Hacker News new | ask | show | jobs
by gwerbret 787 days ago
> Why do you need more than a single phone plus a hardcopy of your Google recovery codes

Because, as I can tell from a similar experience to GP's, they also won't save you if the authentication infrastructure decides you're not who you say you are.

1 comments

If I lost my phone, I would still have access to three different recovery methods:

- I have my recovery codes

- I have access to my recovery email address

- I have access to a TOTP token

I would hope this is sufficient to persuade Google's authentication infrastructure to let me in.

As I learned in Google SRE: "hope is not a strategy"
Hope is part of every strategy that doesn't have infinite cost.