logoalt Hacker News

jakub_gtoday at 5:35 PM1 replyview on HN

Yup, having _two_ active devices which are logged in to Google (and possibly other services that you rely on that opt you in to app-based 2FA) + with backups of 2FA is a must at this point. When I buy a new phone, I make it a "primary", and keep my old phone as "backup".

If you're not into cloud-based password/2FA syncing, Google Authenticator supports local export/import across devices via a QR code. For passwords, I use KeePass Portable / Keepass2Android + syncing between devices from time to time through a USB-C pendrive (The source of truth KP DB is on pendrive, and both phones work off a local on-device cache).

You don't need to have your phone stolen for things to get messed up. If your screen breaks, you can't type in a PIN anymore, can't unblock with a fingerprint, and you effectively can't access anything on the phone. ADB won't connect because screen is off, and you can't unlock / accept a new external connection etc.


Replies

cjtoday at 5:48 PM

> buy a new phone, I make it a "primary", and keep my old phone as "backup".

Sadly this is why I never end up trading in my phone. Always feels too risky to not have an overlap period.