Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

31–40 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#31
post #3

I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system h…

Wtf Calling homelessness a "niche" .. peak apres moi le deluge

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#32
post #15

Earlier quoted context omitted.

The phone number decision is stupid. I up and jump countries every few years. Each time, I'm switching to a new number. I'm the opposite of homeless, I'm that jet set elite. The idea that you want, need, should or will tie your identity to a phone number where people can always reach you is long outdated.

Sticking my German sim card into my phone for fifteen minutes in all sorts of random countries and continents and waiting for a number to come through always feels absurd. I pray for the rise of esims! I feel like it's on the cards.

I've been using eSIMs for the past couple of years for this specific use case, and while they certainly help, it's really just a stop-gap measure:

You still need your phone and cell signal to receive them (at least many European carriers don't support SMS over VoWIFI); the eSIM is "stuck" in your phone if it physically breaks (and on many carriers, you can't re-use an eSIM QR activation code in any case); in many countries, SIMs expire after a couple of months or even weeks of inactivity, losing your number permanently, to name just a few.

I've found Google Voice to work quite well as a workaround for almost all of these problems, but unfortunately, many US companies insist on not allowing VoIP numbers for 2FA or even plain account creation purposes. I usually try to avoid these companies.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#33

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

Counterpoint, I taught several older relatives in my family how to use 1Password.

UX for good security can exist, but it does need a little bit of education.

We will all be old one day but I have trouble believing we will just forget how to use computers. On the other hand, we do need to carefully consider the role google plays in our lives… especially for us Europeans, who are just at the mercy of a US company’s whims.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#34

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

"Not-my-problem" is a bad response, but the actual response is that without 2FA even more people lose access to their accounts. Anything that makes it harder for adversaries to take over an account almost necessarily adds friction for the users themselves. This isn't a "fuck the people who don't have regular access to a phone, they don't matter" situation. It is a "there is an aggravating balancing act in this situation and no solution will avoid harming everybody."

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#35

Won't using e.g. Authy with Gmail for 2FA alleviate the need for a phone number after the initial setup (i.e. requiring a number only once, to initially enable 2FA)? https://authy.com/guides/googleandgmail/

The issue is described further in the Tweet chain: Physical property retention is more or less impossible; these people typically end up getting their phones stolen every month to 4 months. The same would be true of IDs or other paperwork that could be used to prove their identity.

They get phones from a government program. Each new phone has a new number, and due to the above challenges, it'd be challenging to port numbers and keep a consistent number.

Authy accounts are keyed to your phone number, and to set one up on a new phone you have to receive a verification call/text.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#36
I'm a bit surprised, homeless people have phones and email addresses?

Sorry for question, but it is a bit mind blowing for me, in my country homeless people are rare and the ones I see don't worry about anything besides something to eat and alcohol. So having a mobile for them would be like having cash to buy the mentioned things.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#37
post #18
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

Maybe we don't need to meet all those requirements simultaneously. The on boarding process could try to determining if 2fa would actually benefit you or not.

>The on boarding process could try to determining if 2fa would actually benefit you or not.

How?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#38
post #32

Earlier quoted context omitted.

Sticking my German sim card into my phone for fifteen minutes in all sorts of random countries and continents and waiting for a number to come through always feels absurd. I pray for the rise of esims! I feel like it's on the cards.

I've been using eSIMs for the past couple of years for this specific use case, and while they certainly help, it's really just a stop-gap measure: You still need your phone and cell signal to receive them (at least many European carriers don't support SMS over VoWIFI); the eSIM is "stuck" in your phone if it physically breaks (and on many carriers, you can't re-use an eSIM QR activation code in any case); in many cou…

> the eSIM is "stuck" in your phone if it physically breaks

Wait, does this happen?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#39
post #21
post #15

Earlier quoted context omitted.

The phone number decision is stupid. I up and jump countries every few years. Each time, I'm switching to a new number. I'm the opposite of homeless, I'm that jet set elite. The idea that you want, need, should or will tie your identity to a phone number where people can always reach you is long outdated.

So use one of the other 2FA options.

Not always a possibility. Many banks require phone number based 2FA, for example. And you're required to use it any time you want to make a transaction that exceeds some threshold.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#40
post #21
post #15

Earlier quoted context omitted.

The phone number decision is stupid. I up and jump countries every few years. Each time, I'm switching to a new number. I'm the opposite of homeless, I'm that jet set elite. The idea that you want, need, should or will tie your identity to a phone number where people can always reach you is long outdated.

So use one of the other 2FA options.

(FWIW, my bank does not provide any other 2FA options.)
Post reply on HN