Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

41–50 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#41
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution.

How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#42
post #3

I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system h…

Wtf Calling homelessness a "niche" .. peak apres moi le deluge

Exactly. The word people should be looking for is "vulnerable". They are not a niche category, they are a vulnerable category, and need protection, not dismissal.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#43
post #23

Won't using e.g. Authy with Gmail for 2FA alleviate the need for a phone number after the initial setup (i.e. requiring a number only once, to initially enable 2FA)? https://authy.com/guides/googleandgmail/

How do you use Authy if you lose all of your possessions every few months?

[deleted]

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#44
post #4
post #2

Google has a lot of issues, but the gist of these twitter posts, is that homeless people lose their phones multiple times a year, and their phone number, and this makes 2fa hard. But, I mean, why are they not railing on the phone companies, to make it easy for the homeless to keep the same phone number?! Why is this Google's fault?

This is not just the homeless, there was a post on HN from a librarian talking about the same issues for the elderly and socially disadvantaged. The issue is that Google forces 2FA on them, even if they otherwise don’t have a phone.

This post was also very misleading. The concerns the librarian raised were actually addressed. The doc was old and made public by somebody other than the librarian, who edited it after it blew up to make it clear that the content was out of date.

======

Addition, 08/02/2022, 3:03pm: I don’t know how this got shared to HackerNews. I appreciate all of the positive responses we have gotten. However, this was not an open letter. It was meant to be shared internally to Google. It went directly to the security team and we had a conversation about it about a year ago. Things have improved significantly since then and this is no longer a daily problem. Please stop calling the branch or emailing me about it. It’s interfering with my work. Press inquiries can be made through https://libwww.freelibrary.org/contact/ and the public relations department will be in touch with you.

If you want to learn more about patron privacy and support librarians advocating for patron privacy and against big tech please check out https://libraryfreedom.org/ which is a wonderful organization I am a part of that does work like this. I still firmly believe in and stand by everything that I wrote. But this particular action was not meant to be a public letter.

Also! If you’re in Philadelphia you should check out this big program we’re doing on August 12th called Empathy Versus Misinformation where a panel of experts will address questions and misconceptions about transgender youth!! Boy am I relieved that this was a Google Doc and I can just put whatever I want onto the front page of HackerNews now :)

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#45
post #18

Earlier quoted context omitted.

Maybe we don't need to meet all those requirements simultaneously. The on boarding process could try to determining if 2fa would actually benefit you or not.

>The on boarding process could try to determining if 2fa would actually benefit you or not. How?

By asking you?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#46

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

My dad helps people navigate the system to find housing.

Recent story was a 65yo + veteran living in a shelter. They hadn’t started collecting social security due to some debts and was worried it would ALL be garnished.

After explaining that veterans get expedited in line for housing and that they would still get almost all of their SS, they have applied for it and should be housed soon.

It doesn’t surprise me at all that 2FA causes problems after hearing many stories similar to this one.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#47
2FA that delegates to SMS needs to be illegal and addressed by congress at this point. Whats "actual" happening is you're delegating authentication to another company that performed either a hard credit check the person (the vast majority of us) or has a prepaid (likely the situation above). In both cases, it's delegating of IDV and needs to be outlawed.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#48
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

[deleted]

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#49
post #26
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

Probably a dna solution, not that you'd want google to have that info directly.

The problem with biometrics like that is that if the data is stolen or otherwise accessed then it can't be reset. If an attacker has your fingerprint and you use that for 2FA you can't reset that to prevent them from having access.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#50

I don't think access to email is the biggest concern the homeless have. It sucks, but there are alternatives besides gmail and if google is going to spend time on this, I'd rather they not and instead spend time on getting homeless into homes.

What about when you want to apply to a job or an apartment which requires email?
Post reply on HN