Live data from Hacker News

Ask HN: If I get locked out of everything, please try to help me

news.ycombinator.com

241–250 of 350 posts

Re: Ask HN: If I get locked out of everything, please try to help me

#241
post #228

This is my nightmare. This is why I refuse to use 2FA. (Except on services that require it, and I wish they didn't require it.) Am I worried about getting hacked? Absolutely! But when I weigh the likelihood of (1) someone else getting into my account without 2FA and (2) locking myself out of my own account with 2FA, the latter seems much more likely! I understand how backup codes work. I promise you I will loose them…

Not all 2FA is the same. SMS 2FA leads to these problems. But A FIDO2/WebAuthn token (yubikey or similar) would help you stay secure and independent from your phone. I agree that yubikey is a bit expensive, but there are alternatives. Token2 seems quite bit cheaper, but depends on shipping: https://www.token2.com/shop/product/token2-t2f2-fido2-and-u2...

I would avoid a Yubikey if I were homeless and someone could steal it or I could lose it.

Just stick your 2FAs in your password manager, like I do with Bitwarden. I secure it with a Yubikey, but if I lost my house, I would just remove 2FA from it. My bigger concern would be to get cut out, than people somehow guessing my master password.

SMS 2FA is always a terrible idea, homeless or not. It's honestly better to just go 1FA in that case.

Re: Ask HN: If I get locked out of everything, please try to help me

#242

Earlier quoted context omitted.

Losing access because someone stole your account is even worse because of how much access a Google account gives someone.

Honestly, I would suspect that for many homeless people, the "losing access" part is much, much worse than "someone else having access".

I think the GP's point was that the "someone else having access" bit affects everyone, not just homeless people, if the company makes it easier to reset/regain access to accounts.

Bottom line, though, is that these companies should be required to find a way to maintain that high level of security, but also have a process so anyone who loses account access can get it back in a reasonable amount of time.

Re: Ask HN: If I get locked out of everything, please try to help me

#243

This is my nightmare. This is why I refuse to use 2FA. (Except on services that require it, and I wish they didn't require it.) Am I worried about getting hacked? Absolutely! But when I weigh the likelihood of (1) someone else getting into my account without 2FA and (2) locking myself out of my own account with 2FA, the latter seems much more likely! I understand how backup codes work. I promise you I will loose them…

I'm seriously medically handicapped and have terrible eyesight issues. I typed the wrong password at first. I still had 1 percent power on my phone earlier and was previously able to get a code on it and I hoped I could get one last code before it outright died, so I said "Yeah, sure, send it to my phone" since they don't really want to do it another way. So then I had to ask another way when I couldn't get to it bec…

I don’t know all the conditions of your devices, and your accounts, so I don’t know if this will even help. It’s probably too late for this advice and your Google account, but maybe for other accounts. If not you, hopefully someone else who reads this.

Many accounts that support 2FA let you download a few (commonly 10) static codes that don’t change. If you anticipate a situation where you may lose connectivity access like this, it may make sense to download the codes and store them in a physical notebook.

Re: Ask HN: If I get locked out of everything, please try to help me

#245

Earlier quoted context omitted.

The solution to that is to make the increasingly intrusive security processes an opt in, not to completely write off anyone who can't reliably keep a particular physical device on their person and working indefinitely.

Opt-in is pretty useless. If users followed security procedures, people would use strong unique passwords and we wouldn't need 2fa.

In that case I think it's fine to have a default security profile, and let people add or remove things as they see fit. On account creation, they could even present a questionnaire that determines whether the user values security or availability more, and set the security requirements accordingly.

Re: Ask HN: If I get locked out of everything, please try to help me

#246
post #27

Earlier quoted context omitted.

It used to be opt in until the icloud hacking saga where the public demanded something be done. So it was decided users want mandatory security by default. Almost all of these services provide backup codes you can write down on paper as well. Sure, some people are going to lose their only device and the bit of paper, but at that point if you have literally nothing to identify yourself with, it's going to be hard to p…

It can still be opt out with a fallback on the old approach of security questions. The name of your first pet, your favorite teacher, etc. It doesn't matter how much in general 2FA works out better for most people, there are lots of people for whom it is not viable. They know who they are. Give them an option that doesn't make their life worse.

> They know who they are.

OP knows who they are, but I would not be surprised if many poor/homeless users wouldn't realize they need to opt out of something until they find out the hard way when they're locked out and can't get back in.

Re: Ask HN: If I get locked out of everything, please try to help me

#247

Earlier quoted context omitted.

I carefully store backup codes on my Bitwarden vault so I know where to find them. Also, I use Yubikeys for 2FA, those are reliable enough and you don’t need to rely on phones that could break.

If you store the backup codes in your Bitwarden account, why not simply store the secret itself there, and use Bitwarden as your TOTP app?

I find it convenient to just touch a key instead of copy/pasting a TOTP

Re: Ask HN: If I get locked out of everything, please try to help me

#248

Earlier quoted context omitted.

I'm in a small town. I have no car. I no longer drive. I don't see well enough. I work from home due to my medical situation. I have no friends locally who can drive me someplace. Etc etc etc. This is a non-starter for me. I need Google to fix this. I can't do anything about the busted phone at this point.

How much are you paying for this service you need google to fix? I ask because with their paid email products there are a fair number of routes to get help, your admin, then if that doesn't work you can go up the chain... If you are on a free account you may not be (individually) worth a ton to google revenue wise and so support is going to be poor (they have 1.8billion+ ACTIVE gmail users I think - if they increase…

It's pretty tone-deaf to tell someone who's posted about being poor and previously homeless that they should have to pay Google $500 to recover their account.

Re: Ask HN: If I get locked out of everything, please try to help me

#249

Earlier quoted context omitted.

Tying someone's identity to their phone number is not the answer, though. I have this at the moment - I'm travelling, moving country every few weeks, so I need a new SIM card and phone number every few weeks. My phone number is temporary at best. I'd massively prefer to take the risk of my identity being stolen than constantly fighting security measures that assume people never change their phone number (or country o…

You don't need to use a phone number for google. I don't have a phone number attached to my google account at all due to the risk of sim swapping despite asking my carrier to lock it, instead i have multiple hardware keys and devices + backup codes in a safe deposit box.

If Google ever thinks you're doing something suspicious, they'll just make you authenticate using a physical device instead, by way of Android functionality they never told you about or asked you about using. Hopefully they won't demand you authenticate on a device that's defunct.

Re: Ask HN: If I get locked out of everything, please try to help me

#250

This is my nightmare. This is why I refuse to use 2FA. (Except on services that require it, and I wish they didn't require it.) Am I worried about getting hacked? Absolutely! But when I weigh the likelihood of (1) someone else getting into my account without 2FA and (2) locking myself out of my own account with 2FA, the latter seems much more likely! I understand how backup codes work. I promise you I will loose them…

I love 2FA, but only the TOTP based ones. No codes on my phone, emails or already authorized devices please
Post reply on HN