Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

121–130 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#121

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues?

I think we also have to realize that not everyone who is homeless has problems that can explain it away.

It's easy to look at someone who is homeless and tell yourself, "Oh, he's a dope addict. He did this to himself." It's only very rarely true, and you're only making excuses for not helping another human being.

Just last year there were newspaper articles about how a shocking number of perfectly normal public school teachers in California live out of their cars, just because they cannot afford a place to live on what they're paid.

Most people, especially in the SV bubble, would be shocked to learn how many of the baristas, maids, security guards, convenience store clerks, and other people they encounter every single day are homeless, living in their cars, or sleeping on other people's couches through no fault of their own.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#122

Earlier quoted context omitted.

That's also a bad response. The tech industry literally exists to invent things. That's its entire purpose. Why should we satisfied with a status quo that neglects the most vulnerable among us? What is the point of technology if not to solve these problems?

Is there a solution? The claim in the link is that homeless people lose every single one of their possessions after a period of time. They also have minimal access to support structures that could be used as a recovery system. We've had decades of work on authentication and pretty much every solution either involves using a password manager to create unique passwords or having possession of a physical thing.

Consider that the decades of work has probably been done with the exact same blind spots we're discussing now.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#124

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

Right now, technology has reached a point where it's expected to be ubiquitous, however is not as accessible as other ubiquitous and necessary services. This has been brought up before, buy can someone in their 70s keep up with the changing UIs and websites and security requirements these days? This is all fine for something like Netflix or Spotify. But for government services, access to jobs, and fundamental communi…

We're crippling along depending on family, libraries, charities, and other NGO support services.

The DMV works with people like this all the time; perhaps something could be done there where you have a government issued email address that you can't lose or be locked out of (worst case you take your ID to the DMV and the nice clerk helps you reset your password/sign in).

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#125
post #28

Earlier quoted context omitted.

It really is every company's fault that jumps on this absurd trend of seeing SMS-2FA as the be-all and end-all of user identification and verification. Google is actually doing much better than the competition here in many aspects (e.g. it is possible to operate a Google account completely without a phone number for 2FA or account recovery), but as far as I understand, one is still required to initially create an acc…

> it is possible to operate a Google account completely without a phone number This is only true for a limited time. I've tried to use a couple Google accounts this way and inevitably I log in from a new IP and Google's 2FA system kicks in - forcing me to either furnish a phone number or lose access to the account. It's similar to how Twitter forces phone numbers out of people - just not as immediate.

Do they really ask for a phone number, or would a Yubikey work as well?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#126

Earlier quoted context omitted.

"Not-my-problem" is a bad response, but the actual response is that without 2FA even more people lose access to their accounts. Anything that makes it harder for adversaries to take over an account almost necessarily adds friction for the users themselves. This isn't a "fuck the people who don't have regular access to a phone, they don't matter" situation. It is a "there is an aggravating balancing act in this situat…

> but the actual response is that without 2FA even more people lose access to their accounts This is not black and white. It is possible to encourage 2FA but allow to opt out. The same for phone numbers. And that's why companies enforce 2FA: they want your juicy phone-number or other data. And yeah, maybe they also want to reduce support costs and avoid bad publicity. Still, it's not in your interest, it's in theirs.…

For our product, 2FA is pretty important as a security feature (domain registrar). That said, if you don't want to use it, that's on you as the user. We help out in a different way for those users - we make it impossible to disable account sign in email notifications if you don't use 2FA and those email notifications include a "nuke all active sessions and lock my account" button that can (and has) saved users if their account is compromised due to things like leaks of credentials that they've reused on multiple sites.

2FA is a major hassle for support when users get locked out because they smash their phone or change phone numbers or somehow lose access to the 2FA method. But, the benefits of 2FA largely outweigh those downsides for the majority of users. Offering the choice though, is something we think is important.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#127
post #82

Earlier quoted context omitted.

> If they at least would allow for a sufficient number of options. Like paper-tan (even self printed), yubikey or similar, second email address, an authenticator, ... but even big companies often only require a phone number. Google seems to support all of those?

Did you recently try to create a gmail account? If not, I suggest you try it right now. Maybe you will be surprised. Hint: it is still possible to create a gmail account without phone number, but it has become quite tricky to do so.

Oddly, I suspect if Google provided no free accounts at all--if you had to give a credit card and pay $5 to sign up--nobody would be complaining about this.

Which leads me back to the point made elsewhere in this thread: we have too high an expectation for what private companies can or should do, because they have taken the place in our minds if government.

And our expectations for what government can or should do are too limited, because we've convinced ourselves government is ineffective and unaccountable.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#128
post #111

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

No post body was provided.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#129

Earlier quoted context omitted.

> but the actual response is that without 2FA even more people lose access to their accounts This is not black and white. It is possible to encourage 2FA but allow to opt out. The same for phone numbers. And that's why companies enforce 2FA: they want your juicy phone-number or other data. And yeah, maybe they also want to reduce support costs and avoid bad publicity. Still, it's not in your interest, it's in theirs.…

> And that's why companies enforce 2FA: they want your juicy phone-number or other data. It is possible. And, as far as understand it, the teams at Google in charge of this have evaluated this option and found that it leads to more lost accounts. The people responsible for user authentication at Google are in a completely different part of the company as advertising and, in my experience, are especially stubborn abou…

No post body was provided.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#130

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

> we need ideas like to 2FA to gain traction as widely as possible

No, 2FA needs to die in a fire. Easily circumvented in most social attacks that actually matter, false sense of security, massive timewaster/usability-hell/pain in the butt, acts as a novel social/corporate/accessibility barrier to technology for a large number of previously unaffected groups, and poses a threat to software freedoms.

There are many ways to strengthen security and this has got to be the shittiest one.

Post reply on HN