I've written before about passkeys and where they still trip people up, and setting those up got me back into every account I own, checking security settings one by one. Two-factor authentication came up constantly, and I noticed something: almost everyone I know has it turned on for at least one account, and almost nobody has actually set it up right. They turned it on, closed the app, and moved on. That's the part that eventually bites you.
Here's the thing two-factor authentication doesn't warn you about clearly enough: it's designed to lock out anyone who isn't you, and phones get lost, broken, and replaced. If the only place your six-digit codes live is one device, you've built a system that can lock out you too. The fix isn't complicated, but it's a step most setup wizards bury or skip, and it's the difference between "annoying five-minute recovery" and "genuinely losing an account."
Photo by Walls.io on Pexels
What two-factor actually protects against
Quick refresher, because this matters for understanding why the setup step matters. Two-factor authentication (2FA) means logging in requires two things: something you know (your password) and something you have (a code from your phone, a physical key, or an authenticator app). If someone steals your password from a data breach, they still can't get in without that second piece.
That's genuinely effective. Password-only accounts get compromised constantly because people reuse passwords across sites, and one leaked database can expose dozens of accounts at once. Adding a second factor breaks that chain almost entirely.
The trade-off nobody mentions loudly: now your account access depends on a device. Drop your phone in a lake, factory-reset it by mistake, or upgrade to a new one without transferring things properly, and you can end up staring at a login screen with no way in.
The three common types, and where each one breaks
Not all 2FA works the same way, and the failure mode is different for each.
- SMS codes — a text message with a six-digit code. Easiest to set up, but tied to your phone number. If you switch carriers, lose your SIM, or someone pulls off a SIM-swap scam, this becomes a liability rather than a protection.
- Authenticator apps (Google Authenticator, Authy, Microsoft Authenticator, or similar) — generate codes locally on your device, no cellular connection needed. More secure than SMS, but if the app's data isn't backed up and you lose the phone, every account tied to it needs manual recovery.
- Hardware keys (like a YubiKey) — a physical device you plug in or tap. Very secure, and immune to phishing in a way codes aren't, but if you only own one key and it's on your keychain when your bag gets stolen, you're locked out until you use a backup method.
Every single one of these has the same underlying weakness: a single point of failure. That's not an argument against using 2FA — you should absolutely use it — it's an argument for the step most people skip.
The step everyone skips: backup codes
When you turn on two-factor for an account, most services generate a set of one-time backup codes at the same time. It's usually a small link or button that says something like "view backup codes" or "generate recovery codes," sitting quietly below the QR code you just scanned. People scan the QR code, confirm the six-digit prompt works, and close the tab. The backup codes screen gets skipped entirely, or glanced at and forgotten.
Those codes are your insurance policy. Each one works exactly once, and they exist specifically for the scenario where your phone is gone and you can't generate a live code. Skip saving them, and you're relying entirely on whatever recovery process the company offers — which, for smaller services, can mean an email to support that takes days, or in the worst case, no reply at all.
Say you're setting up 2FA on your email provider, your bank, and a cloud storage account this weekend — a completely reasonable thing to do in one sitting. Each one hands you 8 to 10 backup codes. If you don't save them, you've created three separate single-points-of-failure tied to one physical device. If you do save them somewhere safe, you've turned "I lost my phone" from a crisis into an inconvenience.
Where to actually put backup codes
Photo by Walls.io on Pexels
This is the part people get stuck on, because "somewhere safe" is vague advice. A few options that actually work:
- A password manager's secure notes feature. If you already use one for passwords, most (1Password, Bitwarden) let you attach notes or files to an entry. Drop the backup codes right into the note for that account.
- A printed copy, stored somewhere physical. Sounds old-fashioned, but a printed sheet in a drawer or safe can't be hacked remotely. The downside is obvious if your house burns down or floods, so don't treat it as your only copy.
- An encrypted note or file, not a plain text file sitting in your regular cloud drive. If your cloud account itself is one of the things protected by 2FA, storing the recovery codes for that same account inside it defeats the purpose.
What I'd avoid: a screenshot sitting in your photo library with no encryption, or a note titled "backup codes" in an app that isn't password-protected. It works until the day your phone is the thing that's compromised, and then it's the opposite of a safety net.
What to do before you switch phones
This is where most people actually get burned — not by losing a phone, but by upgrading to a new one. Authenticator apps don't always transfer automatically. Before you wipe an old phone or hand it in for trade-in, check that your authenticator app has transferred its codes to the new device, and confirm by actually logging into one account using the new phone before the old one gets erased. Five extra minutes here beats a weekend of account recovery emails.
FAQ
Do I need backup codes if I already use an authenticator app?
Yes. An authenticator app protects you from losing your SIM card or phone number, but it doesn't help if you lose the phone itself, the app's data doesn't transfer, or you reset the device without backing it up first. Backup codes cover the scenario where the app itself is unavailable.
What if I already turned on 2FA months ago and skipped this step?
Most accounts let you regenerate backup codes at any time from the security settings page, even if you never looked at them originally. It's worth doing a quick pass through your important accounts — email, banking, primary cloud storage — and generating fresh codes now rather than waiting until you actually need them.
Is SMS-based 2FA still worth using if it's the weaker option?
Yes, if it's your only choice. Some form of two-factor authentication is meaningfully better than none, even with SMS's weaknesses. Use an authenticator app or hardware key where a service offers it, but don't skip 2FA entirely on a site just because SMS is the only option available.
The boring fix that actually holds up
None of this is exciting, and that's kind of the point — the theme I keep coming back to on this blog is that the unglamorous, slightly tedious setup step is usually the one that saves you later. Turning on two-factor authentication takes two minutes. Saving the backup codes somewhere real takes maybe three more. Skip those three minutes now, and you're betting that your phone never gets lost, broken, or wiped by accident. That's not a bet I'd take, and after watching a few people go through the recovery process the hard way, I don't think you should either.
Comments
Post a Comment