What happens when you change phones
In the previous class we enabled two-factor for your email and your bank. Good — that's real progress. Today we cover the part nobody considers until it happens to them: what happens when you get a new phone.
This is where I lost an hour of my own Saturday, so let's not repeat my mistake.
Why this trips people up
Two-factor works by proving you possess something, usually your phone. It sends you a text code, or an app on your phone generates one, or you tap "approve" on a notification. All of that resides on the phone you're currently holding.
A new phone means none of that is present anymore. The authenticator app did not come along simply because you signed into your email on the new device. It has to be set up fresh, deliberately, before you dispose of the old phone.
I discovered this the hard way. I'd set up two-factor on my own accounts on a Saturday afternoon, feeling proud of myself, and then a few months later I switched phones and simply... didn't think about it again until I was locked out of my own email. An hour of my Saturday, gone, digging through old backup codes I'd shoved in a drawer. That's exactly why I teach backup codes first in this course, before anything else. That hour bothered me enough to reorganize the entire class around it.
The order of operations, before you switch phones
Do this before you trade in, sell, wipe, or recycle your old phone. Not after.
- Find your backup codes. If you did the backup-codes lesson with me, you should already have these written down somewhere other than the phone itself. Go get that piece of paper now, before you need it in a panic.
- Move your authenticator app first. Apps like Google Authenticator or Authy usually have a "transfer accounts" or "sync" option in their settings. Look for it. Some apps require you to do this manually, one account at a time, by scanning a QR code again. It's tedious. Do it anyway.
- Confirm your phone number is current. If you're using text codes — and I still consider that fine for most people — make sure your new phone has the same number, or that you've updated your accounts with the new number before you cancel the old line.
- Log into the major accounts on the new phone while you still have the old one. Email, bank, anything with money or your identity attached. If two-factor asks for a code and you can't obtain one, you want the old phone sitting right there as your safety net, not sitting in a drawer at the recycling center.
- Don't wipe the old phone until everything checks out. I know it's satisfying to factory-reset the old one and hand it off. Wait a few days. Confirm you can actually log into everything on the new phone first.
A word about the "unsubscribe" instinct
While we're on habits that quietly cause problems, I'll bring up my dad. He used to click "unsubscribe" on every piece of spam he received, believing he was cleaning things up. I had to explain to him, on three separate occasions, that clicking unsubscribe on a scam email doesn't unsubscribe you from anything. It merely confirms to the sender that a real, active person reads that address. Now you're on more lists, not fewer.
I ended up printing him a one-page sheet and taping it right next to his computer. Sometimes the fix isn't a lecture; it's a note in the right spot.
The same principle applies here. With phones, the instinct is to just get the new one working and address the rest later. That "later" is precisely how people end up locked out — or, worse, still logged into two-factor on an old phone that's now sitting in someone else's pocket.
A plain caution
If you're disposing of your old phone, factory-reset it before you sell it or hand it off — but only after you've confirmed everything transferred. Don't just delete a few apps and call it done. A factory reset wipes it properly. Skipping that step is how your old phone becomes someone else's route into your accounts.
Before next time
Before the next class, if you have an old phone sitting in a drawer from a switch you made a while back, dig it out and confirm you're not still relying on it for any of your two-factor codes. If you are, let's fix that together next time, rather than finding out the hard way, as I did.
~kenneth