Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

351–360 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#351
post #111

Earlier quoted context omitted.

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…

The case workers could have an email account to use as the recovery email account. This already exists.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#353

Earlier quoted context omitted.

The problems are downstream of that. Not having 2FA is going to allow some portion of users to get hacked. When those users do get hacked they will need a way to regain control of the account. Methods of regaining access to an account are notorious for bad actors social engineering their way to gaining control of accounts. 2FA relieves some of that, because even if you do get hacked you can provide a token from the a…

> I don't find it paternalistic. The goal is to cut down on support costs by reducing the number of users who get hacked and need assistance regaining access to their accounts, and to force users to have a method of demonstrating they own the account even if they can't log in. That it confers some additional security to users is nice, but not really the end goal. So we should be mindful of Google's profit margins, in…

If the service is truly vital it should be provided by the government, not Google. The government would also be free to set security policies and provide support at the level and cost demanded by the public. It is not and should not be the role of a private enterprise to act as a backstop for the fabric of society when it is not in their interests or their customers' overall interests.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#354
post #112

Earlier quoted context omitted.

People can't remember many good passwords. So they start reusing them. If one site has a leak, everything is lost without 2FA.

So the choice is for them to permanently lose access to their email? Homeless people aren't stupid and strong password don't have to be incredibly hard to remember. I'd rather get my accounts hacked because of password reuse than lose access to my email, forever. There is literally nothing more important than your email. Even stuff like your bank account has secondary means of recovery, whereas if you lose access to…

> I'd rather get my accounts hacked because of password reuse than lose access to my email, forever.

This is functionally the outcome of getting hacked, if you want any kind of decent security measures.

Any way that Google can give you access back on a password-only account is going to be rife with bad actors using social engineering to gain control of accounts. As long as that form/page exists, it is a threat vector.

What you're asking is for the password to be the only proof that someone owns an account, which means a hacker can demonstrate ownership just as much as you can.

Banks have more options for account recovery because we're willing to give them a lot more info. They can force me to come in to a branch and compare my ID to my face, or ask for my SSN, or any number of things we're not comfortable handing over to Google (especially over the web).

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#355

Earlier quoted context omitted.

Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…

The case workers could have an email account to use as the recovery email account. This already exists.

While I don't think that's a bad idea in some situations, it means trusting the case worker with access to the entire account (as they could use the recovery email to reset the password). It's also an extra burden to put on the case worker, and the individual who has to coordinate with the case worker.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#356
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

Quite simply there are multiple factors at play here. Do you force 2FA on almost everyone and reduce hostile account takeovers to negligible? Do you allow for no 2FA and permit the homeless use case?

I think Google faced a trolley problem and made the right decision. You need a different tool "homeless mail" for them.

It's Gmail. You don't have to use it. There's a lot of mail providers out there.

Whatever, if this guy won't set it up I will. I'll stick a 20 msg / hr, 100 / day limit on it and call it a nice anti-spam day.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#357

Earlier quoted context omitted.

I'm really curious. What would you propose? The best I can think of is trusted backup accounts, which already exist. A homeless person with regular attachment to a family member or a social worker could set up that person's account as a backup. But this already exists and is likely to fail for a large number of homeless people, who tend to struggle at maintaining long term relationships with family members or social…

I don't have one. I'm not a security expert or researcher or anything like that. But the tech industry has invented thousands of things that to most people would have been inconceivable beforehand. That doesn't mean there's a way to improve on the tradeoffs we have now — but the fact that no one's invented it yet doesn't mean it can't exist. The tech industry self-styles as the smartest people in the world, who try t…

> The tech industry self-styles as the smartest people in the world, who try to solve the hardest problems.

I think this is a good point, but the catch is that there's an implicit footnote that needs to be attached to "the hardest problems*": "*Which generate sufficient monetary returns". This particular problem isn't one that has much revenue potential.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#359

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

People can't remember many good passwords. So they start reusing them. If one site has a leak, everything is lost without 2FA.

Is it though? Just because a password leaked doesn’t mean it will actually be abused. A homeless person without a credit card in their Google account is naturally limited in the amount of damage that can be done.

Security questions are probably enough, at least for people who can’t handle 2FA.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#360
I want out the ability to opt out of this 2FA nonsense. I’m not a journalist in a war zone, I’m just a guy who wants to read his email (with a 64 character password containing random ASCII characters). 2FA is just an excuse to make the abuse departments life easier by raising the cost of botting accounts.
Post reply on HN