Ask HN: If I get locked out of everything, please try to help me
21–30 of 350 posts
Re: Ask HN: If I get locked out of everything, please try to help me
#22Earlier quoted context omitted.
It's a smaller of the two problems for the company . If you are really poor, losing access to your online life because you couldn't pay your phone bill or something can be a huge, huge problem. I have been homeless. I'm not currently. But this is an extremely stressful situation that could do all kinds of damage to my life if I can't get it sorted.
We're talking about hackers getting access to users accounts, that's not a Google problem, that's an everyone problem.
I don't try to crow about being some kind of tech genius because for the HN crowd I'm not. But I'm not poor due to being mentally retarded or something. I have an incurable medical condition as does one of my adult sons.
Re: Ask HN: If I get locked out of everything, please try to help me
#23This is my nightmare. This is why I refuse to use 2FA. (Except on services that require it, and I wish they didn't require it.) Am I worried about getting hacked? Absolutely! But when I weigh the likelihood of (1) someone else getting into my account without 2FA and (2) locking myself out of my own account with 2FA, the latter seems much more likely! I understand how backup codes work. I promise you I will loose them…
I honestly don't know what's going on behind the scenes to know if this is not as secure as it "should" be. But this was my reaction specifically to the non-SMS TOTP 2fa: Wait, if I lose my phone there's literally no way possible to get in? Oh there is, if I have the backup codes... yeah right, you think I can hold on to backup codes? Surely there's something I'm missing, what is everyone else doing here? Oh, everyone else is just hoping they never lose their phone? Really?
Re: Ask HN: If I get locked out of everything, please try to help me
#24hn-support best support in tech
Only support in tech.
Re: Ask HN: If I get locked out of everything, please try to help me
#25Earlier quoted context omitted.
I'm seriously medically handicapped and have terrible eyesight issues. I typed the wrong password at first. I still had 1 percent power on my phone earlier and was previously able to get a code on it and I hoped I could get one last code before it outright died, so I said "Yeah, sure, send it to my phone" since they don't really want to do it another way. So then I had to ask another way when I couldn't get to it bec…
I think you should take your phone to a store which can fix your phone. Googles code doesn't come as an SMS it comes as a notification from the Google app. Almost lost an account to this last week. Turned off 2fa.
I work from home due to my medical situation. I have no friends locally who can drive me someplace.
Etc etc etc.
This is a non-starter for me. I need Google to fix this. I can't do anything about the busted phone at this point.
Re: Ask HN: If I get locked out of everything, please try to help me
#26This is my nightmare. This is why I refuse to use 2FA. (Except on services that require it, and I wish they didn't require it.) Am I worried about getting hacked? Absolutely! But when I weigh the likelihood of (1) someone else getting into my account without 2FA and (2) locking myself out of my own account with 2FA, the latter seems much more likely! I understand how backup codes work. I promise you I will loose them…
I use authy (free) for 2FA TOTP and have it set up on my work laptop, my home laptop, and my phone. As long as least one of those is still good, I should still be able to get in. I honestly don't know what's going on behind the scenes to know if this is not as secure as it "should" be. But this was my reaction specifically to the non-SMS TOTP 2fa: Wait, if I lose my phone there's literally no way possible to get in?…
Google has, in some cases, started requiring auth codes sent to specific devices, even if you're already using your own configured TOTP 2FA.
Re: Ask HN: If I get locked out of everything, please try to help me
#27Earlier quoted context omitted.
The solution to that is to make the increasingly intrusive security processes an opt in, not to completely write off anyone who can't reliably keep a particular physical device on their person and working indefinitely.
It used to be opt in until the icloud hacking saga where the public demanded something be done. So it was decided users want mandatory security by default. Almost all of these services provide backup codes you can write down on paper as well. Sure, some people are going to lose their only device and the bit of paper, but at that point if you have literally nothing to identify yourself with, it's going to be hard to p…
It doesn't matter how much in general 2FA works out better for most people, there are lots of people for whom it is not viable. They know who they are. Give them an option that doesn't make their life worse.
Re: Ask HN: If I get locked out of everything, please try to help me
#28Earlier quoted context omitted.
It's a smaller of the two problems for the company . If you are really poor, losing access to your online life because you couldn't pay your phone bill or something can be a huge, huge problem. I have been homeless. I'm not currently. But this is an extremely stressful situation that could do all kinds of damage to my life if I can't get it sorted.
We're talking about hackers getting access to users accounts, that's not a Google problem, that's an everyone problem.
Re: Ask HN: If I get locked out of everything, please try to help me
#29This is my nightmare. This is why I refuse to use 2FA. (Except on services that require it, and I wish they didn't require it.) Am I worried about getting hacked? Absolutely! But when I weigh the likelihood of (1) someone else getting into my account without 2FA and (2) locking myself out of my own account with 2FA, the latter seems much more likely! I understand how backup codes work. I promise you I will loose them…
>This is why I will not use 2FA except on services where it is absolutely required Software 2FA just computes a number based on a secret string. You treat the latter the same way you take care of your passwords. That's why it's best to handle them with your password manager. 2FA over SMS is even less of an issue (except maybe with a broken eSIM chip). Physical methods are a problem, so you have to spend money for a b…