General EditionThe Daily StandardNo sponsors, no sales pitch

Clear reporting on the choices people actually face.

Technology

Lost Your Phone? Every Route Back Into an Account Runs Through the Device That Is Gone

Losing a handset should be an inconvenience. For most households it is a lockout, because the recovery path and the lost device are the same thing.

A desk drawer open to show a small hardware security key, a folded printed sheet and a spare phone lying beside a notebook
A desk drawer open to show a small hardware security key, a folded printed sheet and a spare phone lying beside a notebook

Picture a desk drawer holding a small hardware key, a folded sheet of paper and a spare handset, and consider how few households have anything like it. For most people the phone in their pocket is the only key to everything: the second factor for the bank, the authenticator application, the number that receives the reset codes, and the mailbox those codes arrive in. Losing it should be an expensive inconvenience. Set up the ordinary way, it is a lockout, and the work required to prevent that takes about forty minutes on a quiet evening.

Why the Single Device Problem Is So Common

Nobody designs this arrangement deliberately. It accumulates, one sensible decision at a time, as each service is set up on the device that happens to be in hand and each recovery method defaults to the phone number or the email already on file. The result is a structure with no redundancy at all, in which the thing most likely to be lost, stolen or dropped in water is also the thing every recovery path depends on, and the dependency is invisible until the day it is tested.

It gets worse under the exact conditions where it matters. A phone lost while traveling takes the boarding pass, the banking application and the authenticator with it, and the recovery route requires a code sent to a number that is now in somebody else's possession or disconnected. The fix is not a different phone or a different service. It is making sure that at least one route into each important account does not pass through that device.

Starting With the Email Account, Because Everything Else Runs Through It

Email is the root of the tree, since almost every other account will send a reset link to it, which means the order of operations here is not arbitrary. Secure that account first with a second factor that is not a text message, generate its backup codes, and print them. Backup codes are the piece nearly everybody skips: a short list of one time strings that will get an account open when no device is available, offered during setup and dismissed by most people who assume they will not be needed.

Then check what the account's own recovery settings say, because they are frequently years out of date. An old phone number, a former work address, a secondary email nobody has opened since a previous job: any of these is either a dead end or a security hole, and both are worth clearing out. Adding a recovery method that survives losing the phone, such as a second email on a different provider, is what turns a lockout back into an inconvenience.

The Second Factor That Does Not Depend on One Object

Text message codes are better than nothing and are the weakest of the widely available options, both because they can be intercepted through a number being ported away and because they fail entirely when the number is unavailable. An authenticator application is stronger, and the version worth using is one that can be restored on a new device from an encrypted backup, since an authenticator with no backup recreates the single point of failure it was meant to remove.

Hardware security keys are the sturdiest option and are worth the modest cost for the two or three accounts that matter most, with the important detail being that they are bought in pairs. One stays on a keyring and one stays in a drawer at home, registered to the same accounts, so losing the first is a nuisance rather than an event. Most services that support keys allow several to be registered, and registering only one is the most common mistake made by people who have gone to the trouble of buying any.

The People and Papers That Sit Outside the System

Several services offer recovery through a trusted person, allowing a nominated contact to help re establish access, and it is a genuinely useful mechanism in a household where two adults can vouch for each other. Setting it up takes a few minutes on each side and it works precisely because it does not depend on any device either party is carrying. The same reasoning applies to the accounts nobody thinks of as accounts, including the mobile carrier itself, where adding a port out PIN or an account passcode prevents somebody persuading a shop to move the number onto a handset they control, which is the attack that unravels every text message based recovery route at once.

The paper component matters as much. A single sheet listing the backup codes, the recovery email addresses and the location of the spare key, kept somewhere sensible and updated when anything changes, is the fallback that survives fire, theft and a dead battery equally well. It should not list passwords, and it does not need to, since the codes and the recovery routes are what get somebody moving again. A fireproof box or a bank deposit box is the right home for it.

Testing It Before It Matters

The final step is the one that separates a plan from an intention. Put the phone in a drawer for an hour and try to get into the email account using only the backup codes and the spare key, then do the same for the bank and for whichever account holds the household's photographs. Anything that fails during that hour was going to fail on a considerably worse day, and it is a great deal easier to repair while the phone is in the next room.

Do the same exercise once a year, and update the sheet whenever a phone is replaced, which is the moment the whole arrangement most commonly quietly breaks. That drawer with a key, a folded sheet and an old handset in it is not a precaution against anything exotic. It is the ordinary answer to the most likely bad day a household will have with its own technology, and it exists because somebody spent an evening building it before they needed it.