everyday mac tools

Where to keep two-factor backup codes on a Mac

· 6 min read

Two-factor backup codes are what get you back into an account when your phone is lost, wiped or replaced. Keep them in two places: one copy on paper, filed somewhere safe at home, and one encrypted on your Mac, somewhere that does not depend on the account those codes unlock. The place to avoid is the default one, a file called something like backup-codes.txt sitting in Downloads, readable by anyone at the Mac and indexed by Spotlight.

What backup codes are, and why they need care

When you turn on two-factor authentication, many services offer a short list of one-time recovery codes. Each code works once, in place of the code from your phone or authenticator app. Anyone who has them and your password can sign in as you, so they deserve the same care as the password itself. Unlike a password, you may not need them for years, by which point it is easy to have forgotten where they went.

Apple’s version is the recovery key, an optional 28-character code you can create on a Mac in System Settings, under your name, then Sign-In & Security, then Account Recovery. Turning it on gives you more control over recovery and removes Apple’s usual account recovery process, so losing the key along with your trusted devices can mean losing the account. If you create one, it needs the same two-copy treatment as everything else here.

The one rule: not inside the thing they unlock

The codes for your email account should not live only in that email account. The codes for your password manager should not live only inside that password manager. If you are locked out of an account, everything stored inside it is locked out too. The same goes for an authenticator app on your phone: the codes are there for the day that phone is gone, so keeping them only on the phone defeats the point.

Go through each account with backup codes and check it against this rule. It is an easy trap, and you only find out you fell into it on the day you need the codes.

Keep a paper copy

Paper suits this job. It cannot be phished, does not sync anywhere, and still works when your Mac will not start. Print the codes or write them out, label each set with the service and the date, and keep them with your other important papers, in a folder in a drawer or a fire safe.

When you use a code, cross it out. When you generate a new set, destroy the old sheet; on most services the old codes stop working as soon as new ones are issued.

An encrypted copy on the Mac

For the digital copy, you have four reasonable options.

The Passwords app. Each saved login in Apple’s Passwords app has a notes field. Pasting a service’s backup codes into the notes of its own entry keeps them encrypted and next to the login they belong to. That works well for most accounts. Just follow the rule above: the recovery key for the Apple Account that syncs those passwords should live somewhere else as well.

A locked note. Notes can lock individual notes with a password. Locked notes on a Mac explains what that protects and what it does not. Notes stored in iCloud are tied to your Apple Account, so the same rule applies.

An encrypted disk image. Disk Utility can make a password-protected container that depends on no account at all. Encrypt a folder on a Mac with Disk Utility walks through it. The catch is that it stays open after you mount it until you eject it yourself.

A locked folder with Hushbox. Hushbox locks a file or folder where it sits: right-click it in Finder and choose Lock with Hushbox. The locked item is an AES-256 encrypted disk image, the same kind Disk Utility makes, and while it is locked its contents stay out of Spotlight, Finder Recents and Quick Look previews. It opens with Touch ID or your Hushbox password and locks again by itself when the screen locks, the Mac sleeps, or after an idle time you choose. If you ever stop using Hushbox, rename the item so it ends in .sparsebundle, double-click it and enter the password, and macOS opens it on its own. It costs $9 once for two Macs after a free 24-hour trial, and unlocking always stays free.

Two honest points about Hushbox for this job. There is no back door and no password recovery, so keep the Hushbox password in your password manager and keep the paper copy of the codes. And Hushbox hides contents, not names: a locked folder called “Backup codes” still shows that name in Finder, so give it a dull one.

Clean up the copies you already have

Before you settle on a home for the codes, find the loose copies scattered around.

  1. Downloads and Desktop. Services often hand codes over as a downloaded text file. Search in Finder for “backup”, “recovery” and “codes”.
  2. Screenshots. A screenshot of codes may be on the Desktop and in Photos, and in iCloud Photos if that is on. Delete it, then empty Recently Deleted in Photos.
  3. Notes, emails and messages to yourself. These are common quick saves, and they sync to every device you own.
  4. Old printouts. Shred any set that has since been replaced.

After moving the codes, delete the originals and empty the Trash. Copies made earlier are not changed by anything you do now: a Time Machine backup taken last month still holds last month’s plain text file. Private files and Time Machine explains how long that lasts and what to do about it.

Questions

Is iCloud Drive a safe place for backup codes? Only inside something encrypted with its own password. Files in iCloud Drive are protected by your Apple Account, and with standard data protection Apple holds the encryption keys; Advanced Data Protection changes that. Is iCloud Drive private enough for sensitive files goes into the difference.

What if I have lost both my phone and my codes? Each service has its own account recovery process, and it can be slow, take days, or end without access. Start it straight away, and set up fresh codes the moment you are back in.

Is a password-protected zip file good enough? Not for this. The zip encryption built into macOS is the old, weak kind. Password protect a zip file on a Mac explains why.