Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

151–160 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#152
post #111

Earlier quoted context omitted.

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

Quoted post unavailable.

> You do realize that KaiOS is Chinese, right?

What's the point of this comment?

Google is American, so what? And people all over the world still use it regardless.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#153
post #16

SMS 2FA needs to disappear (or be relegated to a strictly optional, discouraged method) yesterday, and so does using a phone number as the primary user identifier.

> SMS 2FA needs to disappear (or be relegated to a strictly optional, discouraged method) yesterday, and so does using a phone number as the primary user identifier. A lot of the downsides are mitigated by using Google Voice as the SMS number, since attackers can't migrate your number away from Google. But in general, I totally agree with you from a security perspective. I just think that it's a difficult thing to ge…

That's what I'm doing, and it works fairly well – until I get to one of the many corporations regarding VoIP numbers as inherently insecure, and they don't let you use it for 2FA purposes... (Nevermind Google supporting robust 2FA for logins, and my phone operator not even offering 2FA for eSIM swaps.)

And that's disregarding the elephant in the room, i.e. Google inevitably pulling the plug on Voice at some point.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#154
If you rely on a free google service for anything in any situation, you are one random AI decision away from being completely fucked anyway. If losing 2FA access often is a problem for you, chose a different provider or if you have to use google for some reason, use their google authentication app and save the authentication credentials somewhere save. If you cannot keep a strip of paper with a few recovery codes safe, don't use the internet, it's not for you.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#155

Earlier quoted context omitted.

> Still, it's not in your interest, it's in theirs. Which is okay, because it is a business. If society wants homeless people to have reliable access to email without having SMS 2FA or whatever requirements a business requires, then society should elect a government to provide it as a utility. There is no reason to expect or want businesses to pick up the slack for the government not providing adequate safety nets. L…

I find your worldview overly constrains the range of possibilities and eliminates reasonable ones, like expecting companies to not disproportionately harm those in our society who are least able to recover from or avoid the harm

Businesses are not harming anyone by not providing charity.

I struggle to see a reasonable possibility to the government either directly or legislating others to provide identification and communications services. One of the greatest utilities in the US is USPS, a monumental accomplishment to be able to provide communications to all people in the US.

Tacking on email (and identity verification services - which USPS already does via passports) should be a no brainer.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#156

Earlier quoted context omitted.

Is there a solution? The claim in the link is that homeless people lose every single one of their possessions after a period of time. They also have minimal access to support structures that could be used as a recovery system. We've had decades of work on authentication and pretty much every solution either involves using a password manager to create unique passwords or having possession of a physical thing.

Consider that the decades of work has probably been done with the exact same blind spots we're discussing now.

I'm really curious. What would you propose?

The best I can think of is trusted backup accounts, which already exist. A homeless person with regular attachment to a family member or a social worker could set up that person's account as a backup. But this already exists and is likely to fail for a large number of homeless people, who tend to struggle at maintaining long term relationships with family members or social workers who'd be able to help them.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#157
post #15

Earlier quoted context omitted.

The phone number decision is stupid. I up and jump countries every few years. Each time, I'm switching to a new number. I'm the opposite of homeless, I'm that jet set elite. The idea that you want, need, should or will tie your identity to a phone number where people can always reach you is long outdated.

What’s painful is that I’ve ported my phone number out to a VoIP provider similar to Google Voice for exactly this purpose, but something like 25% of providers now block using SMS for 2FA unless it’s tied to an approved mobile phone operator. Turns out 2FA is also being used as a low-effort form of a captcha in addition to being a tool for data harvesting and “device identification”. I wouldn’t be surprised if legiti…

Using mobile phone numbers as a makeshift captcha is the #1 tool any security team has to prevent fraudulent signups. Because they're expensive to get, it puts any attack at a baseline cost $x, so many would-be attackers that only stand to gain $y just don't carry out the attack when $y < $x.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#158
post #111

Earlier quoted context omitted.

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. We have to break out of the stereotype that homelessness is a city problem. It isn't. Far from it. Homelessness is more obvious in cities because there are fewer places for homeless people to be. But there are plenty of homeless people camped out in rural and suburban towns, if you know w…

If you can't notice it is what makes it not a problem for most people.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#159

Earlier quoted context omitted.

> Still, it's not in your interest, it's in theirs. Which is okay, because it is a business. If society wants homeless people to have reliable access to email without having SMS 2FA or whatever requirements a business requires, then society should elect a government to provide it as a utility. There is no reason to expect or want businesses to pick up the slack for the government not providing adequate safety nets. L…

> Which is okay, because it is a business. It might be legal and maybe even legitimate, but OP said: > This isn't a "fuck the people who don't have regular access to a phone, they don't matter" situation. So yeah, those people don't matter (enough) in the sense that it's not worth to offer more methods of 2FA. Let's not pretend otherwise.

Am I pretending otherwise? Obviously businesses value certain people more than others. It is a business.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#160
post #38
post #32

Earlier quoted context omitted.

I've been using eSIMs for the past couple of years for this specific use case, and while they certainly help, it's really just a stop-gap measure: You still need your phone and cell signal to receive them (at least many European carriers don't support SMS over VoWIFI); the eSIM is "stuck" in your phone if it physically breaks (and on many carriers, you can't re-use an eSIM QR activation code in any case); in many cou…

> the eSIM is "stuck" in your phone if it physically breaks Wait, does this happen?

More common case.

Your phone breaks (broken screen, swollen battery, whatever).

With a physical SIM you can physically extract the SIM and insert it in another (spare) phone (and you can even borrow one for a few minutes).

To transfer an e-SIM you need to authorize the transfer on the old phone (the one that doesn't work):

https://news.ycombinator.com/item?id=32138466

Post reply on HN