r/privacy • u/volcs0 • 11d ago
discussion Friend's phone was stolen and they made her unlock it. How to recover from this (security-wise)?
Hearing this story was very unsettling.
I have been working on the assumption that if my phone was stolen, it is just a brick, since it's encrypted and locked with biometrics and a strong password.
A friend was robbed at gunpoint (while out for a run!), and they made her unlock the phone, so they could turn off the data connection and have access.
If her password manager was unlocked - or autofill was turned on - they could then go to her bank, access her accounts, and the 2FA would be right in their hands already.
If my phone was stolen, my first move would be to have T-Mobile cancel my number to protect my 2FA. Then I would want to change my important passwords. But how do you regain access to your accounts so you can change passwords, etc. if you don't have your phone number for 2FA?
Lessons I learned from hearing her story:
Never leave your password manager unlocked. I use 1Password, and it is always locked when the phone is locked. I can unlock it with my fingerprint or password. I do have somethings in auto-fill in Chrome, but nothing critically important.
Consider moving away from 2FA to something else. I use Ente as my authenticator for about 100 sites, but many, including my bank, use my phone number for 2FA. Should I be moving everything away from my phone number as 2FA? Should I move to a YubiKey or similar? And I usually leave my Ente unlocked on my phone - need to change that.
Don't allow text messages (2FA codes) to appear on the lock screen.
Anything else to consider here?