HACKER Q&A
📣 phasetransition

About to intentionally hose my MFA, suggestions?


Greetings HN,

Murphy is busy tonight. Sitting at IAD with a cancelled flight, and my Pixel XL has concomitantly decided to start exhibiting the following lock screen loop: https://support.google.com/pixelphone/thread/12740836?msgid=12750715

I have a number of TOTP MFA that will be toast if I reset the phone from recovery. I don't have backup codes for all of the TOTP, and even if I did, they wouldn't be on the work laptop I am typing this from.

Any suggestions for now, or next time?


  👤 pwg Accepted Answer ✓
> Any suggestions for ... next time?

When you do get out of your current situation, be sure to backup your TOTP codes somewhere secure so you can recover them should your usual device which hosts them fails. Backup the rest of your data too while you are at it.


👤 gtirloni
Some MFA apps can backup your codes, if that fits your risk profile (e.g. Authenticator Plus)

👤 cloudking
Not sure for now, but for next time SMS as secondary fallback.