Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

161–170 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#162

Earlier quoted context omitted.

This is potentially a solution for some but it’s not perfect. If they had a trusted friend or family member who could store backup codes and deliver them as needed, they could probably also just stay logged in on that person’s phone or even have emails sent you that person. Keep in mind that they have limited transportation and likely lose their contacts when they lose their phones, and many will have strained relati…

I think there are possible solutions here for a library, off the top of my head, taking a picture of your face when dropping off the codes, so that when you come back and ask for your codes, the librarian can ID you against the picture they have. Basically what is done when verifying your ID card/passport when you travel/go to the bank etc... It wouldn't be a librarian doing someone a favour, but rather a service tha…

Yes this is sort of what I was envisioning. Not as much one trusted librarian doing a favour, but a librarian team having a filing cabinet full of backup codes and an ID process that they trust and that is appropriate for their community.

This is the sort of thing that I think Google could support explicitly with more access control around it, but I don't think that's entirely necessary to get the benefits.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#163

Earlier quoted context omitted.

> but the actual response is that without 2FA even more people lose access to their accounts This is not black and white. It is possible to encourage 2FA but allow to opt out. The same for phone numbers. And that's why companies enforce 2FA: they want your juicy phone-number or other data. And yeah, maybe they also want to reduce support costs and avoid bad publicity. Still, it's not in your interest, it's in theirs.…

For our product, 2FA is pretty important as a security feature (domain registrar). That said, if you don't want to use it, that's on you as the user. We help out in a different way for those users - we make it impossible to disable account sign in email notifications if you don't use 2FA and those email notifications include a "nuke all active sessions and lock my account" button that can (and has) saved users if the…

> For our product, 2FA is pretty important as a security feature (domain registrar). That said, if you don't want to use it, that's on you as the user.

That's all I'm asking for as a user - thank you for being on the good side. Optimally you allow for multiple MFA options, so that I can e.g. use an authenticator app and a yubikey, as well as a recovery code in my bank.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#164

Earlier quoted context omitted.

>Maybe the solution should be to have some basic free state-paid email provider for those people. They are not forced to use Gmail specifically (albeit the number of non-sucking and free email providers is probably close to zero). You don't need to use Gmail. There are a lot of good free mail providers.

And what happens if I've already been using that gmail address and then become homeless? I guess too bad! Should have thought of my future homelessness when I was signing up for an email service a decade ago!

OK ... who are you arguing with?

OP stated "Maybe the solution should be to have some basic free state-paid email provider for those people."

I replied that there are a lot of good free email providers already.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#165
post #111

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

I would argue yours is a poor point of comparison and you have missed the forest.

google isn't requiring specific 2FA data, like address, because they are stalwart guardians of data. They are harvesting data because that is their business.

The homeless don't have enough data to be of value to an entity like goolge

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#166
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution.

This is not a technical problem and should not be automated away.

Rely on trustworthy third parties. Universal utilities like Google should have retail outlets which are adapted to local conditions and can exercise educated judgement. In some countries, the police might certify the identity of the individual, and then Google could trust that certification. In another place, it might be some combination of the Red Cross and a public hospital. Obviously some identifications will be easier and others harder - if a person in New York claims they are the owner of an account based in Spain, the employee should be suspicious and require a higher burden of proof (and the reactivation might be logistically more difficult).

> The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile dissidents, journalists, and senators who will inevitably have accounts;

I'm not really convinced high profile dissidents, journalists and senators (why senators?) should be trusting Gmail to protect them from state sponsored adversaries. Google generally wants to do business in territories controlled by states which means they have to follow laws and will sometimes be subject to intimidation; but they have no intrinsic motivation to be unhackable.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#167
post #15

Earlier quoted context omitted.

The phone number decision is stupid. I up and jump countries every few years. Each time, I'm switching to a new number. I'm the opposite of homeless, I'm that jet set elite. The idea that you want, need, should or will tie your identity to a phone number where people can always reach you is long outdated.

What’s painful is that I’ve ported my phone number out to a VoIP provider similar to Google Voice for exactly this purpose, but something like 25% of providers now block using SMS for 2FA unless it’s tied to an approved mobile phone operator. Turns out 2FA is also being used as a low-effort form of a captcha in addition to being a tool for data harvesting and “device identification”. I wouldn’t be surprised if legiti…

It is more that generating thousands of phone numbers is extremely expensive. It is cheap for real users, but scammers and spammers have to pay a lot.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#168
post #112

Earlier quoted context omitted.

People can't remember many good passwords. So they start reusing them. If one site has a leak, everything is lost without 2FA.

So the choice is for them to permanently lose access to their email? Homeless people aren't stupid and strong password don't have to be incredibly hard to remember. I'd rather get my accounts hacked because of password reuse than lose access to my email, forever. There is literally nothing more important than your email. Even stuff like your bank account has secondary means of recovery, whereas if you lose access to…

I would rank a home as more important than email; I'd certainly rather lose access to my email than my home.

But by definition, the homeless have already lost a home (assuming they weren't born homeless) - and I've forgotten passwords before. So "the stupid homeless just need to memorize their password" isn't a solution.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#169

Earlier quoted context omitted.

You're not arguing with me, you're arguing with the author of the twitter thread. "Any solution requiring long-term retention of a physical 2FA key or high-entropy secret will not work."

No, I'm certainly arguing with you. :) Maybe, on top of that, I'm also arguing with the author. But I assume he implicitly talked about Google (which doesn't provide that option).

>But I assume he implicitly talked about Google (which doesn't provide that option).

Google provides backup codes. You can print them on any kind of paper you want.

Regardless, OP argued that printed backup codes don't work because everything is lost every few weeks.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#170
post #134

Reminds me of an anti-CAPTCHA argument, there are many people in this world who have never seen a fire-hydrant in their life.

or American buses, or anything culture centric. The US version of hydrant is just not present around here.
Post reply on HN