Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

231–240 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#231
post #51

Earlier quoted context omitted.

This is a simplification of the problem. Both: 1. Vulnerable populations need more assistance accessing essential services required to participate in society 2. Service providers need to maintain a reasonable level of security for their customers Can both be true. Saying that maximum (or minimum) levels of security are required at all time completely misses the point of security--which is to mitigate risk. How much r…

> there is reasonable debate to be had on how to best provide access to essential services to vulnerable populations. What is the debate? The government can collect taxes and provide services, like they do for multitude of other needs. > I'm not sure what a correct answer here looks like, but I don't think ignoring the need is an approach that gets us to a better society or enables vulnerable populations to better ca…

> The correct answer is not depending on the largesse of businesses. It is using government resources to provide methods for identity verification, communications, and various other bare minimum needs for living.

To be fair I don't see how any government system can do better regarding identity on the internet. Login.gov is one of the best services I've used for access to usajobs/SSA/etc but it follows some of the same security best practices people are complaining about here with no real way to re-gain access to your login.gov account should you lose your 2fa methods (afaik).

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#232

Earlier quoted context omitted.

I'm really curious. What would you propose? The best I can think of is trusted backup accounts, which already exist. A homeless person with regular attachment to a family member or a social worker could set up that person's account as a backup. But this already exists and is likely to fail for a large number of homeless people, who tend to struggle at maintaining long term relationships with family members or social…

I don't have one. I'm not a security expert or researcher or anything like that. But the tech industry has invented thousands of things that to most people would have been inconceivable beforehand. That doesn't mean there's a way to improve on the tradeoffs we have now — but the fact that no one's invented it yet doesn't mean it can't exist. The tech industry self-styles as the smartest people in the world, who try t…

This isn't something we learned about five minutes ago. It's been known that people lose their phones for a very long time. The tradeoffs were considered when designing the system.

Treating the tech industry as a magical black box that can "solve anything" is disingenous and dangerous. This is the exact same attitude that leads to things such as legislation that says "find a way for any communication to be decrypted upon subpoena. You're tech people, figure it out"

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#233
Again, this idea of "secure by default" should at least have an option to opt-out. A few misunderstandings about phones:

1. Somebody has a phone

2. Somebody has a smart phone

3. They are in contact with the phone 24/7

4. They are the unique user of that phone

5. The SIM card and/or number cannot be taken from the phone (virtually or physically)

I currently have to use this for work, with the only positive being that if I get locked out, I can go tell the admin team to let me back in. With someone like Google, it's not even possible to get them on the phone to explain, let alone have them believe it is really you.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#234
post #198

Earlier quoted context omitted.

> Actually giving homes to the homeless would probably be cheaper than whatever we are doing now, even taking into account the mental illness and drug-abuse problems that factor into this. This point is worth reiterating. Homelessness can be solved by providing housing. Yes, homelessness is a complex multi-faceted problem, but the first order solution to the problem is to provide housing. Homelessness is a problem wi…

Unfortunately it's more complicated than this. There have been nonprofit organizations and government initiatives to give homeless people space in unoccupied hotels for example. What ends up happening is they generally just destroy the living space in a variety of ways. It's because the majority of homelessness is an issue of mental health. In the USA, there are pretty much zero mental health resources for people in…

> It's because the majority of homelessness is an issue of mental health.

This isn't true or at least it doesn't start that way. What people don't understand is that there isn't a single homeless population. You have people who are temporarily homeless and people who are chronically homeless. The temporarily homeless are people who lost jobs, fell on hard times, etc etc. The simplest solution for them is yes to give them housing. The chronically homeless is where things get more complicated and those are the people who typically need mental health and abuse services. The simplest and most efficient thing we can do is help the temporarily homeless and prevent them from becoming chronically homeless.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#236

Earlier quoted context omitted.

That's also a bad response. The tech industry literally exists to invent things. That's its entire purpose. Why should we satisfied with a status quo that neglects the most vulnerable among us? What is the point of technology if not to solve these problems?

Is there a solution? The claim in the link is that homeless people lose every single one of their possessions after a period of time. They also have minimal access to support structures that could be used as a recovery system. We've had decades of work on authentication and pretty much every solution either involves using a password manager to create unique passwords or having possession of a physical thing.

Password managers are absolutely not required. While they're a good idea for most of us who don't have to worry about having somewhere to sleep, homeless people can still most likely memorize a password and remember it after a few tries. They can't do that if 2FA is forced on them.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#237
post #12

Won't using e.g. Authy with Gmail for 2FA alleviate the need for a phone number after the initial setup (i.e. requiring a number only once, to initially enable 2FA)? https://authy.com/guides/googleandgmail/

Yes, but that's a highly technical solution. I've been trying to get my girlfriend to use Authy for 6 months now, and the solution we landed on is that my Authy app has all of her 2FA codes, and she just calls me if she needs one. To you and me 2FA doesn't seem that complicated. But to less technical people it's just overwhelming and they don't want to bother with the learning curve.

What learning curve? Setting up the account in the first place? Sure, that’s a tad complicated, but I really don’t understand why your girlfriend finds it easier to call you when she just has to open the app and the code is simply there.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#238

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

OK. Let's play a game.

Let's say I care. Let's say I care a lot. I care so much that I'm willing to make it my personal problem to address the very real, very pressing needs of a critically vulnerable and marginalized part of my community from inside Google.

What am I going to do? Is anyone going to be happier if I stand up and proclaim loudly how much I care? Probably not.

Could I say "Gee, what if we just let everyone put themselves in the group of people who don't do 2FA"? Yes, if I wanted to be responsible for a lot of people not securing their accounts. Could I outsource identity verification to a wide assortment of groups (libraries, non-profits, etc.)? Absolutely, so long as I'm alright with this being used to gain improper access to a LOT of accounts outside the target segment. Could I offer more password chances and friendlier lockout times? Sure, so long as I'm OK with the negative consequences of this for a lot of people.

OK. Let's end the game now. We don't really have any major steps towards real solutions here. Empathy is very useful for showing where a problem is. Demanding what amounts to lowering the global bar for account security is perhaps not the ideal approach here.

Sometimes problems are just hard. Taking ownership and feeling empathy and sincerely wanting to solve the problem does not render them easy.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#239

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

[deleted]

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#240
It's a valid point that I don't expect Alphabet to address. Honest question : what about those security code? I'm not homeless but I expect my phone to die anytime. It's from 2015. I want to bring it to 2025 but it might not make it.

As a result I planned for that phone stopping to work and my understanding is that I will be able to emergency 2FA with those code once it broke. Am I wrong?

Post reply on HN