Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>I don't remember where I've used my YubiKey in the past.

I track this in my password manager. Accounts where the YubiKey is enrolled are tagged "YubiKey (FIDO)".



This would probably be a good place to suggest to others here to track which accounts you've logged into via Google or other social media oath.

I just had to log into stack overflow for the first time in years, and did not remember what I used to previously log in. Once I figured it out that information went into Keepass too.


Just fyi, Google lists sites you’ve used to “sign in with Google” in your account setting page. Apple and GitHub have this as well.


You should assume Google, GitHub, and Apple are hostile and try to limit your blast radius. If you have an account problem they have no customer service to help you.


I can't get into my Google account that's almost 20 years old because I only have the username, password, recovery email and have all the email forwarded to me, but I no longer have the phone number and they silently enabled 2FA SMS at some point.


I wonder if you can phone the phone number, explain the situation and offer to venmo/paypal the new assignee money for the 2FA code

You could try every 3 - 5 years or so as it gets reassigned again


I tried this before, but I haven't tried for a couple of years -- you're right, it might have got reassigned -- I will try again!


+1


Yes, this is exactly why I won’t use these federated identity features of platforms like this. I have a reasonable amount of trust that they are mostly secure, but I have zero trust that they will be helpful if I ever have account troubles. What I don’t need is to have Google (etc) auth problems cascade down to every other account I own.


What's the alternative? What do you use for your base "recovery account" email?


My own domain’s email, which can easily be forwarded wherever I want.


Very well stated, concisely. Thank you.


Thank you, I should review that.


1Password has this functionality and it's excellent.


I really wish Bitwarden had more robust tools for organizing, sorting and tagging passwords. The current system of sorting them into folders is practically useless.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: