Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

361–370 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#362
post #112

Earlier quoted context omitted.

People can't remember many good passwords. So they start reusing them. If one site has a leak, everything is lost without 2FA.

So the choice is for them to permanently lose access to their email? Homeless people aren't stupid and strong password don't have to be incredibly hard to remember. I'd rather get my accounts hacked because of password reuse than lose access to my email, forever. There is literally nothing more important than your email. Even stuff like your bank account has secondary means of recovery, whereas if you lose access to…

> I'd rather get my accounts hacked because of password reuse than lose access to my email, forever.

step 1: get your account hacked

step 2: hacker changes password

step 3: lose access to your email, forever

What you've presented is not in fact a dichotomy, for any practical purposes.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#363

Earlier quoted context omitted.

The problems are downstream of that. Not having 2FA is going to allow some portion of users to get hacked. When those users do get hacked they will need a way to regain control of the account. Methods of regaining access to an account are notorious for bad actors social engineering their way to gaining control of accounts. 2FA relieves some of that, because even if you do get hacked you can provide a token from the a…

> I don't find it paternalistic. The goal is to cut down on support costs by reducing the number of users who get hacked and need assistance regaining access to their accounts, and to force users to have a method of demonstrating they own the account even if they can't log in. That it confers some additional security to users is nice, but not really the end goal. So we should be mindful of Google's profit margins, in…

It's security vs homeless access to vital services. I think it's a diffiult line to draw

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#364
post #198

Earlier quoted context omitted.

> Actually giving homes to the homeless would probably be cheaper than whatever we are doing now, even taking into account the mental illness and drug-abuse problems that factor into this. This point is worth reiterating. Homelessness can be solved by providing housing. Yes, homelessness is a complex multi-faceted problem, but the first order solution to the problem is to provide housing. Homelessness is a problem wi…

Unfortunately it's more complicated than this. There have been nonprofit organizations and government initiatives to give homeless people space in unoccupied hotels for example. What ends up happening is they generally just destroy the living space in a variety of ways. It's because the majority of homelessness is an issue of mental health. In the USA, there are pretty much zero mental health resources for people in…

Source on both mental health being the majority and that generally the homeless will destroy the space they are given?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#365
Every solution/alternative would always impose challenges that can be considered an edge case initially until it becomes permanent.

For example, if Google wants people (who have a tendency to lose their 2FA devices more often) to always use this feature, and in case they lose access to their device, they could use a trusted designate who can verify on their behalf that they are the ones signing into the service. But then again, this alternative will impose some new challenges such as:

- What if the designate is not available? - Designate is available but also lost their access to verify the other person?

As with this case being raised here, it will always be a process wherein Google (or any other organization) will have to explore and find meaningful solutions that is both inclusive and considerate on specific conditions.

The variability alone of such premise is huge that I am quite sure when the next edge case comes up, there are other edge cases boiling down that will become the next set of issues.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#366

Earlier quoted context omitted.

> but the actual response is that without 2FA even more people lose access to their accounts This is not black and white. It is possible to encourage 2FA but allow to opt out. The same for phone numbers. And that's why companies enforce 2FA: they want your juicy phone-number or other data. And yeah, maybe they also want to reduce support costs and avoid bad publicity. Still, it's not in your interest, it's in theirs.…

> It is possible to encourage 2FA but allow to opt out. You might be surprised to learn that this is how it works for Google accounts: it is default-on but you can turn it off. > If they at least would allow for a sufficient number of options. Like paper-tan (even self printed), yubikey or similar, second email address, an authenticator, ... but even big companies often only require a phone number. You might be even…

Can't turn it off for Google Ads account any more. Won't let you in. This is a real pain for shared google account in a small team like ours. Sick of Google removing user choice.

We all knew password, no problems at all. Now it mandates 2FA. And because they mandate it for Google Ads, now it's on for everything like Google Drive etc.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#368
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. This is not a technical problem and should not be automated away. Rely on trustworthy third parties. Universal utilities like Google should have retail outlets which are adapted to local conditions and can exercise educated judgement. In some cou…

I don’t think there’s any universe where a company runs an international chain of retail outlets in order to support a free email service. If that were the standard, free email providers just wouldn’t exist outside of bundles with other services.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#369

Earlier quoted context omitted.

> Actually giving homes to the homeless would probably be cheaper than whatever we are doing now, even taking into account the mental illness and drug-abuse problems that factor into this. This point is worth reiterating. Homelessness can be solved by providing housing. Yes, homelessness is a complex multi-faceted problem, but the first order solution to the problem is to provide housing. Homelessness is a problem wi…

> Homelessness can be solved by providing housing. They used to be called asylums, and the problem is what to do if the homeless person refuses to go. I wonder why you don't hear about homelessness in totalitarian states...

Asylum is one type of housing for people.
Post reply on HN