Security Signing in safely: 2FA, passkeys and account recovery
Account recovery: set it up before you need it
Recovery is how most accounts are actually lost and stolen: the settings to fix today, the recovery contacts and codes to store, and the fifteen minute audit that prevents a very bad week.
The short answer
- Account recovery is the back door every account has, and it is usually weaker than the password and second factor guarding the front.
- Most permanent account losses are not hacks: they are a recovery email that no longer exists or a phone number that was reassigned to someone else.
- Your main email is the root of everything, because whoever reads it can reset every other account without knowing a single password.
- Recovery codes are the path that works when the phone is gone, and the codes for your email and password manager belong on paper rather than inside either one.
- A carrier account PIN and a port freeze are the two settings that blunt a SIM swap, and they take one phone call.
- Recovery details decay, so a yearly fifteen minute check is worth more than any one time setup.
Every account has two doors. The front door is your password and second factor. The back door is account recovery: the process that lets you back in when the front door fails, and it is almost always the weaker of the two. That is why serious attackers go straight for it, and why most people who permanently lose an account lose it to a dead recovery address rather than to a hacker. Fixing this takes about fifteen minutes per important account, and it has to happen before you need it, because recovery is the one security setting you cannot configure once you are locked out.
Why recovery is where accounts are really lost
Recovery is a deliberate backdoor. A service has to be able to distinguish a genuine user who dropped their phone in a lake from a stranger claiming to be them, using only information the genuine user can still produce. Every mechanism built for that is a mechanism an attacker can try to satisfy.
Three failures cover most real cases.
The stale address. Your recovery email is a university account deleted after graduation, a work address you lost when you changed jobs, or an address on a lapsed domain. Whoever registers that domain or username now receives your password resets. It is quiet, cheap and invisible until the day it matters.
The recycled number. Carriers reassign disconnected mobile numbers after a period of months. The next person to get your old number inherits every text message code and reset link sent to it.
The guessable question. Your mother's maiden name, your first school and the street you grew up on are in public records, in social posts, and in old breach data. Security questions are passwords that you published years ago, which is much the same problem described in why reusing a password is so expensive: one answer, known to strangers, unlocking many doors.
Your main email is the root of the tree
Write down the address that receives your password resets. Almost every other account you own hangs from it. Whoever controls that mailbox can request a reset on your bank, your cloud storage and your marketplace accounts and simply read the links as they arrive, without ever knowing a single one of your passwords.
So the root account gets the strongest treatment: a long unique password, a second factor that is an app or a passkey rather than a text, and recovery details you have checked this year. Then there are three structural mistakes to check for.
- Circular recovery: account A recovers to account B, and B recovers to A. When you lose access to either, you lose both. At least one account in the chain must be recoverable independently.
- Work addresses on personal accounts. On the day you leave the job, the mailbox is deactivated and the accounts pointing at it become unrecoverable.
- Custom domain email. If your address is on a domain you own, the domain registration is now a security dependency. Let it lapse and someone else can receive your mail.
The fifteen minute audit
Do this on your main email account first, then repeat the short version elsewhere.
- Open the account's security settings and read the recovery email and recovery phone. Remove any address or number you no longer control. Add a current one.
- Check the list of active sessions and signed in devices. Sign out anything you do not recognize, including devices you sold or gave away.
- Look at mail forwarding and filter rules. An attacker who briefly had access often leaves a rule that quietly forwards or deletes messages from banks. This step takes thirty seconds and catches a persistent intruder that a password change would not.
- Check third party apps and app passwords with access to the mailbox. Revoke anything you no longer use.
- Generate and save the recovery codes. Do this even if you already have a second factor, because they are the path that works when everything else fails.
- Add or upgrade the second factor if it is still a text message, following the authenticator app setup so that the codes survive losing the phone.
- Nominate a recovery contact or trusted contact if the service offers one. The same screen often controls what happens to the account after you die.
Then do steps one, two and five on your password manager account, your mobile carrier account, and your main bank. That covers the accounts whose loss is genuinely expensive.
Recovery codes and where to keep them
Recovery codes are a list of single use strings issued when you turn on a second factor. Each works once, in place of it. They are the reason a lost phone is an inconvenience rather than a disaster, and they are the step people skip.
Where to put them depends on which account they belong to. For ordinary accounts, storing them in your password manager is sensible and far better than not saving them at all, because an encrypted vault is a reasonable place for a secret. For two accounts it is not sensible: the codes for your password manager itself, and the codes for your main email, must live somewhere that does not depend on either. Print them, and keep the paper where you keep your passport.
A second copy elsewhere is worth the effort, since a house fire is a realistic way to lose the only one. A sealed envelope with a relative covers it. Photographing them into your cloud photo library is the shortcut most people take: acceptable for a minor account, poor for the two root ones, because it ties the codes to an account they may need to rescue.
Your phone number is the weak link
A SIM swap is simple to describe. Someone contacts your carrier with details bought from a breach, claims to be you with a lost or damaged phone, and asks for your number to be moved to a new SIM or activated as an eSIM on their device. From that moment your calls and texts arrive on their handset, and every service that resets by text is open to them. Bank accounts and cryptocurrency wallets are the usual targets, and if money has already moved, the first hour after a transfer is what decides whether any of it comes back.
The defenses are unglamorous and effective. Call your carrier and set an account PIN that must be quoted before any change. Ask specifically for a port freeze or number lock, which is a separate control at many carriers. Where a service accepts an app code or a passkey instead, remove the number as a recovery method rather than leaving it as a quiet alternative route. And unlink a number from your accounts before you retire it.
What to set for each kind of account
The right answer is not the same everywhere, because what you are protecting against changes.
| Account | Set this | Avoid this |
|---|---|---|
| Primary email | App or passkey second factor, printed recovery codes, a current alternate address you control | Text message recovery, a work address, circular recovery with another mailbox |
| Password manager | Long unique master credential, printed emergency kit, an emergency access contact if offered | Storing its own recovery codes inside itself |
| Bank and brokerage | In app approval, a known phone number, a card and ID you can produce in branch or by post | Relying on a mailbox as the only proof of identity |
| Mobile carrier | Account PIN, port freeze, a note of which shop or process can override it | Assuming the carrier will verify a caller properly without one |
| Cloud storage and photos | Second factor, recovery contact, a local copy of anything irreplaceable | Treating the cloud account as the only copy of family photos |
| Social and messaging | Second factor, trusted contacts, a linked email you still read | An abandoned address from the year you signed up |
| Work accounts | Whatever the employer mandates, plus personal data moved out | Using the work login as recovery for anything personal |
One category deserves naming: accounts with no recovery at all. Some privacy focused services and most cryptocurrency wallets are built so nobody, including the provider, can let you back in. There the recovery phrase is the account, and losing it is final. Treat that paper like cash.
The audit worth doing today
Open your main email account's security page now and fix the recovery address and phone number. Save the codes to paper. That is the ninety percent of the value, and it takes less time than deciding whether to do it.
Put a yearly reminder in your calendar to repeat it, because recovery details decay: numbers change, addresses close, and the second factor you set up on a phone you no longer own is not helping anyone. While you are there, check that the second factor on the account is not the same channel as the recovery method, since a second factor and a recovery route that both depend on one phone are effectively one thing.
If you are already locked out, use only the provider's own recovery form, from a device, browser and location you normally use, because those signals count in your favor. Expect a wait of days on some services, and understand it exists to protect you. Never pay a stranger who offers to recover an account for you. They cannot do anything you cannot do yourself, and many simply keep the money.
Common questions
What is the best recovery email to use?
A separate address that you control, still read, and can get into without the account you are protecting. A second mailbox at a different provider works well, secured with its own strong password and second factor. Avoid a work address, avoid an address that recovers back to the first one, and avoid anything you will stop checking within a year.
Where should I store recovery codes?
On paper for your email and password manager, kept where you keep important documents, ideally with a second copy elsewhere. For ordinary accounts, your password manager is a fine place. The rule is simply that the codes must not be locked inside the thing they are meant to rescue.
Should I remove my phone number from my accounts?
Remove it as a recovery or second factor method where the service accepts an authenticator app or a passkey instead, because a phone number can be taken over at the carrier. Keep it where it is used only for fraud alerts or delivery notifications. If you cannot remove it, set a carrier PIN and a port freeze instead.
How long does account recovery usually take?
From instant to several weeks, depending on how much you can prove. Providing a recovery code or a second registered device is usually immediate. A form based recovery, where you answer questions about the account from an unfamiliar device, often imposes a waiting period of days on purpose, so a thief cannot rush it through.
What are recovery contacts and are they safe?
A recovery contact is someone you nominate who can generate a code that helps you back into your account. They cannot read your data or sign in as you, so the risk is low and the benefit is real. Choose someone reachable who keeps their own account secure, and tell them what they agreed to, since the request will arrive unexpectedly.