Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

271–280 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#271
post #249

Earlier quoted context omitted.

Exactly. The word people should be looking for is "vulnerable". They are not a niche category, they are a vulnerable category, and need protection, not dismissal.

You're absolutely right. Now let's talk about how much effort and what level of resources it's reasonable to expect a commercial entity to invest in extending protections to vulnerable people in need who happen to not be customers. Perhaps we're asking the wrong entity to address this problem? This seems more like a public service infrastructure problem.

Google is a multi-billion dollar company, they barely have to lift a finger. They simply have to provide an option to opt out of 2FA. Add a bunch of warnings if you must. Even if Google was a small startup it would be trivial for them to do this.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#272
post #132

Earlier quoted context omitted.

2FA is not only SMS 2FA.

Yes, but what else? A hardware token can be lost as well, and "in app" push notification (or whatever the app does) you stil need the telephone or at least the SIM/same telephone number, don't you?

No the device auth prompts are completely independent of mobile number, you don't even need a Sim card.

Giving homeless people a secure and convenient place to stash documents would be a great outcome. Birth certificate, military discharge papers, licences, 2FA codes. Many homeless people live in cars and have all this stashed somewhere in the car, but then the car gets stolen/towed (e.g. because they haven't paid car registration) and then they're sleeping rough, without docs.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#273
post #262

There is a huge disconnect between two types of companies. The majority of companies seem to view email addresses and phone numbers as largely permanent identifiers. Then there are the companies that actually provide you those things. To them, what they provide you is definitely not permanent.

[deleted]

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#274
post #249

Earlier quoted context omitted.

You're absolutely right. Now let's talk about how much effort and what level of resources it's reasonable to expect a commercial entity to invest in extending protections to vulnerable people in need who happen to not be customers. Perhaps we're asking the wrong entity to address this problem? This seems more like a public service infrastructure problem.

Google is a multi-billion dollar company, they barely have to lift a finger. They simply have to provide an option to opt out of 2FA. Add a bunch of warnings if you must. Even if Google was a small startup it would be trivial for them to do this.

To be clear, your answer to vulnerable people needing protections is to lower the minimum level of security for everyone using Gmail. Do I understand correctly?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#275
post #257

Earlier quoted context omitted.

> there is reasonable debate to be had on how to best provide access to essential services to vulnerable populations. What is the debate? The government can collect taxes and provide services, like they do for multitude of other needs. > I'm not sure what a correct answer here looks like, but I don't think ignoring the need is an approach that gets us to a better society or enables vulnerable populations to better ca…

> what is the debate? The debate parent mentioned is what to do with the money, not where to get money. You can see that there are lots of possible options, right? But you say use taxes like it’s ‘duh, easy’ or something. Now we’re in the realm of the debates actually happening every day in the US, whether to provide social services at all, before we even discuss how much money they need, what to do with it, and wher…

> A huge portion of people this country seem to believe that they don’t benefit from taxes and would prefer safety nets for other people not come out of their pockets.

Exactly, and they love it when people waste time and energy blaming businesses for not providing charity. This whole tweet storm should not be directed at Google, but directed at the US federal government.

> This also sounds like you think it’s easy, without considering the implications. (If govt resources is the solution, why do we still have a problem?)

Because it is purely political. Stalling progress on providing essentials for life helps keep people from getting help, and hence keeps taxes lower. If the US government can do identity verification for passports at USPS offices, it can do the same for other purposes.

>We don’t have municipal or federal Gmail or Facebook, and there are reasons to believe programs like that would take a long time and cost a lot of money.

If the world’s leading country cannot setup email infrastructure, then we have huge problems. Presumably, it already does for the how many million federal employees?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#276

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? I think we also have to realize that not everyone who is homeless has problems that can explain it away. It's easy to look at someone who is homeless and tell yourself, "Oh, he's a dope addict. He did this to himself." It's only very rarely true, and you're only making excuses for not helping another human…

Just trying to motivate some empathy, "there but for the grace of God go I." You are correct than many homeless people are not carless, or they suffer from housing uncertainty (couch surfing, itinerant sleepers rolling through difficult family situations and severe housing shortages). Probably they can manage 2FA though.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#277
post #111

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

> The problem here is that misapplied empathy can lead to terrible decisions.

That's not the problem, that's a vague wave at a generic class of innuendo that could be used just as easily to rationalize not allowing your child to eat ice cream or Japanese internment. You have to make the case why Google changing their 2FA system is so much more important than the homeless having phone service, you can't just say "sometimes, empathy can be bad."

I'm not getting that from the rest of the comment, which seems like a gish gallop around a bunch of other things that we're also not going to do for the homeless, and about which you or somebody else can say "it's only human to be worried about other people going through these issues, but empathy can be bad. The answer isn't that HUD should change the second line of the third section of Form B, it's that we should fix the homeless problem completely."

edit: We can't use as an excuse for not making small changes that we should be making larger changes. The excuses that one makes to avoid making small changes will apply more so to larger changes.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#278

It's a valid point that I don't expect Alphabet to address. Honest question : what about those security code? I'm not homeless but I expect my phone to die anytime. It's from 2015. I want to bring it to 2025 but it might not make it. As a result I planned for that phone stopping to work and my understanding is that I will be able to emergency 2FA with those code once it broke. Am I wrong?

How do you expect homeless people who can't hold on to their phones to hold on to the backup codes?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#279
post #238

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

OK. Let's play a game. Let's say I care. Let's say I care a lot . I care so much that I'm willing to make it my personal problem to address the very real, very pressing needs of a critically vulnerable and marginalized part of my community from inside Google. What am I going to do? Is anyone going to be happier if I stand up and proclaim loudly how much I care? Probably not. Could I say "Gee, what if we just let ever…

What do you think the moral of Jurassic Park was?

If you dont know how to control what happens in the park you build, then the park will be shutdown.

In the case of Google its not hard to speed up the process of shutdown. I just encourage them to keep working on more and more mindless ivory tower trash like Pixel phones, watches etc and inject more Ads into everything. They dont have the imagination for anything else but want a pat on the head for whatever they build. Give it to them.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#280
post #111

Earlier quoted context omitted.

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

To be fair, some of us have been calling attention to this problem for a long ass time, and nothing is being done about it. E-mail needs to be a regulated utility, given that getting locked out of one’s email happens all the time with catastrophic consequences.

Don't single out email. The problem is much larger than that. Any big megacorp nowadays figured out that the best way to do whatever they are doing is to provide the service to the median consumer, and just cut the rest out as perfectly as they can. It started with the idiotic get a number to wait in line at the branch offices, IVR audio labyrinths on the phone, completely useless self-service portals, and now there are no branch offices anymore, and in many cases the "helpdesk" is just a dumb caricature of a robot in a fucking submenu of a tragedy of a hacked together mobile app.

Sure, it's great that gmail is cheap, after all "it's free". But Google (and MSFT, fuck outlook.com in particular for their completely anti-competitive spam "protection" that only accepts email from other big providers) cross-finances gmail from their ad business, completely distorting every kind of service and product markets.

---

For email in particular what's needed is a LetsEncrypt-like community-driven solution for reputation management and acceptance of emails from reputable sources by the big inbox providers.

Post reply on HN