Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

131–140 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#131
post #27

Earlier quoted context omitted.

Who do you think would be spending time on this at Google? I highly doubt that their software engineers and product managers in charge of 2FA would, when idle between pull requests, go out and help the homeless. Why not lobby those engineers and product managers to improve something that they are actually have agency and arguably a mandate to improve, helping users homeless and otherwise?

I don't understand the question, google cannot attempt to solve this without assigning someone to spend their time on it. If they do so, I would rather they put that money into actually helping the homeless.

I think you vastly overestimate the fungibility of engineering resources in large corporations.

Also, which one do you think the involved stakeholders at Google would have an easier time getting signed-off: Decreasing reliance on stable phone numbers as an authentication factor, or firing a couple of people and donating their salaries to an organization helping the homeless?

Sometimes, depending on the probability of success, the pragmatic choice is also the ethical one.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#132
post #79

Earlier quoted context omitted.

Quoted post unavailable.

2FA is not only SMS 2FA.

Yes, but what else?

A hardware token can be lost as well, and "in app" push notification (or whatever the app does) you stil need the telephone or at least the SIM/same telephone number, don't you?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#133

Earlier quoted context omitted.

Of course there is. For instance a printed paper tan list. Yes, this is not as safe a proper 2FA device. But it's easy to access, cheap (just go to a copyshop and 10 cents to print it, then put in a plastic bag) and it's so small that it's easy to put it somewhere where you don't lose it and is hard to get stolen.

You're not arguing with me, you're arguing with the author of the twitter thread. "Any solution requiring long-term retention of a physical 2FA key or high-entropy secret will not work."

No, I'm certainly arguing with you. :)

Maybe, on top of that, I'm also arguing with the author. But I assume he implicitly talked about Google (which doesn't provide that option).

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#135

Earlier quoted context omitted.

> but the actual response is that without 2FA even more people lose access to their accounts This is not black and white. It is possible to encourage 2FA but allow to opt out. The same for phone numbers. And that's why companies enforce 2FA: they want your juicy phone-number or other data. And yeah, maybe they also want to reduce support costs and avoid bad publicity. Still, it's not in your interest, it's in theirs.…

> It is possible to encourage 2FA but allow to opt out. You might be surprised to learn that this is how it works for Google accounts: it is default-on but you can turn it off. > If they at least would allow for a sufficient number of options. Like paper-tan (even self printed), yubikey or similar, second email address, an authenticator, ... but even big companies often only require a phone number. You might be even…

Google only allows non-U2F 2FA methods (like TOTP) to be enabled AFTER enabling a hardware U2F device. And signing up without a working mobile number is impossible. Anyone who says that's not true hasn't actually tried in the last several years.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#136
post #15
post #3

I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system h…

The phone number decision is stupid. I up and jump countries every few years. Each time, I'm switching to a new number. I'm the opposite of homeless, I'm that jet set elite. The idea that you want, need, should or will tie your identity to a phone number where people can always reach you is long outdated.

What’s painful is that I’ve ported my phone number out to a VoIP provider similar to Google Voice for exactly this purpose, but something like 25% of providers now block using SMS for 2FA unless it’s tied to an approved mobile phone operator.

Turns out 2FA is also being used as a low-effort form of a captcha in addition to being a tool for data harvesting and “device identification”. I wouldn’t be surprised if legitimate users simply never receive a 2FA SMS because someone used a prepaid phone or something.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#137
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

„Maybe the solution should be to have some basic free state-paid email provider for those people.”

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#138

This is yet another example of the "accessibility, privacy, fraud-protection, choose any two" problem. You can force people to use 2FA, but then you discriminate against people who can't. You can build an account recovery flow that requires government-issued proof of ID, but then you sacrifice privacy. You can do neither, but then you make accounts easier to compromise and harder to recover. There's no good solution…

Maybe each individual should be allowed to "choose the two" that work best for them. Most of us have at least one email account that's already under our real name, where we have no big interest in hiding our real identity, but we do have a big interest in not being randomly shut down by Google. We hear about such shutdowns every few weeks on HN, if not more. Google has unfathomable financial and technical resources,…

There are a lot of email providers out right now that fit one of the three possibilities OP set out.

But most people aren't aware of any of this, choose the one they know of or see first, and get angry when 'it doesn't work right'.

Like OP said, all cover is temporary.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#140

Earlier quoted context omitted.

That's also a bad response. The tech industry literally exists to invent things. That's its entire purpose. Why should we satisfied with a status quo that neglects the most vulnerable among us? What is the point of technology if not to solve these problems?

Is there a solution? The claim in the link is that homeless people lose every single one of their possessions after a period of time. They also have minimal access to support structures that could be used as a recovery system. We've had decades of work on authentication and pretty much every solution either involves using a password manager to create unique passwords or having possession of a physical thing.

Surgical implanting yubikeys.

That won't at all bother anyone homeless, because there's never been a homeless person who was a conspiracy theorist.

(Obvious sarcasm detected)

Post reply on HN