Notebookcheck Logo

Backup codes: Instagram wants a screenshot, Microsoft forbids one

A key sitting in the lock of a closed wooden drawer
ⓘ Jakub Zerdzicki / Pexels
Microsoft, Apple and the password manager vendors all point to paper and a locked drawer rather than a file on the computer.
Turning on two-factor authentication gives you 10 backup codes and the instruction to keep them safe. Almost nobody says where. Microsoft says not to store them on the device you sign in with, Instagram suggests a screenshot, and Google's own help page names the file the codes are saved as. Infostealer malware searches for exactly that.

Two-factor authentication is switched on, setup is done, and a list of 10 codes appears. A line next to it tells you to keep them safe. You are then left with 10 eight-digit strings and no idea what "safe" means here.

The big providers answer that question so differently that two of them contradict each other outright. Microsoft says of its recovery code: "For security, do not store the code on a device used to sign in to your account." Instagram takes the opposite line. Its help pages say: "You should copy the codes to your clipboard, take a screenshot of them or save them in some other way so that they're available when you log into Instagram." Same person, same phone, opposite instructions.

Eight providers, five answers

Google issues 10 codes and offers both printing and downloading. Its help page recommends putting a printed copy "somewhere safe, like where you keep your passport or other important documents." Two sections later the same page contradicts itself. Under the heading for a lost backup code it says: "Search your computer for: Backup-codes-username.txt with your username." Google assumes the file is on the machine, and it supplies the naming scheme too.

Apple also rules out certain locations, though for a different reason. The 28-character recovery key should not be stored in the Passwords app, in iCloud Photos, in Notes or in iCloud Drive. Apple's concern is access rather than theft, because anyone locked out of the account can no longer open those apps.

GitHub is the only one that explicitly recommends a password manager, and it puts a download button right next to that advice. Dropbox requires a tick next to "I've stored my recovery codes in a safe place" without ever explaining which place qualifies. Facebook lists only printing and writing down. Amazon's help pages do not mention backup codes at all.

Only Microsoft and Apple state outright which locations are off limits. Instagram suggests the clipboard or a screenshot.

This is where the malware looks

The U.S. Department of Health and Human Services published a citable analysis of the Vidar malware in 2024. The report describes how the program collects the most recently downloaded files from the Downloads folder and additionally hunts for file names containing certain words. It lists Passwords, Information, Outlook, Screenshot, Cookie and List.

A year later the security firm Trellix printed the decrypted configuration of the Lumma infostealer, meaning the instruction list from its command server. It searches the entire user profile three levels deep for files whose names contain strings such as "pass" or "words." The desktop gets searched two levels deep, for every single text file. The folder where Lumma gathers its haul is called "ImportantFiles."

Every one of those storage recommendations therefore runs into a documented search pattern. The screenshot Instagram suggests lands on the device as an image file with "Screenshot" in its name. The Google file is called Backup-codes-username.txt and matches twice over, through the extension and through the word in the name. The same configurations also target authenticator apps, so the second factor itself is on the list. A stolen session cookie already showed how little two-factor authentication helps once an attacker is past the login, as we covered in a separate piece on hijacked accounts. What is documented here is the attackers' search pattern. No one has counted how often backup codes turn up in those collections.

Downloads folder, desktop and file names: Vidar and Lumma search the same places a backup code tends to end up in.

And if you never saved them

The opposite case is worse than most people expect. Microsoft's help page for the account recovery form repeats one sentence twice: "If you have turned on two-step verification and cannot access any of the alternate methods to get a verification, we cannot help you, sorry." Support staff may not send password links and may not change account details. Anyone who tries anyway may submit the form twice a day and gets an answer within 24 hours, which gives you an answer, not access.

Google sets no fixed deadline at all. Recovery can take hours or several days, and an active two-factor setup lengthens the wait rather than shortening it. That is deliberate, not a backlog, because the delay gives the real owner a chance to reject someone else's request. The help article ends with a link headed "Create a replacement Google Account."

Apple says several days or longer and no longer publishes a figure. Asked about a shortcut, it answers with a flat no. One condition surprises people. If the account is still in use on any device during the waiting period, Apple cancels the process automatically. A forgotten iPad on a shelf resets the clock to zero. Our guide to a lost phone covers what else helps there.

Bitwarden and 1Password recommend paper in a safe place for their own emergency codes.

Where they belong

Germany's federal cybersecurity agency, the BSI, is unusually blunt about this construction. In its assessment of common two-factor methods it calls recovery mechanisms fundamentally critical whenever a single-factor procedure replaces two-factor authentication. A backup code is precisely that, because it cancels the second factor you have just set up.

The BSI names no storage location. That comes, of all places, from the password manager vendors, and for their own emergency codes. Bitwarden says to keep the code outside the vault, because the company cannot hand it back. It recommends a printed copy in a safe place. 1Password gives its Emergency Kit the same advice, a printout for a safe deposit box or for wherever the passport and birth certificate are kept. The advice loops back on itself. GitHub sends backup codes into the password manager, and the password manager sends its own emergency code back onto paper.

In practice that means three things. Print the codes or copy them out by hand and file them with the documents you already keep. Delete the downloaded file afterwards and empty the recycle bin, because a deleted file in the Downloads folder is not yet a deleted file. Set up a second route back into every account that matters, whether that is a spare address, a second device or, on Apple, a recovery contact. Anyone holding only the codes gets exactly one shot. The same pass through your accounts is worth doing for the devices still signed in there.

Google LogoAdd as a preferred source on Google
Mail Logo

No comments for this article

Got questions or something to add to our article? Even without registering you can post in the comments!
No comments for this article / reply

static version load dynamic
Loading Comments
> Expert reviews and news on laptops, smartphones and tech innovations > Reviews > Backup codes: Instagram wants a screenshot, Microsoft forbids one
Steffen Zahn, 2026-09- 9 (Update: 2026-09- 7)