Security Signing in safely: 2FA, passkeys and account recovery
Setting up an authenticator app properly, including backups
How to move your two factor codes to an app without locking yourself out: what the QR code contains, where to store recovery codes, and how to handle a new phone.
The short answer
- Set up an authenticator app by scanning the QR code, confirming with the code it shows, and then immediately saving the recovery codes the service gives you.
- The QR code holds a shared secret, so scanning it into two devices gives you two apps producing identical codes and a working backup from day one.
- Codes are calculated from that secret plus the current time, which is why they work with no signal and why a phone clock that is badly wrong breaks them.
- Print your recovery codes rather than photographing them, because the phone is the thing you are protecting against losing.
- Storing codes in the same password manager as your passwords is convenient but collapses two factors into one, so keep email and banking separate if you can.
- Transfer your accounts to a new phone before wiping the old one, because a general device backup does not always carry authenticator seeds across.
Setting up an authenticator app takes about two minutes per account. What decides whether it goes well is the next two minutes: save the recovery codes, and make sure the secret behind those six digit codes exists somewhere other than one phone. The app itself is simple: you scan a QR code, type back the number it shows, and from then on it produces a fresh code every thirty seconds with no internet connection. Almost every horror story about authenticator apps is really about a lost phone and an empty drawer where the recovery codes should have been.
What the QR code actually contains
The square on screen is not a picture of your account. It is a short piece of text: a secret written in letters and digits, plus the name of the service, your username, and a couple of settings such as how many digits the code has (usually six) and how long each one lasts (usually thirty seconds).
That secret is shared. The service keeps a copy and your app keeps a copy, and there is no other copy unless you make one. This one fact explains three things that confuse people.
First, the same QR can be scanned into two apps on two devices, and both show identical codes forever. That is not a bug, it is the most reliable backup you can make, and the moment to do it is while the QR is on screen.
Second, anyone who photographs that QR gets the same permanent ability to generate your codes, and you would never know. Treat the setup screen like a password, and watch out for screenshots that sync into a shared photo library.
Third, most sites offer a can't scan it link that shows the same secret as a string of letters, which is what you save into a password manager if you want a copy you control.
Why the codes work with no signal
The app does not receive codes, it calculates them, which is why it works in airplane mode, in a basement, or on an old phone with no SIM card.
The calculation takes two inputs: the shared secret and the current time, rounded down to the nearest thirty second block. It mixes them with a standard one way function and chops the result to six digits. The server runs the same sum with its copy of the secret and its own clock, then compares. Nothing travels between you and the server except the six digits you type.
The one practical consequence is the clock. If your phone's time is wrong by more than a minute, every code will be rejected. Servers normally accept a code from one step either side, so a few seconds of drift is harmless. Set your phone to network time, or use the time correction option most authenticator apps include.
The second consequence is less comfortable. A six digit code is something you can be talked into reading out. Codes stop a stranger who bought your password, but not a fake login page that relays what you type to the real site in real time, which is why phishing that targets codes still works and why passkeys count as a stronger class of protection. Never read a code to a caller, and never enter one on a page you reached from a link in a message.
Setting one up in the right order
Order matters, because the recovery pieces appear on screen once.
- Pick your app first, since moving later is the annoying part. The choice is whether it keeps an encrypted backup in an account of yours or stores everything on the device only.
- Start with your main email account. It is the account that resets all the others, as set out in what a second factor actually blocks.
- In the account's security settings, choose authenticator app rather than text message, which is exposed to SIM swapping and fails when you travel.
- Before you scan, decide where the second copy goes: the same QR into a second device, or the manual entry string pasted into your password manager.
- Scan, then type the current code back. The service will not finish enrolment until you prove the app works.
- Save the recovery codes now. Download or print them, and do not close that page until they are somewhere real.
- Test it. Open a private browsing window and sign in from scratch, because failed setups are otherwise discovered weeks later on a new laptop.
Backups, the part everyone skips
There are two separate things to back up. Recovery codes are one time escape hatches issued by the service, typically eight or ten, each usable once. The seeds are the secrets behind the rotating codes. Recovery codes get you back in after a disaster. Seeds mean the disaster never happens.
Print the recovery codes. Paper is immune to the failure you are protecting against: losing the device that holds everything. A photo in your phone gallery is not a backup, because the phone is what goes missing. If paper is impossible, put them in your password manager, but know that the keys and the locks are then in one building.
For seeds, pick one approach from the next section and stick to it. The purist advice that you should never back up seeds at all is wrong for most people. It optimizes against a targeted attacker while ignoring the failure that actually occurs: a phone in a taxi and a week of identity checks to get an email account back. There is more on building that safety net in setting account recovery up before you need it.
Where to keep the seeds, and the trade off
| Approach | If the phone dies tomorrow | What it exposes | Suits |
|---|---|---|---|
| App with no backup, device only | Recovery codes or nothing | Least, seeds never leave the phone | People who will genuinely print codes |
| App with encrypted cloud backup | Restore on the new phone in minutes | The backup password, if it is weak | Most people |
| Seeds stored in your password manager | Restore with the vault | One vault holds both factors | Convenience over separation |
| Same QR scanned into two devices | The second device just works | Two devices worth losing | Travelers and households |
| Hardware key as a second factor | Use your backup key | Physical theft only | High value accounts |
Row three starts arguments. Keeping passwords and one time codes in one vault means a single compromise gives an attacker both, so it is not really two factors any more. It still defeats the attack that causes most account takeovers, where someone tries a password leaked from another site, and does nothing at all once your vault is opened. A reasonable middle path: let the manager hold codes for routine accounts, and keep email, banking and the manager's own login on a separate app or a hardware key. How the vault itself is protected is covered in how a password manager encrypts what you store.
Whichever you choose, lock the authenticator app itself with face or fingerprint unlock, so an unlocked phone does not hand over codes. And if two of you share one account, the seed belongs in a shared vault entry rather than one person's phone, for the reasons in sharing access without sending a password.
New phone, lost phone
A planned upgrade is easy in the right order and painful if you wipe first. Install the app on the new phone while the old one still works. Most apps have an export or transfer function that shows a QR on the old screen for the new phone to read, or restore from a backup in your account. Move the accounts, then sign in to one service with a code from the new phone to prove it worked. Only then wipe the old device, following the steps in wiping a device before you sell it.
Two traps. Restoring a phone from a general device backup does not always bring authenticator seeds, since some apps exclude them. And if your app has no transfer feature there is no shortcut: you turn two factor off and back on at each service, one at a time, an hour to book rather than discover.
If the phone is already gone, work in this order. Use a recovery code. Failing that, a second registered method, a backup phone or a hardware key. Failing that, start account recovery early, because it often takes days and may ask for identity documents. Once back in, remove the old authenticator entry at each service and enrol the new device, which cancels the old seed. If the phone was stolen while unlocked, assume the thief has both factors: change those passwords and ask your carrier to block the SIM.
The setup worth doing today
Spend twenty minutes on four accounts: your email, your mobile carrier, your bank and your password manager. For each one, switch from text message codes to the app, scan the QR into two places, print the recovery codes onto one sheet, and sign in once from a private window to confirm. Put the sheet where you would look for a passport, and write the date on it. That is the whole job, and it is the difference between a lost phone being an errand and a lost phone being a week of your life.
Common questions
What happens if I lose the phone with my authenticator app on it?
You fall back to a recovery code, a second device running the same accounts, or another registered method such as a hardware key. If none of those exist, you use the service's account recovery, which can take days and may require identity documents. Once you regain access, remove the old authenticator entry from each account and enrol your new device, which stops the lost phone generating valid codes.
Can I use the same authenticator app on two phones?
Yes, and it is a sensible backup. Scan the same QR code into both devices during setup and each will generate the same six digit code independently, because they hold the same secret and read the same clock. Some apps also sync across your devices automatically. If you missed the moment, remove the account at the service and set it up again, scanning into both devices this time.
Why is my authenticator code being rejected?
Almost always the clock. Codes depend on your device time matching the server, so a phone that has drifted by more than a minute produces numbers the server will not accept. Set the phone to automatic network time, or use the time correction option in the app settings. If the time is fine, check you are reading the entry for the right account, since several services show similar names.
Is an authenticator app better than text message codes?
Yes, on two counts. App codes are generated on the device, so they work with no signal and cannot be intercepted by someone who persuades your carrier to move your number to their SIM. Text codes are still much better than no second factor, so if a service offers only SMS, use it. Neither method protects you from typing a code into a convincing fake login page.
Should I store my two factor codes in my password manager?
It is a trade off. It is convenient, survives a lost phone, and still blocks the common attack where someone tries a password leaked from another site. What it gives up is separation: if your vault is opened, the attacker has both factors at once. If you do go this route, make sure the vault has a long master password, a short auto lock timer and its own second factor that is not stored inside it.