Digital Legacy
Two-Factor Codes And The Phone Nobody Can Unlock
Second-factor authentication protects accounts during life and blocks them after death, because the codes arrive on a device the family often cannot open.

A password left behind is frequently not enough. Modern account security depends on a second factor, and that factor usually lives inside a locked handset.
The second factor is designed to be unshareable
Two-factor authentication assumes that whoever holds the password may not be the account owner, so it demands proof of possession of a specific device.
That is precisely the assumption that defeats an executor. From the system's perspective a relative with the password and no device looks exactly like an attacker.
The protection is working as intended. The difficulty is that account recovery was designed around a living owner who can complete an identity check.
Where the codes actually come from
Text-message codes depend on the phone number, which depends on the SIM and on the mobile account remaining active. Cancelling that account can lock every service attached to it.
Authenticator applications generate codes on the device itself with no network involved, so the codes are unavailable the moment the handset cannot be unlocked.
Hardware keys and passkeys tie access to a physical object or to the device's biometric unlock, which is stronger still and correspondingly harder to inherit.
Recovery codes are the intended escape route
Most services issue a set of one-time backup codes when two-factor authentication is enabled. They exist for the case where the device is lost, which includes this one.
Almost nobody stores them deliberately. They are shown once, during a setup process the user wants to finish quickly, and then forgotten.
Printing them and keeping them with the will or in a sealed envelope with other documents is the single most useful thing to do about digital access.
Keeping the number alive for a while
Cancelling a mobile contract is an early instinct after a death, and it is often premature. The number is the recovery route for banking, email and much else.
Keeping the line active for a period, and knowing the handset's passcode, preserves access while accounts are dealt with in an orderly way.
Writing this down without writing down passwords
The useful record is not a list of credentials but a note of where the recovery material is: which device, whose number, where the backup codes are kept.
Providers' identity and recovery procedures differ and change frequently, and terms of service may restrict sharing credentials. Where an account holds anything of value, a solicitor can advise on the proper route.
Also by Daniel Krajewski
- The annual review: half an hour, once a yearWills & Estates
- Making a will yourself, and when not toWills & Estates
- When you are both the executor and the familyFamily Conversations
- Phones, laptops and what to do with the devicesDigital Legacy





