Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

341–350 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#341

Earlier quoted context omitted.

This post was also very misleading. The concerns the librarian raised were actually addressed . The doc was old and made public by somebody other than the librarian, who edited it after it blew up to make it clear that the content was out of date. ====== Addition, 08/02/2022, 3:03pm: I don’t know how this got shared to HackerNews. I appreciate all of the positive responses we have gotten. However, this was not an ope…

There was a followup comment on HN: > Doesn't sound like it was completely resolved. In fact, it sounds like Google may have treated it as a "squeaky wheel," and only that library is getting better help. -- https://news.ycombinator.com/item?id=32309190

So on one hand we've got the actual author of the original document saying one thing and on the other hand we've got an uninvolved internet poster saying something else.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#342

Earlier quoted context omitted.

Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…

The problems are downstream of that. Not having 2FA is going to allow some portion of users to get hacked. When those users do get hacked they will need a way to regain control of the account. Methods of regaining access to an account are notorious for bad actors social engineering their way to gaining control of accounts. 2FA relieves some of that, because even if you do get hacked you can provide a token from the a…

> Not having 2FA is going to allow some portion of users to get hacked. When those users do get hacked they will need a way to regain control of the account.

I don't think they do! This would be part of the tradeoff.

Currently, people who cannot use or rely on 2FA are getting locked out of their accounts even if they weren't hacked and knew their password! Isn't that worse?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#343

Earlier quoted context omitted.

Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…

The problems are downstream of that. Not having 2FA is going to allow some portion of users to get hacked. When those users do get hacked they will need a way to regain control of the account. Methods of regaining access to an account are notorious for bad actors social engineering their way to gaining control of accounts. 2FA relieves some of that, because even if you do get hacked you can provide a token from the a…

> I don't find it paternalistic. The goal is to cut down on support costs by reducing the number of users who get hacked and need assistance regaining access to their accounts, and to force users to have a method of demonstrating they own the account even if they can't log in. That it confers some additional security to users is nice, but not really the end goal.

So we should be mindful of Google's profit margins, instead of homeless people's access to vital services?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#344
post #21

Earlier quoted context omitted.

So use one of the other 2FA options.

Not always a possibility. Many banks require phone number based 2FA, for example. And you're required to use it any time you want to make a transaction that exceeds some threshold.

We are talking about Google here, right?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#345
post #111

Earlier quoted context omitted.

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…

This seems like something the homeless services are best positioned to fix by providing email hosting to their clients. They know their clients are actual humans, not hackers, so can provide the continuity that the giant providers can't.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#346

Earlier quoted context omitted.

Is there a solution? The claim in the link is that homeless people lose every single one of their possessions after a period of time. They also have minimal access to support structures that could be used as a recovery system. We've had decades of work on authentication and pretty much every solution either involves using a password manager to create unique passwords or having possession of a physical thing.

Password managers are absolutely not required. While they're a good idea for most of us who don't have to worry about having somewhere to sleep, homeless people can still most likely memorize a password and remember it after a few tries. They can't do that if 2FA is forced on them.

Everybody sucks at memorizing unique passwords. I'd be stunned if homeless people are consistently not reusing passwords. Credential stuffing is the #1 form of account takeover and 2FA is the solution.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#347
post #337

Earlier quoted context omitted.

And you seem to think doing the easiest thing is actually useful.

Yes, I do think that doing something useful is useful, even if it is easy.

and thus does the problem continue because those who could help are too busy making themselves feel better with as little effort as possible.

It's 2FA ... for homeless people.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#348

Earlier quoted context omitted.

I'm really curious. What would you propose? The best I can think of is trusted backup accounts, which already exist. A homeless person with regular attachment to a family member or a social worker could set up that person's account as a backup. But this already exists and is likely to fail for a large number of homeless people, who tend to struggle at maintaining long term relationships with family members or social…

> I'm really curious. What would you propose? The solution is very simple. Don't force 2FA. I'm sure most homeless people would rather risk the unlikely case of their accounts being hacked if they didn't choose a strong enough password to memorize than risk getting locked out of their accounts permanently. You can encourage 2FA but forcibly enabling it for everyone does more harm than good, especially to homeless peo…

> The solution is very simple. Don't force 2FA.

And then in alternative-universe HN people are complaining about the rate of account takeovers via credential stuffing and calling Google irresponsible for making it easy to disable a powerful security measure.

> You can encourage 2FA but forcibly enabling it for everyone does more harm than good

I'd wager that pretty much the only people on the planet who can definitively say this are the people who handle account takeovers and lockouts of large email services. My understanding is that the folks at Google responsible for this have concluded that making it behave the way it currently does is the setup that causes the fewest people to lose access to their accounts.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#349
post #198

Earlier quoted context omitted.

Unfortunately it's more complicated than this. There have been nonprofit organizations and government initiatives to give homeless people space in unoccupied hotels for example. What ends up happening is they generally just destroy the living space in a variety of ways. It's because the majority of homelessness is an issue of mental health. In the USA, there are pretty much zero mental health resources for people in…

> It's because the majority of homelessness is an issue of mental health. This isn't true or at least it doesn't start that way. What people don't understand is that there isn't a single homeless population. You have people who are temporarily homeless and people who are chronically homeless. The temporarily homeless are people who lost jobs, fell on hard times, etc etc. The simplest solution for them is yes to give…

yes there are different castes of homeless, some do quite well, and are not problematic. others are of disorganized psyche, and cause much of thier own problems, resulting in no one wanting them around.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#350
post #112

Earlier quoted context omitted.

People can't remember many good passwords. So they start reusing them. If one site has a leak, everything is lost without 2FA.

So the choice is for them to permanently lose access to their email? Homeless people aren't stupid and strong password don't have to be incredibly hard to remember. I'd rather get my accounts hacked because of password reuse than lose access to my email, forever. There is literally nothing more important than your email. Even stuff like your bank account has secondary means of recovery, whereas if you lose access to…

> I'd rather get my accounts hacked because of password reuse than lose access to my email, forever.

When your account is stolen the attacker changes your password. You lose access to your email forever and lose access to all of the services that use your email as a recovery platform.

Post reply on HN