Backup codes?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In 2FA setting, does PayPal provide backup codes, just in case of phone / authenticator loss?
- Labels:
-
Login Issues
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Created a log in to add to the chorus calling PayPal a bunch of morons for not handling this properly.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm stunned to see there is no way to generate a backup code.
Twitter only allows a single, single-use code, which makes it truly last-ditch, but at least it's available. I maintain some DropBox and Google backup codes in secure locations, which I can access through multiple methods (ie paper on a safe, telephone call to trusted party, encrypted online storage, etc). I also have a physical TOTP device for one of my VPN accounts which I keep sealed in a waterproof pouch when I'm on a journey.
How can PayPal not provide such a standard feature, and even worse how can they believe a telephone call is the answer if I'm traveling outside the country and making voice calls is difficult or impossible?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Backup codes are absolutely vital for every TFA method that uses a losable/breakable authenticator such as a phone app.
Every other 2FA system I've ever used offers this. PayPal, please get on the ball.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How is this not supported!? Every other site that implement 2fa through an authenticator app provide these codes to protect against losing the device setup to authenticate with. How are PayPal… a financial organisation… so behind with security.
It's taken years for you to introduce 2fa that's not the insecure SMS confirmation codes, and when you do, the implementation is half baked! You really must provide backup codes, otherwise your offering is still as insecure as just using SMS codes, since we still have to have the SMS setup in case we lose our authenticator device… or worse still, you support disabling the need for the authentication on login by contacting you support team without any better way of confirming my identity!?
I'm seriously considering closing my account because of the lack of industry standard level of security offered!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I agree. Bizarre and worrying that PayPal doesn't use backup codes and just requires one to call tech support to regain access.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I set up my 2fa and was like **bleep** do I find the backup codes? I'm looking all over the place for these things, and I'm glad I'm not the only one who is more than concerned that this doesn't exist. If this isn't going to be implemented I'm going to be disabling 2fa as it's completely useless. You realize that don't you paypal? Many have already shared with you why they are so important to have yet you aren't implementing them. When you do, I'll add it back.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just to add my voice to this discussion. I will not use paypal's 2FA until such time as they add recovery codes.
I see in the EU they are now sending out SMS verification codes for logging in. Sigh, it's 2021 and simswap hacks have been around for years.
Going to search for alternatives to paypal that might value security more highly.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm still here hoping they will! Please Paypal! My phone is finicky and could be one 5' drop away from bye-bye.

Haven't Found your Answer?
It happens. Hit the "Login to Ask the community" button to create a question for the PayPal community.
- Paypal doesn't send text with log in code. in Managing Account Archives
- Paypal keeps failing with second time verification code in Managing Account Archives
- not recive verification code from Paypal on my phone in Managing Account Archives
- New account, Text message not received in Managing Account Archives
- Change phone number to receive code for 2 step verification in Managing Account Archives