Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

101–110 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#102
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

How do you remember a complex password? By practice? On what device? I’m sure those involved have bigger things to worry about/remember than a complex password to email.

I don’t think that is the solution. I also don’t know what is.

Public services that somehow provide safe access to email etc?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#103
post #16

SMS 2FA needs to disappear (or be relegated to a strictly optional, discouraged method) yesterday, and so does using a phone number as the primary user identifier.

> SMS 2FA needs to disappear (or be relegated to a strictly optional, discouraged method) yesterday, and so does using a phone number as the primary user identifier.

A lot of the downsides are mitigated by using Google Voice as the SMS number, since attackers can't migrate your number away from Google.

But in general, I totally agree with you from a security perspective. I just think that it's a difficult thing to get people to use authenticator apps. Apple has resorted to baking the functionality into their OS.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#104

An authenticator app is a much better 2FA solution that I opt for at every opportunity. Google's authenticator app is brain dead because they want to encourage 2FA over SMS. Why? Because it has the wonderful side effect of destroying your privacy. With your phone number, Google can easily identify you personally. Ain't that special --- privacy invasion wrapped up in security clothing! Much too tempting for Google to…

How are you going to sign in to your OTP app on a new device?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#105

Earlier quoted context omitted.

> but the actual response is that without 2FA even more people lose access to their accounts This is not black and white. It is possible to encourage 2FA but allow to opt out. The same for phone numbers. And that's why companies enforce 2FA: they want your juicy phone-number or other data. And yeah, maybe they also want to reduce support costs and avoid bad publicity. Still, it's not in your interest, it's in theirs.…

> Still, it's not in your interest, it's in theirs. Which is okay, because it is a business. If society wants homeless people to have reliable access to email without having SMS 2FA or whatever requirements a business requires, then society should elect a government to provide it as a utility. There is no reason to expect or want businesses to pick up the slack for the government not providing adequate safety nets. L…

> Which is okay, because it is a business.

It might be legal and maybe even legitimate, but OP said:

> This isn't a "fuck the people who don't have regular access to a phone, they don't matter" situation.

So yeah, those people don't matter (enough) in the sense that it's not worth to offer more methods of 2FA. Let's not pretend otherwise.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#106

Earlier quoted context omitted.

> but the actual response is that without 2FA even more people lose access to their accounts This is not black and white. It is possible to encourage 2FA but allow to opt out. The same for phone numbers. And that's why companies enforce 2FA: they want your juicy phone-number or other data. And yeah, maybe they also want to reduce support costs and avoid bad publicity. Still, it's not in your interest, it's in theirs.…

> Still, it's not in your interest, it's in theirs. Which is okay, because it is a business. If society wants homeless people to have reliable access to email without having SMS 2FA or whatever requirements a business requires, then society should elect a government to provide it as a utility. There is no reason to expect or want businesses to pick up the slack for the government not providing adequate safety nets. L…

I find your worldview overly constrains the range of possibilities and eliminates reasonable ones, like expecting companies to not disproportionately harm those in our society who are least able to recover from or avoid the harm

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#107

Earlier quoted context omitted.

"Not-my-problem" is a bad response, but the actual response is that without 2FA even more people lose access to their accounts. Anything that makes it harder for adversaries to take over an account almost necessarily adds friction for the users themselves. This isn't a "fuck the people who don't have regular access to a phone, they don't matter" situation. It is a "there is an aggravating balancing act in this situat…

That's also a bad response. The tech industry literally exists to invent things. That's its entire purpose. Why should we satisfied with a status quo that neglects the most vulnerable among us? What is the point of technology if not to solve these problems?

Is there a solution?

The claim in the link is that homeless people lose every single one of their possessions after a period of time. They also have minimal access to support structures that could be used as a recovery system. We've had decades of work on authentication and pretty much every solution either involves using a password manager to create unique passwords or having possession of a physical thing.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#108

Earlier quoted context omitted.

"Not-my-problem" is a bad response, but the actual response is that without 2FA even more people lose access to their accounts. Anything that makes it harder for adversaries to take over an account almost necessarily adds friction for the users themselves. This isn't a "fuck the people who don't have regular access to a phone, they don't matter" situation. It is a "there is an aggravating balancing act in this situat…

> but the actual response is that without 2FA even more people lose access to their accounts This is not black and white. It is possible to encourage 2FA but allow to opt out. The same for phone numbers. And that's why companies enforce 2FA: they want your juicy phone-number or other data. And yeah, maybe they also want to reduce support costs and avoid bad publicity. Still, it's not in your interest, it's in theirs.…

> It is possible to encourage 2FA but allow to opt out.

You might be surprised to learn that this is how it works for Google accounts: it is default-on but you can turn it off.

> If they at least would allow for a sufficient number of options. Like paper-tan (even self printed), yubikey or similar, second email address, an authenticator, ... but even big companies often only require a phone number.

You might be even more surprised to discover that all of these options are supported for Google accounts.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#109

Earlier quoted context omitted.

My dad helps people navigate the system to find housing. Recent story was a 65yo + veteran living in a shelter. They hadn’t started collecting social security due to some debts and was worried it would ALL be garnished. After explaining that veterans get expedited in line for housing and that they would still get almost all of their SS, they have applied for it and should be housed soon. It doesn’t surprise me at all…

> They hadn’t started collecting social security due to some debts and was worried it would ALL be garnished. Is this common? I knew a guy who had the same mindset. I ended up paying him in cash for some work, he was convinced that if he made any money in a traditional role it would be instantly garnished.

It is unfortunately common. We're not perfectly rational robots, and so for a decent subset of the population, they go off what has happened to them.

And being paid $1k and assuming they'd have $1k and then discovering they only had $500 because of garnishment tells them "don't accept checks, cash is the only safe method".

And then it's not a step much further to be "it's not worth setting up social security because it'll all be taken".

People forget that there is a population group where fines are MORE HARMFUL than jail time. At least with jail, you can serve your time and be done.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#110
post #38

Earlier quoted context omitted.

> the eSIM is "stuck" in your phone if it physically breaks Wait, does this happen?

That's overly dramatic, of course you can re-create it on the other phone. But what's true is that you can't physically transfer it.

I wasn't trying to be dramatic here: Without deleting an eSIM profile from a device, all implementations I know indeed disallow reinstalling the profile on another device. (The eSIM standard effectively enforces the singleton nature of an instantiated eSIM profile.) But of course most providers can re-issue eSIMs if required, just like they can mail a physical SIM replacement.

But in many cases, they either charge for it, require more or less involved bureaucratic acrobatics (including sending the QR code via physical mail as proof-of-address, because they've been burned badly by eSIM swapping), or both.

So the assumption that an eSIM activation (QR) code is more or less like a bearer token that you can keep in your password safe and use whenever required often does not hold true, especially when needed most (traveling internationally etc).

Fortunately, my provider is pretty good about it (I can instantly self-serve reissue an eSIM in their portal free of charge), but that seems to be the exception, and I also don't know how I feel about that, security-wise. (They don't offer 2FA, as far as I know.)

Post reply on HN