Page 1 of 1

Will your account be accessible when life happens?

Posted: Wed Oct 19, 2022 8:23 am
by Sarah Manter
Dropped your phone in the toilet? (More of us have done it than care to admit it.) Were all of your 2fa codes on there? Do you have an authenticator with backup codes so you can recover them? Double check to keep your account secure and accessible, even when life happens.

Image

Re: Will your account be accessible when life happens?

Posted: Wed Oct 19, 2022 8:36 pm
by Kaffiend
I highly recommend goggle authenticator app. Recently (Sept 1) at 1AM I had someone call my mobile provider and convince them that they were me. Told them they lost their phone but had a new one and a sim card already in hand. My mobile provider proceeded to complete a SIM Swap. They deactivate my phone and activate their new one. Now that they had full control of my phone number and text they went to email account hit forgot password and they sent 6 digit code to their phone to unlock my email. Then from there right to coinbase and changed my password. Same to Microsoft account. and a couple others. I caught it about 30 minutes into the ordeal. I started locking out accounts and changing passwords. The only saving grace for my coinbase and crypto accounts was the fact that I used the google authenticator app. They may have had full control of my phone number and were getting all my text messages but they couldnt gain access to accounts without having the authenticator on their device.
As Sarah says you MUST have it backed up/ on a second device though. If your primary device is lost/damaged/stolen and you cannot get your codes anymore you have lost access to your accounts as well.

Re: Will your account be accessible when life happens?

Posted: Thu Oct 20, 2022 7:20 am
by Sarah Manter
Kaffiend wrote: Wed Oct 19, 2022 8:36 pm I highly recommend goggle authenticator app. Recently (Sept 1) at 1AM I had someone call my mobile provider and convince them that they were me. Told them they lost their phone but had a new one and a sim card already in hand. My mobile provider proceeded to complete a SIM Swap. They deactivate my phone and activate their new one. Now that they had full control of my phone number and text they went to email account hit forgot password and they sent 6 digit code to their phone to unlock my email. Then from there right to coinbase and changed my password. Same to Microsoft account. and a couple others. I caught it about 30 minutes into the ordeal. I started locking out accounts and changing passwords. The only saving grace for my coinbase and crypto accounts was the fact that I used the google authenticator app. They may have had full control of my phone number and were getting all my text messages but they couldnt gain access to accounts without having the authenticator on their device.
As Sarah says you MUST have it backed up/ on a second device though. If your primary device is lost/damaged/stolen and you cannot get your codes anymore you have lost access to your accounts as well.
That's awful! I'm so sorry that happened to you! I'm glad you had 2fa set up on those accounts to prevent further damage. The issue tends to be when people use Google Authenticator without setting up backup codes first, The largest number of 2fa tickets we receive are from people using Google Authenticator because they have no backup to recover their codes and get locked out of their accounts. Unfortunately, we cannot reset them because the point of them is to prevent things like what happened to you. Your story is a great example of why we don't simply reset accounts when codes are lost.