Ask
15

Galaxy lockout survival check: what has to be off the phone before a factory reset is the only way back in?

Not locked out. I want the list I will wish I had.

Context: with One UI 9.0 turning 13 consecutive wrong unlock attempts into a permanent lock, where the documented recovery is a factory reset, a forgotten PIN is now a data-loss event rather than an inconvenience. Even if you are on an older device that is not affected, the same list applies the day the handset dies in a river.

What I am trying to get straight:

  • what actually survives a wipe-and-restore, and what quietly does not
  • where TOTP seeds and passkeys really live, and whether I can get them onto a second device
  • whether my photo sync has genuinely run recently or is one of those things that stopped in March
  • what reset protection will demand from me afterwards

If you have done this for real, what was the thing you forgot?

6 answers Share
Report

Answering anonymously — a moderator will review it first.

  • @coldstorage_cy · yesterday · 2 replies

    The categories that die with the handset, in the order people get hurt by them:

    1. Authenticator apps with no export. If your codes live in an app that has never been exported or synced, a wipe takes every second factor you own, including the one guarding the account you need to complete the reset.
    2. Device-bound passkeys. A passkey held in the device keystore is not in a backup by design. Make sure every account with a passkey also has a second credential you can use from a laptop.
    3. App data that was never in the backup set. Chat history, offline notes, scanned documents, anything in a secure container. Backup coverage is per-app and inconsistent.
    4. Files you "saved" to the device from downloads and never moved.

    The fix is boring: export the seeds into a password manager you can open from another machine, print the recovery codes for the two accounts that gate everything else, and then do the part everyone skips, which is proving the restore works.

    11
    Share
    Reply

    Answering anonymously — a moderator will review it first.

    Report
    • @egress_egon · yesterday

      Seconding the last line hard. A backup you have never restored is a hypothesis, not a backup. Borrow or dig out an old handset once a year, restore onto it, and see what is actually there. Mine was missing an entire messaging app's history and had been for over a year, and the backup dashboard was cheerfully green the whole time.

      7
      Share
      Reply

      Answering anonymously — a moderator will review it first.

      Report
  • @airgap_amir · yesterday

    Plan for reset protection before you need it, because it is the step that turns a bad day into a week.

    After a factory reset the device wants the account it was signed into. So write down, somewhere off the phone: which account that is, the password, and a second factor that is not this handset. A hardware key or a code printed on paper both work. What does not work is "the app on the phone I just wiped".

    9
    Share
    Reply

    Answering anonymously — a moderator will review it first.

    Report
  • @schema_drift_lu · yesterday · 2 replies

    The actual root cause in most lockouts is not brute force, it is a PIN you changed once and never rehearsed, usually after a work policy forced a longer one. Fingerprints hide the problem for months until a wet hand or a reboot forces the code.

    Two cheap habits: record the current unlock code somewhere you can reach without the phone, and deliberately type it in once a month instead of using biometrics. Muscle memory is a cache, and it expires.

    7
    Share
    Reply

    Answering anonymously — a moderator will review it first.

    Report
    • @static_typing_fan · yesterday

      Add one constraint to that: wherever you record it must be openable without the phone. A vault whose only unlocked session is on the locked device is decoration. Laptop copy, or paper in a drawer, otherwise you have written the code into the exact thing you have lost access to.

      6
      Share
      Reply

      Answering anonymously — a moderator will review it first.

      Report
  • @probe_to_ground · yesterday

    Do not plan around a remote unlock saving you. Remote find-and-unlock features have historically required prior setup, a signed-in account and connectivity, and I could not find anything saying they bypass the new permanent lock state. Assume they do not, prepare for the wipe, and treat any remote rescue as a bonus.

    While you are in there: check that whatever device-finding service you use is actually enabled and has reported a location this month. Half the people who need it discover it was switched off during setup.

    1
    Share
    Reply

    Answering anonymously — a moderator will review it first.

    Report