Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

411–420 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#411

An authenticator app is a much better 2FA solution that I opt for at every opportunity. Google's authenticator app is brain dead because they want to encourage 2FA over SMS. Why? Because it has the wonderful side effect of destroying your privacy. With your phone number, Google can easily identify you personally. Ain't that special --- privacy invasion wrapped up in security clothing! Much too tempting for Google to…

Replace sms with yubikey and he first part of this post is correct. But it invalidates the second part.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#412
I think the answer here is not that Google makes bad product design decisions it's that we shouldn't live in a society of incredible wealth but some people still don't have homes and have to sleep in places where they are constantly the victims of property crime.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#413

Earlier quoted context omitted.

Maybe each individual should be allowed to "choose the two" that work best for them. Most of us have at least one email account that's already under our real name, where we have no big interest in hiding our real identity, but we do have a big interest in not being randomly shut down by Google. We hear about such shutdowns every few weeks on HN, if not more. Google has unfathomable financial and technical resources,…

There are a lot of email providers out right now that fit one of the three possibilities OP set out. But most people aren't aware of any of this, choose the one they know of or see first, and get angry when 'it doesn't work right'. Like OP said, all cover is temporary.

The only email provider I'm aware of that still doesn't require a phone number during sign up is protonmail. Maybe tutanota but IIRC they wouldn't let you sign up over a VPN.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#415

Earlier quoted context omitted.

> What ends up happening is they generally just destroy the living space in a variety of ways. Citation very much needed here. This certainly does happen. But, I don’t believe this the general (i.e. typical) outcome. From what I understand talking to acquaintances who work in this area, wrecking the place is not the typical outcome. And property damage is generally cheaper to address than the constant provision of em…

At least a data point here - my city of Austin is buying a hotel to convert into housing for the homeless. This has gone badly. The property sees intense vandalism and destruction, the neighbors are afraid for their safety, and the whole thing is an amazingly expensive boondoggle. [0]: https://www.foxnews.com/us/austin-hotel-purchased-homeless-s... [1]: https://www.statesman.com/story/news/2022/05/16/austin-homel...

Seems like a bad situation. But follow the timetable:

1) Austin buys the property

2) Begins renovations on vacant premises

3) Vandalism takes place

---------------

4) The conversion is complete

5) Property officially offered to homeless residents

Steps 4 and 5 haven't happened yet. So homeless people who "generally just destroy the living space" isn't a good fit for what's going on. This is simply a situation of an unsecured construction site that has attracted squatters and vandals.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#416

Earlier quoted context omitted.

The problems are downstream of that. Not having 2FA is going to allow some portion of users to get hacked. When those users do get hacked they will need a way to regain control of the account. Methods of regaining access to an account are notorious for bad actors social engineering their way to gaining control of accounts. 2FA relieves some of that, because even if you do get hacked you can provide a token from the a…

> Not having 2FA is going to allow some portion of users to get hacked. When those users do get hacked they will need a way to regain control of the account. I don't think they do! This would be part of the tradeoff. Currently, people who cannot use or rely on 2FA are getting locked out of their accounts even if they weren't hacked and knew their password! Isn't that worse?

> Currently, people who cannot use or rely on 2FA are getting locked out of their accounts even if they weren't hacked and knew their password! Isn't that worse?

Not if it's happening to fewer people than the alternative.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#417

Earlier quoted context omitted.

The problems are downstream of that. Not having 2FA is going to allow some portion of users to get hacked. When those users do get hacked they will need a way to regain control of the account. Methods of regaining access to an account are notorious for bad actors social engineering their way to gaining control of accounts. 2FA relieves some of that, because even if you do get hacked you can provide a token from the a…

> Not having 2FA is going to allow some portion of users to get hacked. When those users do get hacked they will need a way to regain control of the account. I don't think they do! This would be part of the tradeoff. Currently, people who cannot use or rely on 2FA are getting locked out of their accounts even if they weren't hacked and knew their password! Isn't that worse?

> Currently, people who cannot use or rely on 2FA are getting locked out of their accounts even if they weren't hacked and knew their password! Isn't that worse?

I don't think so. You seem to presume the end state of both is that the user is locked out, which is only half true.

With a lost 2FA device, the user and everyone else is locked out of the account.

With a compromised account, the user may be locked out but the hacker is not. The hacker is free to impersonate the user to social services, hospitals, potential employers, etc. If there's no mechanism for the user to regain control of the account, the hacker will have that access until the user can contact all of those people and give them a new email address. That could take a while, especially if we're considering that the user has a high chance of not having a phone at the moment.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#418

Earlier quoted context omitted.

There was a followup comment on HN: > Doesn't sound like it was completely resolved. In fact, it sounds like Google may have treated it as a "squeaky wheel," and only that library is getting better help. -- https://news.ycombinator.com/item?id=32309190

So on one hand we've got the actual author of the original document saying one thing and on the other hand we've got an uninvolved internet poster saying something else.

The original author is not saying anything to disclaim what the HN comment said.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#420
An elegant solution here might be to allow users to designate a list of other users who can "vouch" for them; if multiple people who you previously designated as trustworthy say "hey, this is my friend's new phone number, use it instead of the old one for account recovery", then that should satisfy the "who you are" authentication factor (and set the new "what you have" factor).

Similar idea behind web-of-trust or multisig cryptocurrency wallets, except without the cryptographic mumbo-jumbo.

Post reply on HN