Take control of your chaotic inbox
Spam. Promotions. Phishing links. A messy inbox is more than annoying. It’s risky.
Proton Mail shields your inbox from invasive tracking and junk clutter by default. No creepy ad sorting. No surveillance. Just clean, simple organization designed to protect your focus.
You shouldn’t have to fight your email to find what matters. Proton Mail keeps your inbox safe, private, and easy to manage — so you can stay productive, not distracted.
FROM THE DESK
A coworker dropped her phone in a lake. Within an hour, she discovered she couldn't log into her email, her bank, or her cloud storage. Every account was protected with two-factor authentication sent to the phone that was now at the bottom of a lake. It took her three days to regain access to her own digital life. Three days without email, banking, or cloud files. All because her backup plan for losing the 2FA device was "don't lose the 2FA device."
Here's what I've got this morning.
THE BRIEF
When Your 2FA Device Disappears
We covered digital security in Issue 42, including two-factor authentication. This week addresses the vulnerability that 2FA creates: if your second factor (usually your phone) is lost, stolen, broken, or destroyed, you can be locked out of your own accounts during the exact moments you need them most.
The solution is backup codes. When you enable 2FA on any account, most services offer a set of one-time backup codes. These are typically 8 to 10 alphanumeric codes that each work once to bypass 2FA. Download them, print them, and store them securely. Keep a printed copy in your document go-bag (Issue 34) and a digital copy on your encrypted drive.
A second hardware key is the gold standard. In Issue 42, we covered YubiKeys. If you use a hardware key as your primary 2FA method, buy two. Register both with every account. Keep one on your keychain and one in your fireproof bag or go-bag. If you lose one, the other still works.
Authenticator app backup varies by app. Google Authenticator now supports cloud sync, meaning your codes transfer to a new phone automatically if you're logged into your Google account. Authy has always supported multi-device sync. If you use an authenticator app, enable whatever backup or sync feature it offers.
Recovery email addresses serve as a fallback for many services. Make sure your recovery email is a separate account, not one that also requires the same 2FA method. If your primary email requires phone-based 2FA and your recovery email also requires phone-based 2FA, losing your phone locks you out of both.
Print and store account recovery information: security question answers, backup email addresses, and phone numbers on file with each service. This list, stored with your encrypted documents, is your master recovery key.
The action hierarchy when you lose your 2FA device: use backup codes first, try a registered backup hardware key, access via a recovery email, and if all else fails, contact the service's support with identity verification.
ONE THING THIS WEEK
Download and print the backup codes for your three most important accounts.
Email, bank, and cloud storage. Go to each account's security settings, find the 2FA backup codes, and print them. Store them in your document go-bag. Takes about 15 minutes.
ON THE RADAR
A New Identity Theft Victim Is Created in the US Every 4.9 Seconds
An estimated 22% of Americans have experienced identity theft, and the FTC received 1.4 million identity theft reports in 2024 alone. Criminals use stolen credentials to lock victims out of email, banking, and cloud accounts — not just to drain money. When a phone is the only 2FA method, losing it means losing access to everything it protects. The average time to discover an account takeover is 196 days.
LESSON FROM: JESSIE KREBS
Jessie Krebs' SERE training philosophy, demonstrated on Hacking the Wild, centers on redundancy for critical systems. In survival, you never depend on a single tool for a critical function. Fire needs three methods. Water needs multiple sources. Navigation needs compass, map, and natural indicators.
The same principle applies to digital access. Your phone is one tool. If it's your only method for accessing every important account, you have a single point of failure on a critical system. Backup codes, a second hardware key, and a recovery email create the redundancy that SERE doctrine requires for anything you can't afford to lose.
WHAT'S HAPPENING
Belfast Erupts in Riots After Attempted Beheading. Knife Violence Rising Steeply Across Europe
On June 8, Stephen Ogilvie, 44, was attacked on a Belfast street by a 30-year-old Sudanese national who had been granted leave to remain in the UK. The attacker repeatedly stabbed Ogilvie's neck in what police described as an attempted beheading. Ogilvie lost his left eye. Video of the attack circulated online overnight, sparking riots across Belfast on June 9 with hundreds of masked protesters torched vehicles, homes, and a Middle Eastern supermarket. Unrest spread to Glasgow, Edinburgh, and Southampton. The Belfast incident follows months of simmering anger over British policing: in December 2025, 18-year-old Henry Nowak was stabbed five times in Southampton by a man who falsely accused Nowak of racism. Responding officers handcuffed Nowak as he lay dying — he died at the scene. Body-camera footage of officers dismissing his pleas ("I don't think you have, mate") went viral and sparked major protests over what critics call two-tier policing in Britain.
The attack is part of a documented trend across Europe. Germany alone recorded a 32% increase in knife attacks at train stations between 2022 and 2023; foreign nationals made up 51% of identified suspects in knife incidents despite comprising 16% of the population. England and Wales recorded approximately 53,000 knife offenses in the year ending March 2025 and knives now account for nearly 40% of European homicides.
If you are traveling in Europe: practice situational awareness at transit hubs, nightlife districts, crowded markets, and public streets. Know the pan-European emergency number (112) before you arrive; it connects to police, fire, and ambulance in all EU member states and the UK. More importantly, have a pre-arranged check-in protocol with someone at home, and save the address of the nearest US embassy or consulate offline if you are an American citizen in need of aid.
Source: Al Jazeera, Washington Post, NPR, Euronews
WHAT I'M TESTING
YubiKey 5 NFC (Backup Key)
We picked up a second YubiKey specifically as a backup (the first was covered in Issue 42). Both are registered with every account that supports hardware keys. The primary lives on my keychain. The backup lives in my fireproof document bag.
If my keychain key is lost or destroyed, I can authenticate with the backup immediately. If both are lost (unlikely since they're stored in different locations), I fall back to printed backup codes.
The 10 minutes it took to register the second key with each account is the best security investment we've made. About $58 for the second key.
Budget alternative: Printed backup codes from each service, stored in your document go-bag. Free. Less convenient than a hardware key but equally effective as a recovery method.
OVERRATED / UNDERRATED
Overrated: Memorizing backup codes. There are too many accounts and too many codes. Print them and store them securely. Your memory is unreliable under stress.
Underrated: Testing your recovery process. Try logging into an important account using only your backup code, without your primary 2FA device. Verify it works before you need it to work. A backup you've never tested is a backup you're hoping works.
THE LINK DUMP
KeePassXC— Password manager with secure notes for storing recovery information.
YubiKey.com — Hardware security keys and setup guides.
EFF: Two-Factor Authentication — Electronic Frontier Foundation guide to 2FA and backup methods.
Grokipedia: Multi-Factor Authentication — Background on authentication technology and best practices.
HaveIBeenPwned.com — Check if your accounts have been compromised.
NEXT ISSUE
Wilderness First Aid versus Stop the Bleed. Which medical training matters most, and how to decide where to invest your learning time.
PS: My coworker now has backup codes printed and stored, a second YubiKey, and Authy synced across two devices. She said, "I didn't realize how fragile my digital life was until it broke." That's usually how we learn. But it doesn't have to be.
Beauty That Starts From Within
Pique's Carrara Marine Collagen combines Type I + II marine collagen, biotin, and micronized pearl powder for smoother skin, stronger hair, and whole-body vitality. All of it comes in a coconut cream base that transforms your morning routine into a ritual. Get 15% off for life.
5 Seconds a Day. Your Natural Color, Back.
Hair dye fixes gray. It also gives you a bad smell, a hairline that looks painted, and roots that remain gray. Particle Anti-Gray Serum targets the root cause — restoring natural pigment gradually, hair and beard, no dye, no mess. Five seconds a day. Thirty-day guarantee. 20% off with code BH20.




