2FA and Recovery Keys: The Two Habits That Actually Protect Your Photos
Published 2026-09-14
Most advice about account security piles on a long list of things to do. In practice, two habits do almost all of the real work for a cloud photo account: turning on two-factor authentication properly, and storing your recovery key somewhere that isn't also the first thing an attacker — or a dropped phone — takes away from you.
Two-factor authentication, done the right way
Two-factor authentication (2FA) means proving who you are with something beyond just a password — usually a code from an app, or a physical security key. The important detail most people miss is which kind of 2FA they're using.
SMS-based 2FA is better than nothing, but it shares a weakness with your phone number itself: it can be intercepted through a SIM swap (covered in detail here). App-based authenticators (Google Authenticator, Authy, or your phone's built-in option) and hardware security keys don't depend on your phone number at all, so they're not exposed to that particular attack. If you have a choice, use one of those instead of SMS.
The recovery key is the part people get wrong
A recovery key or recovery code exists for one purpose: getting back into your account, or your encrypted photos specifically, if you lose your primary device. It's not a spare copy of your data — it's a spare key to your key. That distinction matters, because how you store it determines whether it actually helps in an emergency.
Common mistakes that quietly defeat the whole point:
- Screenshotting it and leaving it on the same phone the account lives on — if that phone is lost or wiped, the backup goes with it.
- Only keeping it in an email inbox that itself depends on the same phone number or recovery chain.
- Not writing it down anywhere physical — a password manager entry is good, but a second copy on paper in a safe place is what actually survives a lost-phone-and-locked-out-of-everything day.
Recovery contacts: the safety net under the safety net
Even a well-stored recovery code can be lost alongside the device it was meant to protect — house fire, theft, a bad year. Recovery contacts exist for exactly that edge case: a person you trust who can help verify it's really you, without ever holding a full copy of your key themselves. It's not a replacement for the recovery code, it's what catches you if the code and the device disappear together.
How this maps onto Archivios specifically
With end-to-end encryption turned on, your recovery code is what lets you move your encryption key to a new device — without it, and without an unlocked device or a recovery contact, encrypted content genuinely cannot be recovered by anyone, including us. That's the direct tradeoff of real end-to-end encryption, and it's why there are three separate recovery paths rather than one. We go through all three in detail on the encryption and recovery page.
Fifteen minutes spent turning on an authenticator app and writing your recovery code down somewhere durable is the highest-leverage security work most people will ever do for their photo library.
Download on the App StoreSee also: How our encryption & recovery works · SIM swap attacks explained · FAQ
Tags: account recovery, security, 2FA, encryption