Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

111–120 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#111

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers.

The problem here is that misapplied empathy can lead to terrible decisions. Having Google change their 2FA system for this group would be one such decision. It's similar to the 'think of the kids + terrorism' attacks on encryption. It's socially difficult to argue against these ideas because you are then labeled as a terrible and non-empathetic person, but the solutions themselves make one other thing worse without really being helpful other than for garnering retweets and likes.

In this case, we actually aren't being ambitious enough. Why are we having a system where we give out phones every 12 weeks to each homeless person? We'd probably save money for the program by developing some sort of dedicated device designed to be harder to steal or lose. Maybe a high-autonomy low-powered KaiOS smartphone that can be attached as a strap? It's not like the current devices are working.

Why is it such a hassle to keep the same number after a theft? We could investigate there too. Improving this would be better than decreasing the effectiveness of gmail's measures.

Heck, if we want to focus on Gmail, why not focus on why it's the default choice for the homeless to begin with, as opposed to removing features.

We could try to solve the problem structurally but we prefer the caseworker approach, because it's more easily packaged 'empathy' than actually fixing the homelessness issue. It's like people who travel to developing countries to 'help', when the locals need investments and training facilities, not extra warm bodies. Actually giving homes to the homeless would probably be cheaper than whatever we are doing now, even taking into account the mental illness and drug-abuse problems that factor into this.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#112

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

People can't remember many good passwords. So they start reusing them. If one site has a leak, everything is lost without 2FA.

So the choice is for them to permanently lose access to their email?

Homeless people aren't stupid and strong password don't have to be incredibly hard to remember. I'd rather get my accounts hacked because of password reuse than lose access to my email, forever.

There is literally nothing more important than your email. Even stuff like your bank account has secondary means of recovery, whereas if you lose access to your email you're pretty much fucked.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#113

Earlier quoted context omitted.

I wonder how many people suffer identity theft versus how many have a working recovery email but are denied to use it because some algo finds it suspicious that you moved country or logged in from a linux machine? The key takeaway is not about how we should promote 2FA or how we should promote long ass passwords, the main issue at hand is google's neglectful lack of customer support. I was once caught in this non-sen…

> the main issue at hand is google's neglectful lack of customer support. Customer support is the main entrypoint into 99% of sim swapping attacks and would be similarly for any targeted account takeovers. What sort of information do you possibly think would be enough to prove someone actually owns a Google account over the phone?

I've heard of some system for reviewing identification like drivers licenses in extreme cases, but homeless people are largely not going to have access to this either.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#114

Earlier quoted context omitted.

I wonder how many people suffer identity theft versus how many have a working recovery email but are denied to use it because some algo finds it suspicious that you moved country or logged in from a linux machine? The key takeaway is not about how we should promote 2FA or how we should promote long ass passwords, the main issue at hand is google's neglectful lack of customer support. I was once caught in this non-sen…

> the main issue at hand is google's neglectful lack of customer support. Customer support is the main entrypoint into 99% of sim swapping attacks and would be similarly for any targeted account takeovers. What sort of information do you possibly think would be enough to prove someone actually owns a Google account over the phone?

that is a phenomenal question that deserves to be answered by the highly paid engineers at Google

they're smart, I'm sure they can find a way, even if it contains such horrible, detestable ideas like "more support staff" and "more training for support staff"

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#115

Earlier quoted context omitted.

> They hadn’t started collecting social security due to some debts and was worried it would ALL be garnished. Is this common? I knew a guy who had the same mindset. I ended up paying him in cash for some work, he was convinced that if he made any money in a traditional role it would be instantly garnished.

> They hadn’t started collecting social security due to some debts and was worried it would ALL be garnished. Your contractor’s actions makes a some twisted sense to me as he’s still receiving ‘undisclosed’ cash. The homeless veteran doesn’t make any sense to me as he was not receiving the social security funds at all.

If I told you that you had a bunch of forms to fill out, and after doing all the work you'd get no money (and it would all go to your hated ex-wife or something), you might not bother doing it.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#116
post #54

Earlier quoted context omitted.

"Not-my-problem" is a bad response, but the actual response is that without 2FA even more people lose access to their accounts. Anything that makes it harder for adversaries to take over an account almost necessarily adds friction for the users themselves. This isn't a "fuck the people who don't have regular access to a phone, they don't matter" situation. It is a "there is an aggravating balancing act in this situat…

Yep, reducing standards for everyone in an attempt to help a small minority is also a growing trend in the west. Schools dumbing down so everyone gets A’s type of top level decision making. Sometimes you have to make hard choices where some people get burned because the alternatives are worse. That doesn’t mean you don’t care.

> to help a small minority

In this case the people asking for 2FA are the "small minority", and the rest of us have to suffer through 2FA-authentication hell because of them.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#117

Earlier quoted context omitted.

> but the actual response is that without 2FA even more people lose access to their accounts This is not black and white. It is possible to encourage 2FA but allow to opt out. The same for phone numbers. And that's why companies enforce 2FA: they want your juicy phone-number or other data. And yeah, maybe they also want to reduce support costs and avoid bad publicity. Still, it's not in your interest, it's in theirs.…

> It is possible to encourage 2FA but allow to opt out. You might be surprised to learn that this is how it works for Google accounts: it is default-on but you can turn it off. > If they at least would allow for a sufficient number of options. Like paper-tan (even self printed), yubikey or similar, second email address, an authenticator, ... but even big companies often only require a phone number. You might be even…

Not only have I not said that Google doesn't offer 2FA - yes they do.

However, Google tries _very hard_ to prevent people from e.g. creating a gmail account without a phone number. Try it if you don't believe me.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#119

Earlier quoted context omitted.

"Not-my-problem" is a bad response, but the actual response is that without 2FA even more people lose access to their accounts. Anything that makes it harder for adversaries to take over an account almost necessarily adds friction for the users themselves. This isn't a "fuck the people who don't have regular access to a phone, they don't matter" situation. It is a "there is an aggravating balancing act in this situat…

> but the actual response is that without 2FA even more people lose access to their accounts This is not black and white. It is possible to encourage 2FA but allow to opt out. The same for phone numbers. And that's why companies enforce 2FA: they want your juicy phone-number or other data. And yeah, maybe they also want to reduce support costs and avoid bad publicity. Still, it's not in your interest, it's in theirs.…

Gmail offers all of these (except for the second email address): paper backup codes, hardware authenticators, non-Google/gmail authenticator apps. The problem is that homeless people can/do routinely lose the “thing you have” part of 2fa.
Post reply on HN