Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

141–150 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#141
post #111

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers.

We have to break out of the stereotype that homelessness is a city problem. It isn't. Far from it.

Homelessness is more obvious in cities because there are fewer places for homeless people to be. But there are plenty of homeless people camped out in rural and suburban towns, if you know what to look for.

I recently lived in a snooty city suburb where most of the homes cost from $600,000 to $10 million, and guess what — the drainage tunnels beneath the Home Depot, the maintenance underpasses in the parks, the undeveloped wooded lots were all full of homeless people.

Promulgating the notion that homelessness is a city problem is what allows suburban and rural politicians to cut funding for homeless services because "it doesn't affect my constituents."

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#142

Earlier quoted context omitted.

"Not-my-problem" is a bad response, but the actual response is that without 2FA even more people lose access to their accounts. Anything that makes it harder for adversaries to take over an account almost necessarily adds friction for the users themselves. This isn't a "fuck the people who don't have regular access to a phone, they don't matter" situation. It is a "there is an aggravating balancing act in this situat…

I wonder how many people suffer identity theft versus how many have a working recovery email but are denied to use it because some algo finds it suspicious that you moved country or logged in from a linux machine? The key takeaway is not about how we should promote 2FA or how we should promote long ass passwords, the main issue at hand is google's neglectful lack of customer support. I was once caught in this non-sen…

> the main issue at hand is google's neglectful lack of customer support

Imagine Google had a full service customer support system for account recovery that everybody could access rapidly. How would a homeless person use it? They lose all their possessions regularly so they don't have a reliable form of identification. They'd need to enroll their drivers license (which they probably don't have) in the system and then still have that license when they need to recover their account. Or they could be vouched for by a pre-enrolled trusted party account that does have strong authentication systems. But... homeless people are often transient and don't have access to regular support networks like a family member or social worker who could be enrolled as a backup account. In fact, you can already enroll as backup account if you want to.

> Google as a brand is absolutely dead in the water for anyone that has woken up from the 'Don't be evil' kool-aid of the early days.

Google has a pretty bad reputation at this point on tech blogs and forums. But, believe it or not, it actually shows up near the very top of trusted brands when 3rd party analysts do surveys on the wider population. Maybe this data is wrong, I don't know. But it is interesting.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#143

Earlier quoted context omitted.

> but the actual response is that without 2FA even more people lose access to their accounts This is not black and white. It is possible to encourage 2FA but allow to opt out. The same for phone numbers. And that's why companies enforce 2FA: they want your juicy phone-number or other data. And yeah, maybe they also want to reduce support costs and avoid bad publicity. Still, it's not in your interest, it's in theirs.…

Gmail offers all of these (except for the second email address): paper backup codes, hardware authenticators, non-Google/gmail authenticator apps. The problem is that homeless people can/do routinely lose the “thing you have” part of 2fa.

Huh? Gmail most certainly supports paper codes, hardware authenticators, and non-google auth apps.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#144
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

>Maybe the solution should be to have some basic free state-paid email provider for those people. They are not forced to use Gmail specifically (albeit the number of non-sucking and free email providers is probably close to zero). You don't need to use Gmail. There are a lot of good free mail providers.

And what happens if I've already been using that gmail address and then become homeless?

I guess too bad! Should have thought of my future homelessness when I was signing up for an email service a decade ago!

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#145
post #82

Earlier quoted context omitted.

> If they at least would allow for a sufficient number of options. Like paper-tan (even self printed), yubikey or similar, second email address, an authenticator, ... but even big companies often only require a phone number. Google seems to support all of those?

Did you recently try to create a gmail account? If not, I suggest you try it right now. Maybe you will be surprised. Hint: it is still possible to create a gmail account without phone number, but it has become quite tricky to do so.

> it is still possible to create a gmail account without phone number

Nope. Not possible.

Oh how I would love to be proven wrong though.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#147

Earlier quoted context omitted.

My dad helps people navigate the system to find housing. Recent story was a 65yo + veteran living in a shelter. They hadn’t started collecting social security due to some debts and was worried it would ALL be garnished. After explaining that veterans get expedited in line for housing and that they would still get almost all of their SS, they have applied for it and should be housed soon. It doesn’t surprise me at all…

> They hadn’t started collecting social security due to some debts and was worried it would ALL be garnished. Is this common? I knew a guy who had the same mindset. I ended up paying him in cash for some work, he was convinced that if he made any money in a traditional role it would be instantly garnished.

It sounds like they're used to being nickel -and-dimed or having money taken away from them.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#148

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

Right now, technology has reached a point where it's expected to be ubiquitous, however is not as accessible as other ubiquitous and necessary services. This has been brought up before, buy can someone in their 70s keep up with the changing UIs and websites and security requirements these days? This is all fine for something like Netflix or Spotify. But for government services, access to jobs, and fundamental communi…

> someone in their 70s keep

I'm in my early 40s, computer programmer, and I've temporarily lost access to my WhatsApp account because I don't have a recent enough mobile phone, and the phone that I do have doesn't have a relatively recent OS installed.

It's a 4-year old (I think I've got it for 4 years) iPhone SE, on which I never updated the OS because I hadn't feel the need to do it. When I started getting pop-ups that "hey, our app will stop functioning on your phone unless you upgrade the OS" was already too late for that, I was afraid that upgrading the phone to the latest OS will cripple it permanently in terms of performance (the battery is already on its way out by this point).

So, assuming I get to 70, in no way I'll be up to date by then in terms of having the latest OS installed and all that crazy stuff, who has the time and the nerves for that? (especially the nerves).

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#149

I agree there should be more explicit support here, but can this not be "solved" with backup codes? One or more could be given to a trusted person – a family member, a friend, or even a trusted librarian – or a backup code could be remembered. The tough issue here is that these access edge cases look a lot like malicious use. The aren't but authenticating someone who has no device or ID or really much else to authent…

This is potentially a solution for some but it’s not perfect. If they had a trusted friend or family member who could store backup codes and deliver them as needed, they could probably also just stay logged in on that person’s phone or even have emails sent you that person. Keep in mind that they have limited transportation and likely lose their contacts when they lose their phones, and many will have strained relati…

I think there are possible solutions here for a library, off the top of my head, taking a picture of your face when dropping off the codes, so that when you come back and ask for your codes, the librarian can ID you against the picture they have. Basically what is done when verifying your ID card/passport when you travel/go to the bank etc...

It wouldn't be a librarian doing someone a favour, but rather a service that libraries provide.

This could be a great evolution for libraries. They are already a distributed, public system, that people in general trust, but their role in society has changed with the rise of the internet and online services, and this could be a really useful role they could fill.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#150

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? I think we also have to realize that not everyone who is homeless has problems that can explain it away. It's easy to look at someone who is homeless and tell yourself, "Oh, he's a dope addict. He did this to himself." It's only very rarely true, and you're only making excuses for not helping another human…

The "quiet homeless" who can hold down a job are also likely to be able to keep track of a phone or other two factor device.

If we can "solve" the problem for the dopest of dope addicts, the problem will also be solved for the homeless barista.

That still doesn't solve the problem for homelessness, of course.

Post reply on HN