Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I know SMS is not 100% secure, but you can easily get SMS recovered if you lose your phone. How do you cover Authenticator if you lose your phone?

I always keep both.



You can easily set up Authy, for example, to be multi-device. Then hope that you don’t lose your computer, phone, and tablet simultaneously.


You can always back up the secret ID on, for example, a piece of paper, if you don’t want to use a TOTP app with sync/backups (there are several, both proprietary and FLOSS)


if using normal TOTP apps, print the QR code and store it somehwere secure. It’s a risk, but it’s one part of the puzzle needed and it reduces a more likely risk of being locked out.


Some sites give recovery codes that you have to store somewhere and that you should be able to use if you lose access to an Authenticator app.


Something about printed recovery codes makes me think of passwords on postit notes


There is absolutely nothing wrong with passwords on post-it notes as long as you secure them.

In fact, printed passwords in a physical safe is what you want to do for your "break the glass" accounts.


I keep them in my Bitwarden vault


Microsoft Authenticator and Authy both backup to the cloud. I also have a non-Microsoft email linked to receive 2FA codes, as well as 2 hardware security keys, and an account recovery code. I think I'm covered.


Microsoft Authenticator is one of the authentication apps that can backup online.


Like, what could possibly go wrong...




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: