Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

251–260 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#252

Earlier quoted context omitted.

Maybe each individual should be allowed to "choose the two" that work best for them. Most of us have at least one email account that's already under our real name, where we have no big interest in hiding our real identity, but we do have a big interest in not being randomly shut down by Google. We hear about such shutdowns every few weeks on HN, if not more. Google has unfathomable financial and technical resources,…

There are a lot of email providers out right now that fit one of the three possibilities OP set out. But most people aren't aware of any of this, choose the one they know of or see first, and get angry when 'it doesn't work right'. Like OP said, all cover is temporary.

Appreciate the principle, but not all of us have time to change everything we don't like the moment we don't like it a little bit.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#253
post #112

Earlier quoted context omitted.

So the choice is for them to permanently lose access to their email? Homeless people aren't stupid and strong password don't have to be incredibly hard to remember. I'd rather get my accounts hacked because of password reuse than lose access to my email, forever. There is literally nothing more important than your email. Even stuff like your bank account has secondary means of recovery, whereas if you lose access to…

Who's to say that your email account getting hacked is less dire than losing access to it? Attackers can easily search your inbox for 'verify your email', visit any website of value, and use their access to change the account away from your email to an address that they own, effectively removing your access to your third-party website accounts entirely.

I don't know that it is less dire, but I do think it's less likely. Are homeless people's email accounts getting hacked three times per year?

Also... maybe getting hacked is worse, or maybe loosing access is worse, but the user should have the right to make that decision! Google can set the default, but the user knows his or her own life.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#254
Not only Google.

A much less critical or important thing but underlines the bad attitudes: I just tried to renew my cancelled Netflix membership yesterday. I am not allowed to do that without providing a phone number (I used Netflix for ca. 8 years without it). I do not provide that because I do not want to. I do not tie every aspect of my life to my phone number. In fact I do not want to tie any aspect of it to my phone exclusively. Phone number based authentication is not safe and reliable anyway (can loose, stolen, damaged, then I'll have a cascading effect of problems instantly).

I talked long to the helpdesk lady and the conclusion is that I am not allowed to renew my Netflix account without providing a phone number. End of story.

I permanently remain a non-Netflix user this way. Their loss actually.

(A secondary trouble with them is that they are trying to misinform me, giving false reasons! The support lady reasoned that they need the phone number for validating bank transaction. Since they - Netflix - want to use this to send a code in text that I am required to type into their - Netflix - system it has nothing to do with my bank and with authenticating the transaction! (my bank would never use phone for authienticating a transaction btw, I am not even sure if I updated my phone number with them, they reach me other electronic ways). She was just bullsh%ting! Also the renewal pages stated differently, saying that authenticating my account is where the phone number is required. Not to mention that a friend of mine registered recently and for him the reason to register a phone number was to retrieve password recovery messages. Three sources, three different reasons, one of them is complete bullsh%t. Very repelling kind of practice, I am actually glad staying away.)

(A third smaller aspect was that the helpdesk lady tried to interview me about my phone usage strategy and my reasons instead of answering my question about alternatives. It is not her business how I use phone and trying to pressure me into some rigid lifestyle strategy they determine. There are many alternative ways to carry out the same task, they should provide more and better choices.)

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#255

Earlier quoted context omitted.

> there is reasonable debate to be had on how to best provide access to essential services to vulnerable populations. What is the debate? The government can collect taxes and provide services, like they do for multitude of other needs. > I'm not sure what a correct answer here looks like, but I don't think ignoring the need is an approach that gets us to a better society or enables vulnerable populations to better ca…

> The correct answer is not depending on the largesse of businesses. It is using government resources to provide methods for identity verification, communications, and various other bare minimum needs for living. To be fair I don't see how any government system can do better regarding identity on the internet. Login.gov is one of the best services I've used for access to usajobs/SSA/etc but it follows some of the sam…

The US government uses the USPS to do identify verification for passports. If it can handle identity verification for passports, why would it not be able to handle identity verification for other purposes, such as replacing or reauthorizing one’s MFA device?

Hell, it should be trivial to offer federal government provided emails with ID verification with customer service in the event of loss of device/loss of ID/death/etc.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#257
post #51

Earlier quoted context omitted.

This is a simplification of the problem. Both: 1. Vulnerable populations need more assistance accessing essential services required to participate in society 2. Service providers need to maintain a reasonable level of security for their customers Can both be true. Saying that maximum (or minimum) levels of security are required at all time completely misses the point of security--which is to mitigate risk. How much r…

> there is reasonable debate to be had on how to best provide access to essential services to vulnerable populations. What is the debate? The government can collect taxes and provide services, like they do for multitude of other needs. > I'm not sure what a correct answer here looks like, but I don't think ignoring the need is an approach that gets us to a better society or enables vulnerable populations to better ca…

> what is the debate?

The debate parent mentioned is what to do with the money, not where to get money. You can see that there are lots of possible options, right? But you say use taxes like it’s ‘duh, easy’ or something. Now we’re in the realm of the debates actually happening every day in the US, whether to provide social services at all, before we even discuss how much money they need, what to do with it, and where to get it. A huge portion of people this country seem to believe that they don’t benefit from taxes and would prefer safety nets for other people not come out of their pockets.

> The correct answer is […] using government resources to provide methods for identity verification, communications, and various other bare minimum needs for living.

This also sounds like you think it’s easy, without considering the implications. (If govt resources is the solution, why do we still have a problem?) We don’t have municipal or federal Gmail or Facebook, and there are reasons to believe programs like that would take a long time and cost a lot of money. The ‘bare minimum needs’ have changed dramatically in 20 years, and will probably keep changing just as fast for a while, with the homeless population growing in the mean time because the tax-funded social safety net we have isn’t doing the job.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#258

Earlier quoted context omitted.

> They hadn’t started collecting social security due to some debts and was worried it would ALL be garnished. Your contractor’s actions makes a some twisted sense to me as he’s still receiving ‘undisclosed’ cash. The homeless veteran doesn’t make any sense to me as he was not receiving the social security funds at all.

If I told you that you had a bunch of forms to fill out, and after doing all the work you'd get no money (and it would all go to your hated ex-wife or something), you might not bother doing it.

First, anyone skipping out on their responsibilities shouldn’t be getting a sympathetic reaction (and, yeah, I know they always have stories about how it’s justified in their case - my dad spent a lot of time hanging out with other deadbeats but every time details came out, surprise, surprise, they were leaving out a lot).

Paying people under the table has a lot of potential liability for you and it almost always catches up with them. Especially now it’s just not viable to live off the grid (e.g. hoping you don’t get sick isn’t effective) and all this does is ensure that the amount they owe the IRS is unaffordable when the bill finally arrives, usually when their earning potential has gone down.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#259
post #111

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

> Having Google change their 2FA system for this group would be one such decision.

It could be opt-out.

> It's similar to the 'think of the kids + terrorism' attacks on encryption.

No, it's not. Nobody choosing whether _they_ enable 2FA affects your decision to use it or not. It's more like forcing drugs down somebody's throat because you believe it benefits them and everybody else is doing it anyway.

> Why is it such a hassle to keep the same number after a theft? We could investigate there too.

Sim-jacking. Somebody could claim to have lost it and just take your number. This has happened before. The problem of authentication is fundamental in security and Google are just passing the buck onto phone service providers.

> Heck, if we want to focus on Gmail, why not focus on why it's the default choice for the homeless to begin with, as opposed to removing features.

Because it's free and the emails don't bounce. Most big tech has 2FA now.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#260

Earlier quoted context omitted.

How do you remember a complex password? By practice? On what device? I’m sure those involved have bigger things to worry about/remember than a complex password to email. I don’t think that is the solution. I also don’t know what is. Public services that somehow provide safe access to email etc?

I always recommend a easy to remember sentence as a password. with spaces, punctuation, some sort of capilatiozation scheme (cap every last letter, or every other ,etc) and throw a number in there. lot easier to remember than 32 random bits. purposely misspelling something, adding spaces, and your own cap scheme make it a secure password.

What works great for me is using _songs_ , ideally a sentence not directly from the chorus of a lesser-known song, complete with punctutation and some obvious replacement rules (such as `and` -> `&` ) . The reason why this works so great is that many people have some obscure song "in them" that they know by heart but which are not super widely known.

I only had to change one of my passwords once when my coworkers discovered I was reliably whistling "Stayin' alive" after logging in.

Post reply on HN