs..

 

Forgetting your password - can lock you out of many things.  Not just authy ;)

11 minutes ago, BudMan said:

This for sure.. Also - fan of authy.. Which allows you to sync devices with your 2fa.. So I have it on my phone, I have them on my ipad and also have the app running on my pc.  So worse case if I lost my phone with the app on it, or walked into the ocean with it in my pocket of my swim trunks ( I have done this!! )..

 

You can turn off the ability to add devices to the sync, etc.. so you only need to enable it when you want to add a new device.  Makes it real easy to get new phone up and running with your 2fa app that is for sure.

 

I like having it on my PC - so if the phone is in the kitchen and need to auth to something, I don't have to go get my phone ;)

 

4 minutes ago, BudMan said:

How would you get locked out of authy - other than forgetting your password ;)  It also asks you to do your password now and then, for example if you have it open with face, or fingerprint - so you don't forget it ;) heheh

 

Also you would have such passwords written down somewhere, on a piece of paper where you keep all your other important docs..

 

Forgetting your password - can lock you out of many things.  Not just authy ;)

I do like the fact Authy can be installed on just about everything, wish I had it installed on everything before this happened. As for my passwords, all are pretty easy to forget since I randomly generate them. Most are twenty characters long of letters, numbers, and symbols.

9 minutes ago, warwagon said:

This is why I never have and probably never will use Authy, because the thought of getting locked out of Authy (for whatever reason) and in turn getting locked out of all my 2 factor codes and being royally F*cked, scare(s) the Sh*t out of me.

 

So I have just always used authenticator and printed off the QR codes and saved the QR codes to two sperate USB flash drives and two disconnected hard drives (1 USB Flash drive and 1 HDD in a safety deposit box) and added all authenticator codes to 3 devices.

I mean all in all this is a lesson learned in life for myself. Don't be lazy and get those backup codes writing down! Well, I guess back to the grind working on these accounts...

5 hours ago, Superuser said:

I wonder if should even be using my cell number for my Authy account and instead be using a number have via MySudo that use for Signal and Telegram.

I would give yourself as many backup methods as possible, take it from me who's just learned the hard way.

When possible, I tend to avoid 2FA that uses text messaging and go for something like Authenticator and WinAuth. When I don't have a choice, I run 2FA through Google Voice instead of my cell. Google itself is going through authenticator and WinAuth so I won't be locked out of Google if I don't have my cell.

My passwords live in KeePass, which is also 2FA, but in that case the second factor is a keyfile that never goes online, while the database itself is on cloud storage. 

 

It's a system designed to reinforce security and add redundancy. I can lose my cell phone and cell phone account and still have 2FA working.  It's not perfect, but it's pretty good.

 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • XnConvert 1.112 by Razvan Serea  XnConvert is a cross-platform batch image-converter and resizer with a powerful and ease of use experience. All common picture and graphics formats are supported (i.e. JPG, PNG, TIFF, GIF, Camera RAW, JPEG2000, WebP, OpenEXR) as well as supporting over 500 other image formats. Also available within the batch operations include rotating, adding of watermarks, adding of text along with many image-adjustment features such as brightness, shadows and more. Among the features included are: Batch adding of files and folders Support for drag and drop of files Batch rotating, cropping, resizing and more Adding of photo masks Preserving or removing image metadata in conversions Multipage image file support (i.e animated GIF, APNG, TIFF) Command line integration via NConvert Filters - such as 'Blur', 'Gaussian Blur', 'Emboss', "Sharpen' and much more Effects - such as 'Old camera' and much more Download: XnConvert 64-bit | Standalone | ~30.0 MB (Freeware) Download: XnConvert 32-bit | Standalone Links: XnConvert Website | Screenshot | Release Announcement Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Microsoft updates Visual Studio Code with chat cost tracking and multi-agent chats by Paul Hill Microsoft has just launched Visual Studio Code 1.126, its latest weekly release. This time, the company has focused on letting you see the total cost of chat sessions to spot expensive conversations; enabling multiple chats per session that run side-by-side in one agent host Copilot session; and letting you browse new folders safely in restricted mode. We have now reached the stage where free AI in IDEs is coming to an end. To help you keep track of your costs, VS Code now lets you see the entire cost of a chat session, rather than just individual turns. This should give you more transparency about which sessions consume the most credits, so you can better manage your usage over time and spend less. For those of you using the Agents window, you know it is possible to run and manage multiple agent sessions at once. In this update, a Copilot session started from an agent host can hold several chats at once. Explaining how this feature works, Microsoft writes: Finally, from this update forward, Microsoft will remove the pop-up when opening an untrusted folder. When you open a new folder now, it will automatically open in Restricted Mode. You will see a banner that lets you manage the trust level of the folder. Microsoft has made this change so that it’s easier to start inspecting code without giving it trust right away. If you have VS Code, you can check for updates within the app now to get this new version. Otherwise, you can download it from the Visual Studio Code website.
    • Anthropic accuses Alibaba of using 25,000 fake accounts to copy Claude's capabilities by Karthik Mudaliar Anthropic has accused Alibaba of using nearly 25,000 fraudulent accounts to extract capabilities from Claude on a huge scale. According to a report from Reuters, Anthropic told US lawmakers that operators linked to Alibaba and the company’s Qwen AI team generated 28.8 million exchanges with Claude between April 22 and June 5, 2026. That is a lot of Claude conversations, but Anthropic says this was not ordinary chatbot use. The company believes the accounts were part of a coordinated effort to collect answers that could help train or improve rival AI systems. The alleged campaign reportedly focused on some of Claude’s most valuable skills, including software development, multi-step reasoning, and agentic tasks. In practical terms, that means getting an AI model to plan and complete work across several stages rather than simply answering a single question. This is called 'distillation,' where AI companies use outputs from a larger model to train a smaller and cheaper one. The smaller model learns to imitate useful parts of the more capable system without needing the same amount of computing power. The distillation process isn't automatically suspicious, but the problem comes when one company gathers another provider's outputs without permission and at an industrial scale. Also, this does not mean Alibaba obtained Claude’s source code, model weights, or original training data. Instead, Anthropic claims the accounts repeatedly asked Claude carefully designed questions and collected the answers. Those answers could then be used as training material for another model. Anthropic has made similar accusations against DeepSeek, Moonshot AI, and MiniMax earlier this year. As Neowin previously reported, Anthropic said those three companies collectively generated more than 16 million Claude exchanges through roughly 24,000 accounts. Anthropic says the new campaign produced almost twice as many exchanges in a matter of weeks. Anthropic reportedly told lawmakers that the campaign could help Chinese AI developers approach the capabilities of its Mythos Preview model. Mythos is focused on advanced cybersecurity work, including finding and exploiting complex software vulnerabilities. via Reuters | Photo via DepositPhotos.com
    • An Indian manufacturer that assembles roughly one-third of Apple's iPhones and supplies semiconductor components to Tesla confirmed Monday that attackers had stolen and publicly published a 630-gigabyte cache of confidential files — including engineering blueprints stamped "TRADE SECRET," a 52-page quality inspection document for iPhone circuit board components, and cryptographic certificates that security experts say could be weaponized in follow-on attacks. https://www.techtimes.com/articles/319019/20260624/apple-tesla-supplier-tata-electronics-confirms-630-gb-data-theft-iphone-specs-dark-web.htm
  • Recent Achievements

    • Rookie
      krychek57 went up a rank
      Rookie
    • Grand Master
      Jaybonaut went up a rank
      Grand Master
    • One Year In
      Philsl earned a badge
      One Year In
    • Dedicated
      Scoobystu earned a badge
      Dedicated
    • First Post
      Tom Schmidt earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      441
    2. 2
      +Edouard
      176
    3. 3
      PsYcHoKiLLa
      133
    4. 4
      Michael Scrip
      79
    5. 5
      Xenon
      77
  • Tell a friend

    Love Neowin? Tell a friend!