Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

291–300 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#291
post #36

I'm a bit surprised, homeless people have phones and email addresses? Sorry for question, but it is a bit mind blowing for me, in my country homeless people are rare and the ones I see don't worry about anything besides something to eat and alcohol. So having a mobile for them would be like having cash to buy the mentioned things.

They are homeless not Amish. People can have jobs too while being homeless, since you often can't afford rent in many parts of the world with just a single income. You have to choose between a roof over your head, or eating and having a car to be able to go to work. Or you can get a second income, either another job or a relationship, but that's not always an option, hence why so many people live in their cars. Around 200,000 people live in their cars in the United States alone, but that number is climbing rapidly and will reach a million in a few years, because housing is a luxury now.

And just to compare, the cheapest completely useful (4G, 3GB RAM, 3000mAh battery, Android 11) smartphone is $30, the average monthly rent of a two-bedroom apartment in the United States is $1300.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#292

"Unhoused people" The newspeak is strong with this one. There was never anything wrong with the word homeless. Have progressives gone too far?

It's meant to imply that private persons shouldn't be allowed to own property, and that a central authority should be responsible for "housing" people.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#293

Earlier quoted context omitted.

> The correct answer is not depending on the largesse of businesses. It is using government resources to provide methods for identity verification, communications, and various other bare minimum needs for living. To be fair I don't see how any government system can do better regarding identity on the internet. Login.gov is one of the best services I've used for access to usajobs/SSA/etc but it follows some of the sam…

The US government uses the USPS to do identify verification for passports. If it can handle identity verification for passports, why would it not be able to handle identity verification for other purposes, such as replacing or reauthorizing one’s MFA device? Hell, it should be trivial to offer federal government provided emails with ID verification with customer service in the event of loss of device/loss of ID/death…

Passports require the most paperwork out of anything - your in particular, a birth certificate, a second form of ID including a driver's license, a photo, and $130+$35. The USPS isn't just looking at a face and issuing a passport.

0The issue here is that homeless don't hold onto anything physical for 4 months; identity verification breaks down in-person immediately as shelters/libraries can't be expected to run a facial recognition operation, and specific shelter employees/volunteers aren't guaranteed to be there anytime a homeless person might walk in and need those backup codes, but it breaks down even further online since 2fa is inherently 'what you know' + ('what you have'/'who you are').

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#294
post #111

Earlier quoted context omitted.

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

> The problem here is that misapplied empathy can lead to terrible decisions. That's not the problem, that's a vague wave at a generic class of innuendo that could be used just as easily to rationalize not allowing your child to eat ice cream or Japanese internment. You have to make the case why Google changing their 2FA system is so much more important than the homeless having phone service, you can't just say "some…

I can make a very specific case for it. Out of 1.5+ billion users, millions of which are barely tech-literate and vulnerable, with gmail a constant target for malicious entities. That means intuitively at least hundreds of thousands of vulnerable people getting cleaned out of their life savings. Changing things for billions in exchange for a marginal benefit to thousands is bizarre.

It's not a 'gish gallop' but a framework for looking at the issue. I'm not saying that empathy is sometimes bad, I'm saying that it can't be the starting point for our reasoning. It can be the impetus that makes us act, but the actual solution should come first. Sure, maybe none of the things I'm proposing will be implemented. Maybe they're all godawful ideas, but I can't fix the problem in the five minutes it took to write the post or even five decades of intense research on my own. But it's clear that keeping to that pseudo-empathy performative martyrdom mindset is an active roadblock against the more ambitious solutions. And it leads to truly awful ideas such as getting rid of encryption, rights, and so on.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#295
post #125

Earlier quoted context omitted.

> it is possible to operate a Google account completely without a phone number This is only true for a limited time. I've tried to use a couple Google accounts this way and inevitably I log in from a new IP and Google's 2FA system kicks in - forcing me to either furnish a phone number or lose access to the account. It's similar to how Twitter forces phone numbers out of people - just not as immediate.

Do they really ask for a phone number, or would a Yubikey work as well?

A yubikey would be as useless in this article's specific case, as the problem is losing valuable things (eg, phones). A yubikey is no different.

It too would be lost.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#296
post #181

You lose your entire Google account if you lose your 2FA device or number (assuming it's a phone number), for any reason. Even if your Google account is set up with a non-Google email address which you still have access to, and you still know the correct password. And there's nobody you can reach at Google about it, no appeals process, nothing. https://news.ycombinator.com/item?id=33098261

I verify that this is true at the time of posting. In previous volunteer work at a non-profit run by university students, the organization assigned a free Gmail account to each executive. Each year, we ran into a problem where the executives would change, and we needed to transfer the Gmail account to the new person.

Problems would happen when the new person tried to log in to the account. Since the login was from an unrecognized device and an unrecognized IP address, security was tightened. Even after inputting the correct password and entering the right backup email, it was mandatory to enter an SMS message from the phone number tied to the account, even after various troubleshooting and attempted workarounds. That meant getting ahold of the previous executive, who may be busy or changed their number.

You could argue that Gmails weren't meant to be used this way, which is fair; the goal of this comment is just to provide additional evidence that the description provided by the parent comment is true. (In the end, we went for a low-cost, reliable email service to fix the issue in the long-term. We also found that registered non-profits are eligible for free Google Workspace or Microsoft Outlook email plans subject to certain eligibility conditions, though we did not have a need of becoming an officially registered non-profit at the time.)

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#297
post #127

Earlier quoted context omitted.

Oddly, I suspect if Google provided no free accounts at all--if you had to give a credit card and pay $5 to sign up--nobody would be complaining about this. Which leads me back to the point made elsewhere in this thread: we have too high an expectation for what private companies can or should do, because they have taken the place in our minds if government. And our expectations for what government can or should do ar…

> Oddly, I suspect if Google provided no free accounts at all--if you had to give a credit card and pay $5 to sign up--nobody would be complaining about this. That is like saying 'if the DMV didn't offer IDs to people, no one would complain about not being able to get an ID'. The fact of the matter is that email is 'de facto' online ID, and gmail has positioned itself into this role. They are now a societal need, not…

Email may be a societal need, but Gmail === Email. They're one email provider in a sea of providers. There are dozens to hundreds of free email provider choices out there.

One doesn't need Gmail to have a functioning email address.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#298
post #79

Earlier quoted context omitted.

Quoted post unavailable.

2FA is not only SMS 2FA.

In practice SMS or mobile specific applications seem to be the only usable option. Some sites do allow email.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#299
post #132

Earlier quoted context omitted.

Yes, but what else? A hardware token can be lost as well, and "in app" push notification (or whatever the app does) you stil need the telephone or at least the SIM/same telephone number, don't you?

No the device auth prompts are completely independent of mobile number, you don't even need a Sim card. Giving homeless people a secure and convenient place to stash documents would be a great outcome. Birth certificate, military discharge papers, licences, 2FA codes. Many homeless people live in cars and have all this stashed somewhere in the car, but then the car gets stolen/towed (e.g. because they haven't paid ca…

>No the device auth prompts are completely independent of mobile number, you don't even need a Sim card.

Sorry, I don't understand, I believed that the independence from the SIM for an app was for an app already installed and authenticated on the specific device.

If you lose the smartphone (with the app), and the SIM, how can you install the app and be authenticated on another device?

I mean short of a SMS or a code via e-mail (both not receivable/accessible).

>Giving homeless people a secure and convenient place to stash documents would be a great outcome. Birth certificate, military discharge papers, licences, 2FA codes. Many homeless people live in cars and have all this stashed somewhere in the car, but then the car gets stolen/towed (e.g. because they haven't paid car registration) and then they're sleeping rough, without docs.

A sort of luggage deposit, you mean?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#300
post #181

You lose your entire Google account if you lose your 2FA device or number (assuming it's a phone number), for any reason. Even if your Google account is set up with a non-Google email address which you still have access to, and you still know the correct password. And there's nobody you can reach at Google about it, no appeals process, nothing. https://news.ycombinator.com/item?id=33098261

I took three steps against this happening: 1) Not providing phone number for 2FA. Never. 2) Using multiple (3 pcs.) physical keys for 2FA (like Yubikey and similar). Authentication app is an alternative for one choice of 2FA (but not the sole one!) 3) Only using a limited set of Google functionality. Use for secondary purposes mostly. Well, the last one is mainly to mitigate the consequences if happens anyway, for ot…

I took one step:

     1) Don't use anything Google.
Post reply on HN