Backup codes?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In 2FA setting, does PayPal provide backup codes, just in case of phone / authenticator loss?
- Labels:
-
Login Issues
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I agree with everyone else here that having backup codes is an important feature of Two Factor Authentication (2FA) that is missing from PayPal.
I also see that I can only register a single authenticator app instance for my account. If this were not the case, then a workaround would be to register a second authenticator app instance on a backup device (perhaps even the phone of someone you really trust). Since I can't do that either, however, I am left with the following choice:
1) Add my phone number as a backup authentication method or
2) Don't have any backup and risk getting locked out of my account if anything happens to my phone.
I decided to add my phone number as a backup authentication, but I feel that defeats the point of an authenticator app. Authenticator apps are more secure and I don't want it to be possible to use SMS instead of the app.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I thought I was nuts for not being able to find the backup codes for PayPal 2FA. Would you trust PayPal with your money when it is unwilling to properly implement 2FA and backup codes?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@jroop wrote:I agree with everyone else here that having backup codes is an important feature of Two Factor Authentication (2FA) that is missing from PayPal.
I also see that I can only register a single authenticator app instance for my account. If this were not the case, then a workaround would be to register a second authenticator app instance on a backup device (perhaps even the phone of someone you really trust). Since I can't do that either, however, I am left with the following choice:
1) Add my phone number as a backup authentication method or
2) Don't have any backup and risk getting locked out of my account if anything happens to my phone.
I decided to add my phone number as a backup authentication, but I feel that defeats the point of an authenticator app. Authenticator apps are more secure and I don't want it to be possible to use SMS instead of the app.
It's even worse than your two numbered scenarios. Earlier A Paypal support rep in this topic said they will disable 2FA for you if you call them and report a lost authentication device, so the 2FA is just security theater at Paypal, it's not protecting anything.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There is a solution! I just did it for my paypal account.
When you setup TFA (or you can cancel it and set it up again) and you get that QR code (with a text code under it) take a screen shot and print that out on paper. Save that paper in a safe, off site location (for example a safe deposit box or at work). You can scan that code months/years later and it will work!
I tested it out. I printed out on paper. I scanned the "live" screen code with my primary phone and then I scanned the paper with a second, offline phone. The two phones now create the same codes synchronized! The sheet of paper is in a safe place.
Alternatively leave the screenshot as a png file and save that somewhere or email it to yourself or whatever you feel is both convenient and also secure and will not get lost if your house burns down.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Paypal support: recovery/backup codes is a very standard feature in the industry to ensure that 2FA through authenticator has a secure recovery system. Please put it on your roadmap to bring it to your customers. Being able to get "unlocked" from 2FA through the phone is a security flaw that defeats the purpose of authenticator.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@PayPal_EJ ; @PayPal_BJ ; @PayPal_Jo ; @PayPal_Yi ; @PayPal_Jae
We'd love to hear from you.
So many users share the same opinion on this matter and PayPal is not responding ...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Chiming in once again to say that this is an absolutely *critical* piece of a useful 2FA architecture. Lacking support for backup codes, and allowing anyone who gets a couple basic pieces of biographical information to remove my 2FA over the phone, is exactly as good as not having 2FA at all.

Haven't Found your Answer?
It happens. Hit the "Login to Ask the community" button to create a question for the PayPal community.
- Paypal doesn't send text with log in code. in Managing Account Archives
- Paypal keeps failing with second time verification code in Managing Account Archives
- not recive verification code from Paypal on my phone in Managing Account Archives
- New account, Text message not received in Managing Account Archives
- Change phone number to receive code for 2 step verification in Managing Account Archives