General EditionThe Daily StandardNo sponsors, no sales pitch

Clear reporting on the choices people actually face.

Technology

Set up account recovery before you need it, in about forty minutes

Losing a phone should be an inconvenience. For most households it is a lockout, because every route back into an account runs through the device that is gone.

A desk drawer open to show a small hardware security key, a folded printed sheet and a spare phone lying beside a notebook
A desk drawer open to show a small hardware security key, a folded printed sheet and a spare phone lying beside a notebook

Work out what happens if your phone disappears tonight. For most people the answer is that the authenticator app is gone, the text messages that would verify a login go to a dead number, and the email account that could reset everything else needs a code from the phone.

That is a circle, and the way out of it is built in advance or not at all. Forty minutes, in this order.

Start with the account everything else runs through

Your primary email is the master key. Password resets for the bank, the utilities, the insurer and the pharmacy all land there, so anyone who controls it controls the rest, and anyone locked out of it is locked out of the rest.

Do this one first and do it properly. The other accounts are easier once it is solved, and several of them are solved by it.

Generate and print the recovery codes

Every major provider offers a set of one-time backup codes, usually ten of them, buried a level or two into security settings. Generate them, print them, and store the paper where your household keeps documents.

These are the single most useful item in this piece. They work without a phone, without a network, and without anyone else's cooperation. They are also the thing nobody has when they need one, because generating them requires being logged in, which is precisely what you cannot do.

Do it for email, for the password manager, and for the bank if it offers them.

Register a second factor that is not the phone

One device is a single point of failure. Add a second one.

The options, roughly in order of robustness: a hardware security key kept in a drawer, a second device with the authenticator app installed, or an authenticator that syncs across devices. Any of them beats having everything on one handset.

Where you can, move away from text messages as the primary second factor. A number can be ported away from you by someone who convinces a carrier they are you, and that attack is aimed at exactly the accounts you care about. Text is still better than nothing, and it should not be the only thing.

Fix the recovery contacts, which are usually stale

Most accounts hold a recovery email address and a recovery phone number, set years ago. Open the security page and read them.

Common findings: a work address from a job you left, a phone number you gave up, an email account you no longer check that is itself protected by a password you have forgotten. Any of those turns a recovery attempt into a dead end.

Set the recovery email to an account you control and actually monitor, and make sure that one has its own recovery configured. Otherwise you have built a chain that fails at the weakest link.

Set up the access somebody else may need

The part people skip because it is uncomfortable, and the part with the largest consequences.

If you are in the hospital for three weeks, someone has to pay the mortgage, tell the insurer, and answer the utility. If you die, an executor has to close accounts they cannot see. Neither of those goes well when the entire household's digital life is behind one person's fingerprint.

Several providers now offer a legacy or trusted contact feature, which lets a nominated person request access after a waiting period. Password managers commonly offer emergency access on the same model. Turn both on where they exist.

Then write the paper document that covers everything they do not: which email is the main one, where the recovery codes are kept, which password manager is in use, and where the master password can be found in an emergency. Seal it, tell one trusted person that it exists and where, and note that a will becomes a public document in probate, which is a reason to reference the location rather than write the passwords into it.

Test one of them

Pick a single account and try to log in from a device you do not normally use, without your phone in the room. Use a recovery code.

Fifteen minutes, and it will find the gap. The most common one is an account where the second factor works fine but the recovery route was never configured, so a code arrives at an address nobody has opened since 2019.

Write down which accounts matter

Not all of them. Most households have dozens of logins and perhaps eight that would cause real trouble.

The usual list is the primary email, the bank, any brokerage or retirement account, the mortgage or landlord portal, the insurer, the utility that has autopay attached, the phone carrier, and the password manager itself. The phone carrier belongs on it for a reason that is not obvious: control of the number is what an attacker wants, and a carrier account with a separate PIN on it is much harder to move.

Work through that list once with the steps above, then stop. A recovery plan that covers eight accounts and exists beats a comprehensive one that was abandoned in the middle.

What this is worth over a few years

Almost every part of it is free. The hardware key is the only purchase, it costs less than a month of most streaming subscriptions, and it lasts for years.

Set that against the alternative. Being locked out of a primary email account is not a support ticket, it is weeks of identity verification with an uncertain outcome, during which the accounts that reset through it are also unreachable. Households that go through it describe the same thing: the problem was never the password, it was that every road back went through a device sitting at the bottom of a lake.

Put a reminder in the calendar for two years out to check the recovery contacts again. Phone numbers and email addresses change, and a recovery plan is only as current as the last time somebody read it.