Earlier quoted context omitted.
OK. Let's play a game. Let's say I care. Let's say I care a lot . I care so much that I'm willing to make it my personal problem to address the very real, very pressing needs of a critically vulnerable and marginalized part of my community from inside Google. What am I going to do? Is anyone going to be happier if I stand up and proclaim loudly how much I care? Probably not. Could I say "Gee, what if we just let ever…
I guess I don't see a lot of difference between the practical results of loudly proclaiming empathy vs. loudly proclaiming cynicism.
Gmail 2FA causes the homeless to permanently lose access 3 times a year
331–340 of 770 posts
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#332Earlier quoted context omitted.
Do they really ask for a phone number, or would a Yubikey work as well?
A yubikey would be as useless in this article's specific case, as the problem is losing valuable things (eg, phones). A yubikey is no different. It too would be lost.
Essentially, if you rule out possession, your choice is between server-side validated biometrics (if offered at all), or "double knowledge" (e.g. a password and email 2FA, with the email account also only protected by a password), which is pretty phishable.
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#333Earlier quoted context omitted.
> Actually giving homes to the homeless would probably be cheaper than whatever we are doing now, even taking into account the mental illness and drug-abuse problems that factor into this. This point is worth reiterating. Homelessness can be solved by providing housing. Yes, homelessness is a complex multi-faceted problem, but the first order solution to the problem is to provide housing. Homelessness is a problem wi…
Some homeless people don't want to deal with the maintenance of a home. Some homeless people aren't capable of the maintenance of a home due to mental or physical issues. Some homeless people refuse to accept help for mental issues for fear of being trapped in a psych ward. Simply put, you need to split homelessness into temporary and chronic populations. For the temporary group, homelessness is the problem. For the…
Sometimes mental issues are purely genetic but often they can also arise from or be exacerbated by trauma. And homelessness sure is traumatic.
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#334Is homeless a temporary or permanent state? How many homeless have been so for longer than four months?
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#335Earlier quoted context omitted.
Oddly, I suspect if Google provided no free accounts at all--if you had to give a credit card and pay $5 to sign up--nobody would be complaining about this. Which leads me back to the point made elsewhere in this thread: we have too high an expectation for what private companies can or should do, because they have taken the place in our minds if government. And our expectations for what government can or should do ar…
> Oddly, I suspect if Google provided no free accounts at all--if you had to give a credit card and pay $5 to sign up--nobody would be complaining about this. That is like saying 'if the DMV didn't offer IDs to people, no one would complain about not being able to get an ID'. The fact of the matter is that email is 'de facto' online ID, and gmail has positioned itself into this role. They are now a societal need, not…
If email is a societal requirement--and maybe it is, or should be--public utilities should provide it.
It's easy to build an email provider. Why shouldn't your state or local government provide one?
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#336Earlier quoted context omitted.
This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…
Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#337Earlier quoted context omitted.
Did you even read the linked thread, of a person apparently actually working with homeless people? It explicitly mentions that email is the preferred method of communication for many of them, for reasons also mentioned in the thread. > The homeless have challenges, no doubt, but that does not imply google worrying about 2FA for the homeless is the best way to solve those challenges. You seem to be under the impressio…
And you seem to think doing the easiest thing is actually useful.
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#338Earlier quoted context omitted.
Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…
That wouldn't help at all unless it was the default.
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#339In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…
> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?
Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good solution for people who, as the OP says, aren't capable of keeping track of a physical device for more than N weeks?
I'm not unsympathetic to the problems of the homeless ant the burdens 2FA entails, but I'm also not willing to ignore the huge problems the 2FA solves, and realizing there will often be a tradeoff between making it very difficult to hack into accounts and making it easy for people with mental and other problems access their accounts.
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#340Earlier quoted context omitted.
This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…
Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…
Not having 2FA is going to allow some portion of users to get hacked. When those users do get hacked they will need a way to regain control of the account. Methods of regaining access to an account are notorious for bad actors social engineering their way to gaining control of accounts.
2FA relieves some of that, because even if you do get hacked you can provide a token from the authenticator that was attached to the account, proving that you do in fact own that account.
> I think it's excessively paternalistic to not provide that option.
I don't find it paternalistic. The goal is to cut down on support costs by reducing the number of users who get hacked and need assistance regaining access to their accounts, and to force users to have a method of demonstrating they own the account even if they can't log in. That it confers some additional security to users is nice, but not really the end goal.