Live data from Hacker News

Ask HN: If I get locked out of everything, please try to help me

news.ycombinator.com

281–290 of 350 posts

Re: Ask HN: If I get locked out of everything, please try to help me

#282
post #264

Earlier quoted context omitted.

Github is extremely insistant on sending me a 2FA push notification on the mobile app every time I want to connect to the desktop. I find it very annoying because I configured TOTP based 2FA and do not want to rely on any proprietary 2FA mechanism. I just can't seem to make it understand that I want to use my TOTP tokens and only that.

remove mobile app as a 2FA. Use U2F/FIDO.

There’s no way to remove it if you have the app installed

Re: Ask HN: If I get locked out of everything, please try to help me

#283
If you can get to a public library, these often (though of course not always) can and will go to heroic lengths to help people with device and service issues. They may also be able to help with charging problems.

Repair shops should also have some capacity to help as others have noted.

I'd also open a consumer-rights issue with your state's consumer-affairs agency, usually the state attorney general or equivalent office. For Washington State:

https://www.atg.wa.gov/consumer-protection>

(This tends to be oriented toward utilities and comms providers though it addresses general concerns as well.)

Washington State's AG specifically notes:

The division’s Consumer Resource Center provides an informal complaint resolution service. The informal complaint resolution process includes notifying businesses of written complaints and facilitating communication between the consumer and the business to assist in resolving the complaint.

Otherwise, this is a major and escalating problem. The present privately-operated, corporate, for-profit systems we have come to rely on address the problem quite poorly. It's bad enough for techbros and the generally affluent. It's literally life-or-death for the poor, indigent, and handicapped.

I'd like to see organisations such as the EFF, mental health and social welfare organisations, the AARP, and others, put this issue on their priority lists. Ultimately we're going to need some sort of legislation to address the question.

Good luck, Doreen.

Re: Ask HN: If I get locked out of everything, please try to help me

#284

Earlier quoted context omitted.

> They each carry the tone of "This content isn't available right now" At this point it's merely static deception. Wait until they run a GPT bot programmed to interactively lie to you, deflect, stall, misdirect and stonewall you based on your personal profile. These companies are devious and untrustworthy to their core, and the only reason anyone uses them is because they're forced to.

No need to wait: https://www.theguardian.com/technology/2022/dec/13/becoming-...

Quite staggering account of how technology has created the worst of all possible worlds for everyone. There are no winners here. People, we have failed. Give up and grow vegetables :)

Re: Ask HN: If I get locked out of everything, please try to help me

#285
post #203

Earlier quoted context omitted.

for the rest of us having a hacker gain access to our accounts and stealing money or scamming others is a far greater risk. And for google a far more common occurrence. There is a reason there are so many safeguards in place and its because hackers are trying all day every day to break in and steal identities and money. Homeless people don't need to use 2fa if they are so unconcerned with someone stealing their accou…

The issue though is 2FA is now required. That's literally the whole reason of this post.

according to google you can turn it off: https://support.google.com/accounts/answer/1064203?hl=en&co=...

Re: Ask HN: If I get locked out of everything, please try to help me

#286

Earlier quoted context omitted.

You don't need to use a phone number for google. I don't have a phone number attached to my google account at all due to the risk of sim swapping despite asking my carrier to lock it, instead i have multiple hardware keys and devices + backup codes in a safe deposit box.

If Google ever thinks you're doing something suspicious, they'll just make you authenticate using a physical device instead, by way of Android functionality they never told you about or asked you about using. Hopefully they won't demand you authenticate on a device that's defunct.

luckily, so far, this doesn't involve the phone number. Google seems to know what my device is and how to reach it without needing to know the number. Little bit scary, but really useful.

Re: Ask HN: If I get locked out of everything, please try to help me

#287
post #53
post #50

I have long wondered if two factor authentication actually causes more economic harm than it solves - it just doesn’t cause that harm to be noticeably all in one place (the harm is spread to millions of users who will lose access at some point during their lives rather than concentrated on the company that implements TFA dealing with fraud). It feels like it might. This isn’t counting the productivity that’s lost to…

This is the way of capitalism. Move costs outside your organization and call it profit. It's why companies don't offer phone support. Or ones that do (like mine) get premium pricing.

Of course many if not most of the services would not be offered in the first place had it not been for the financial incentive offered by the market economy (i.e. 'capitalism' painted with broad strokes) so you can pick your evil: have a market economy with many players, some good and some bad... or have some alternative economical organisation with far fewer services, usually still good or bad.

At least the market economy and 'capitalism' offers the choice of foregoing on those 'premium' services by enabling me to run my own services on my own hardware connected to the 'net through my own fibre connection. Since 'capitalism' leads to more choice it puts the onus on the individual to choose wisely. For some that choice comes down to paying more for those 'premium' services, for others - like me - it means I do a little more work to be able to run my own things. If I loose access I can get it back, the hardware is right here on the farm after all. I have 2FA enabled on a number of services to protect against leaked passwords but since everything is run in-house I can always get back access if I for some reason lost (access to) my devices and backup codes.

This is a win for 'capitalism' as far as I'm concerned no matter which way you turn it - those who want to be served can get served, those who want to serve themselves can do so. You do need to make a conscious decision on what side of the divide - pay and be served or do the work to serve yourself - you want to be on since the space in between can be treacherous to navigate. You also do need to react if a supplier does not keep to its end of the bargain if the system is to work. For the likes of Google/Microsoft/Facemetabook/Apple/etc. this means you should avoid them if possible in any way and if not, make sure you have a way out if they start acting up.

Re: Ask HN: If I get locked out of everything, please try to help me

#288

Earlier quoted context omitted.

Hard disagree. MFA is the best mechanism to stop hackers from constantly hacking everyone. Without it everyone would be getting brute forced 24/7.

Why wouldn’t exponential API rate limiting not solve this brute force issue?

Because brute force does not imply a high rate. You can brute force a password by making attempts on an irregular schedule, a few attempts per hour. That will not be caught by any rate limiter as it would make the service unusable for regular users with fat fingers or misconfigured keyboards.

Re: Ask HN: If I get locked out of everything, please try to help me

#289

Earlier quoted context omitted.

I use authy (free) for 2FA TOTP and have it set up on my work laptop, my home laptop, and my phone. As long as least one of those is still good, I should still be able to get in. I honestly don't know what's going on behind the scenes to know if this is not as secure as it "should" be. But this was my reaction specifically to the non-SMS TOTP 2fa: Wait, if I lose my phone there's literally no way possible to get in?…

Considering that Authy relies on an SMS OTP for the account creation (and possibly account recovery), I prefer to use something else that provides the benefits of cloud syncing across devices and isn’t tied to a phone number. I understand that SMS OTP is simple for most people to handle (encouraged by many platforms over the years), but I just cannot get past that barrier to choose Authy over something else for perso…

I'm literally only using it for things that require it. (including heroku, and rubygems). My thinking is: how do I meet this requirement with the least likelyhood of later locking myself out forever, and having HN threads blaming and shaming me for not carefully preserving my backup codes in a firesafe crypt?

If someone wants me enough to target Authy with an SMS reroute attack focused on me, they're gonna get me either way. I'm not Ed Snowden here, I'm just a guy trying not to lose his car keys.

But, what's the thing you use that provides the benefits of cloud syncing across devices and isn’t tied to a phone number? For anyone that might be interested, including me if it seems as easy and as idiot-proof. (and free or cheap).

Re: Ask HN: If I get locked out of everything, please try to help me

#290

Earlier quoted context omitted.

I'm in a small town. I have no car. I no longer drive. I don't see well enough. I work from home due to my medical situation. I have no friends locally who can drive me someplace. Etc etc etc. This is a non-starter for me. I need Google to fix this. I can't do anything about the busted phone at this point.

On the off chance it helps, because I don't see anyone else mentioning it: could it be that your charging port is stuffed with lint? If you have a thin needle, try to poke inside and see how much material can you get out of the port. Despite this being a common problem, it's not well recognized, and it's easy to forget about it too. I went through several charging cables and almost replaced my phone half a year ago,…

A plastic toothpick worked best for me, and it lowers the risk of scratching / piercing something with the needle.
Post reply on HN