Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

171–180 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#171

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

How do you remember a complex password? By practice? On what device? I’m sure those involved have bigger things to worry about/remember than a complex password to email. I don’t think that is the solution. I also don’t know what is. Public services that somehow provide safe access to email etc?

Complex doesn't mean hard to remember. XKCD936-style passwords (four words with no special chars) are nearly uncrackable and quite easy to remember. Something even simpler like [mother's name][father's name][year of birth] is also very strong when you aren't being targeted specifically (you almost certainly aren't, especially if you're homeless). The remaining issue is password reuse, but that's mostly solved by having two passwords - one for your email and one for everything else.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#172
post #104

An authenticator app is a much better 2FA solution that I opt for at every opportunity. Google's authenticator app is brain dead because they want to encourage 2FA over SMS. Why? Because it has the wonderful side effect of destroying your privacy. With your phone number, Google can easily identify you personally. Ain't that special --- privacy invasion wrapped up in security clothing! Much too tempting for Google to…

How are you going to sign in to your OTP app on a new device?

Reinstall the app and restore private keys from off device backup.

The lack of key backup and restore is one big reason not to use Google's authenticator app. Other compatible apps are not so brain dead. I backup every time I add a new sign in.

If you don't have the ability to sign in from multiple devices and the ability to install access onto any new device, then you're doing it wrong.

Phones are highly portable devices subject to being stolen, damaged or just dying for no obvious reason --- so always be prepared. This is simply not possible with 2FA over SMS.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#173

Earlier quoted context omitted.

> Which is okay, because it is a business. It might be legal and maybe even legitimate, but OP said: > This isn't a "fuck the people who don't have regular access to a phone, they don't matter" situation. So yeah, those people don't matter (enough) in the sense that it's not worth to offer more methods of 2FA. Let's not pretend otherwise.

Am I pretending otherwise? Obviously businesses value certain people more than others. It is a business.

Not you, but the OP certainly gives this vibe.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#174

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

How do you remember a complex password? By practice? On what device? I’m sure those involved have bigger things to worry about/remember than a complex password to email. I don’t think that is the solution. I also don’t know what is. Public services that somehow provide safe access to email etc?

The same way I remember everything else: I think about it enough. There are plenty of good memorable password mnemonics out there, too. So that seems a non-issue.

In any case, I'm sure those involved would prefer the option of remembering a password to not having that option and getting locked out forever. Seems like a good solution. There may be better ones you can implement once this one is, always room for improvement you know

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#175
post #131

Earlier quoted context omitted.

I don't understand the question, google cannot attempt to solve this without assigning someone to spend their time on it. If they do so, I would rather they put that money into actually helping the homeless.

I think you vastly overestimate the fungibility of engineering resources in large corporations. Also, which one do you think the involved stakeholders at Google would have an easier time getting signed-off: Decreasing reliance on stable phone numbers as an authentication factor, or firing a couple of people and donating their salaries to an organization helping the homeless? Sometimes, depending on the probability of…

oh stop it, tech people always think the world works in binary.

Apparently this multi-billion dollar company can't see fit to help humanity because it's literally hard (or impossible?). That somehow I, as an individual, have more of an effect because charities only ever accept money from individuals and not billion dollar corporations?

seriously, just stop.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#176

"Unhoused people" The newspeak is strong with this one. There was never anything wrong with the word homeless. Have progressives gone too far?

Maybe. Look up George Carlin's soft language skit. It's happening to "homeless" now.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#177

Potential solution, the Obamaphone program keeps using the same phone number for an individual instead of totally new ones every time they lose a phone.

this feels like a workaround.

We should not be treating phonenumbers as SSN round two, where everyone relies on it for your identity, and it should never be changed because of how much shit was needlessly tied to it.

I rue the day I need to change my phone number and my digital identity becomes a huge headache, especially for far flung services that decided they wanted my phone number, but I wouldn't have considered going explicitly to them to update it.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#178

Earlier quoted context omitted.

Consider that the decades of work has probably been done with the exact same blind spots we're discussing now.

I'm really curious. What would you propose? The best I can think of is trusted backup accounts, which already exist. A homeless person with regular attachment to a family member or a social worker could set up that person's account as a backup. But this already exists and is likely to fail for a large number of homeless people, who tend to struggle at maintaining long term relationships with family members or social…

I don't have one. I'm not a security expert or researcher or anything like that. But the tech industry has invented thousands of things that to most people would have been inconceivable beforehand. That doesn't mean there's a way to improve on the tradeoffs we have now — but the fact that no one's invented it yet doesn't mean it can't exist.

The tech industry self-styles as the smartest people in the world, who try to solve the hardest problems. All I'm saying is that we shouldn't throw our hands up when we can't immediately come up with a solution to something we only learned about five minutes ago.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#179

I agree there should be more explicit support here, but can this not be "solved" with backup codes? One or more could be given to a trusted person – a family member, a friend, or even a trusted librarian – or a backup code could be remembered. The tough issue here is that these access edge cases look a lot like malicious use. The aren't but authenticating someone who has no device or ID or really much else to authent…

Backup codes could work - but if they have the support of a trusted person they likely can be assisted in other ways, too.

Defining a state-sponsored email account that can only be logged in from specific government machines (imagine a kiosk at the DMV, say) where there are trained clerks who can identify homeless in some way could work.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#180
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

>So what kind of 2FA would be homeless-proof?

Drop the password requirement. Use fingerprints + face. Very hard to lose these, but not impossible. Note, this solution is 1.5FA, but would solve the issue at hand. (pun alert)

Post reply on HN