Skip to content
IdeaScout.
← Back to archive

Emergency account recovery kit for lost/stolen phone 2FA lockouts

AI-discovered

Problem

When someone's phone is stolen, they lose access not just to the device but to every account tied to it: Google, banking, email, drive, and all 2FA-dependent services. Google's automated recovery offers options that all assume possession of the old phone or an old email password, leaving victims locked out with no human support path. 119 points and 130 comments on HN show this is a widespread, acute pain with no real solution today.

Opportunity

A service that proactively builds and maintains a verified 'recovery kit' (backup codes, fallback contacts, escrowed identity proofs) and then actively guides or advocates for the user through each provider's recovery maze when disaster strikes — think emergency roadside assistance for your digital identity.

Market analysis

The pain is real and recurring, but the core promise (getting providers like Google to restore access) is outside any third party's control, and no consumer product today actually solves it. What remains buildable is a proactive preparation and guidance layer, which behaves like insurance: near-zero perceived value until disaster strikes.

Market · Consumers locked out of accounts after device loss or 2FA failure; recurring HN threads and Google support communities confirm steady, acute demand with no consumer-grade solution.

Pricing · No consumer comparable found; enterprise account-recovery vendors (Proof, Transmit Security) sell B2B CIAM, so a concierge price (one-time fee per recovery or a low monthly preparedness plan) would be untested territory.

score 4/10 by glm-5.1

Pros

  • + Acute, emotionally intense pain that resurfaces in viral discussion cycles.
  • + Zero real consumer competitors; the gap is genuine.
  • + The proactive kit (backup codes, fallback contacts, runbooks) is buildable as pure software.

Cons

  • − The lockout itself is resolved (or not) by Google and banks; a third party has no API, no leverage and no human to call.
  • − Insurance-shaped product: users will not pay before the emergency, and after it the kit can no longer help.
  • − Escrowing identity proofs creates a catastrophic liability and attack target for a solo builder.

Source

Hacker News (Ask HN)

Open original thread ↗

The hard truth is that the valuable half of this idea, advocating through each provider’s recovery maze, is not deliverable: there is no paid escalation channel into consumer account recovery at Google or major banks, so the service can only prepare, document and advise. That makes it a preparedness product sold to people who feel invulnerable, which historically converts terribly. The most viable wedge is B2B2C, selling digital-identity continuity checks to family offices, elder-care attorneys or IT-managed families, where a payer exists before the emergency. A solo builder could also start with content and tooling (per-provider recovery runbooks, a backup-code vault) and monetize through affiliates for password managers and hardware keys.