Live data from Hacker News

Ask HN: If I get locked out of everything, please try to help me

news.ycombinator.com

201–210 of 350 posts

Re: Ask HN: If I get locked out of everything, please try to help me

#201

Earlier quoted context omitted.

It's a smaller of the two problems for the company . If you are really poor, losing access to your online life because you couldn't pay your phone bill or something can be a huge, huge problem. I have been homeless. I'm not currently. But this is an extremely stressful situation that could do all kinds of damage to my life if I can't get it sorted.

I sympathise that this would be really difficult for homeless people. But i am not homeless. I'm sorry if this is cold, but should i have to have an insecure account because homeless people exist? Its not like google has a monopoly on email service providers.

but should i have to have an insecure account because homeless people exist?

No, of course not.

This is like when people who drive get chuffed about pedestrians wanting their lives to work and acting like "Well, if we do anything for you, then my life will fall apart." As if we can only build a world that works for cars or build a world that works for non-drivers and the other camp just has to accept a sucky life and all kinds of flak for not liking it.

What in the hell makes you think someone must get screwed and it might as well be those who already have the least? No one is asking you to get screwed here.

Re: Ask HN: If I get locked out of everything, please try to help me

#202

Earlier quoted context omitted.

> As long as least one of those is still good, I should still be able to get in. Google has, in some cases, started requiring auth codes sent to specific devices , even if you're already using your own configured TOTP 2FA.

I have uninstalled Google applications from most of the mobile devices that I use for this exact reason.

Same! It was such an aggravation

Re: Ask HN: If I get locked out of everything, please try to help me

#203

Earlier quoted context omitted.

Having spent nearly six years homeless and also had a college class from SFSU in Homelessness and Public Policy and having written about homelessness for years, I can assure you that for the vast majority of homeless people, losing their physical phone or being unable to pay for it is a much bigger problem than other people wanting to break into their accounts and steal their identity or some such.

for the rest of us having a hacker gain access to our accounts and stealing money or scamming others is a far greater risk. And for google a far more common occurrence. There is a reason there are so many safeguards in place and its because hackers are trying all day every day to break in and steal identities and money. Homeless people don't need to use 2fa if they are so unconcerned with someone stealing their accou…

The issue though is 2FA is now required. That's literally the whole reason of this post.

Re: Ask HN: If I get locked out of everything, please try to help me

#205

Earlier quoted context omitted.

> As long as least one of those is still good, I should still be able to get in. Google has, in some cases, started requiring auth codes sent to specific devices , even if you're already using your own configured TOTP 2FA.

I have uninstalled Google applications from most of the mobile devices that I use for this exact reason.

Google will send you codes to devices that don’t even have the app installed. Ask me how I know.

Re: Ask HN: If I get locked out of everything, please try to help me

#206
post #8

Earlier quoted context omitted.

Problem is that support people mistakenly resetting account auth when the attacker calls up and social engineers them is a bigger and more common issue than people’s only device dying. Not to say that’s not a thing that happens, but it’s a smaller of the two problems.

The solution to that is to make the increasingly intrusive security processes an opt in, not to completely write off anyone who can't reliably keep a particular physical device on their person and working indefinitely.

> The solution to that is to make the increasingly intrusive security processes an opt in

Absolutely. A common phrase is "mechanism, not policy". The service providers should be enabling all kinds of mechanisms for account level security so users can pick what works best for them. They should absolutely not be imposing any kind of policy. That's where all the source of trouble comes from.

Only I know the threat models I care about for any particular account I have.

For some of them, preventing unauthorized access is the top priority and I'll enable geofencing, 2FA, hardware tokens.

For other accounts, availability is an absolute must and more important than anything else so for those I'll just have a strong password.

Only I can possibly know the correct answer, so for a service provider to come in an impose their policy on my requirements is fundamentally wrong.

Re: Ask HN: If I get locked out of everything, please try to help me

#207

I wanted to point out a very serious problem related to this post: Google will no longer simply accept totp as a verification but insists on sending you a notification to one of your devices. Now I can't just use KeepassXC to get into Google anymore, I have to use my phone. The problem that the OP points out provides very real and poignant evidence that this is not only annoying but dangerous. What is it that compani…

I get an annoying message to use my phone, but then there is an option to authenticate using TOTP instead. Do you not see the same thing?

Re: Ask HN: If I get locked out of everything, please try to help me

#208

This is my nightmare. This is why I refuse to use 2FA. (Except on services that require it, and I wish they didn't require it.) Am I worried about getting hacked? Absolutely! But when I weigh the likelihood of (1) someone else getting into my account without 2FA and (2) locking myself out of my own account with 2FA, the latter seems much more likely! I understand how backup codes work. I promise you I will loose them…

> Am I worried about getting hacked? Absolutely!

If you set a strong, long, unique password for every account, your chances of getting the account compromised are just about zero.

2FA is a good thing in most cases, but I do hate how the industry has blindly adopted it as some sort of mantra that you can't exist without. The reality is that if you chose 128+ bit passwords generated out of /dev/random, they cannot be brute-forced within the lifetime of the universe. You might get phished, which is entirely different, but if you're careful about that you'll do fine without 2FA.

Re: Ask HN: If I get locked out of everything, please try to help me

#209
post #54

Earlier quoted context omitted.

> What do you do? I get screwed! I guess the right answer is that I have the backup codes carefully preserved.... off site! In case of natural disaster. Every time I sign up for a new account, I print out the backup codes, and take them to an off-site secure storage location, which of course i have... somewhere. There's no way 90%+ of internet users are doing that. I'm not even going to pretend I have any chance of d…

Ah, I see we both have a more similar view than I thought! I really should be storing some codes for my password manager somewhere…

Although not as safe as a printout, I keep codes encrypted on a couple of flash drives, one stays in a drawer and one that's always on my person with my keys, yubikey etc. Haven't needed the codes thus far but feels like a decent compromise.

Re: Ask HN: If I get locked out of everything, please try to help me

#210
post #208

This is my nightmare. This is why I refuse to use 2FA. (Except on services that require it, and I wish they didn't require it.) Am I worried about getting hacked? Absolutely! But when I weigh the likelihood of (1) someone else getting into my account without 2FA and (2) locking myself out of my own account with 2FA, the latter seems much more likely! I understand how backup codes work. I promise you I will loose them…

> Am I worried about getting hacked? Absolutely! If you set a strong, long, unique password for every account, your chances of getting the account compromised are just about zero. 2FA is a good thing in most cases, but I do hate how the industry has blindly adopted it as some sort of mantra that you can't exist without. The reality is that if you chose 128+ bit passwords generated out of /dev/random, they cannot be b…

Companies leak passwords constantly.
Post reply on HN