Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

421–430 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#421
post #274

Earlier quoted context omitted.

To be clear, your answer to vulnerable people needing protections is to lower the minimum level of security for everyone using Gmail. Do I understand correctly?

No, please reread.

Ah! Then the problem is solved, I suppose.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#422

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

Someone with a drug addiction or mental health issues needs treatment _now_. Access to email is a lower priority.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#424

Earlier quoted context omitted.

Is there a solution? The claim in the link is that homeless people lose every single one of their possessions after a period of time. They also have minimal access to support structures that could be used as a recovery system. We've had decades of work on authentication and pretty much every solution either involves using a password manager to create unique passwords or having possession of a physical thing.

Surgical implanting yubikeys. That won't at all bother anyone homeless, because there's never been a homeless person who was a conspiracy theorist. (Obvious sarcasm detected)

An only-slightly-less-sarcastic solution would be to get a tattoo of the recovery codes.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#425

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…

>...often forgotten...

The great thing about something like an email service is that password guessing can be extremely rate limited. You miss three guesses and you can't log in for several hours. So an easily remembered password is perfectly fine unless it is blindingly obvious. As a homeless person loosing access to a phone on a regular basis, I am going to be comfortable with the risk that the Gmail password hashes might get leaked. I think others would be quite comfortable with that risk as well...

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#426
post #181

You lose your entire Google account if you lose your 2FA device or number (assuming it's a phone number), for any reason. Even if your Google account is set up with a non-Google email address which you still have access to, and you still know the correct password. And there's nobody you can reach at Google about it, no appeals process, nothing. https://news.ycombinator.com/item?id=33098261

One of the many reasons why I switched from GMail to Fastmail.

Google accounts are required for many other Google services besides Gmail. Replacing Gmail is the easy part.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#427
post #111

Earlier quoted context omitted.

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

Yup. Why break 2FA when we could have the Obamaphone program work with the case workers so that they don’t loose track of people in the first place? Also, homelessness isn’t the problem we think it is. It’s millions of problems. Any solution will never help more than a subset of the homeless population. We need to iterate on small solutions to make progress.

Utter nonsense. Mandated treatment for drug addiction and severe mental illness would tackle half the problem.

Then provide contingent housing based on staying sober, sticking to your treatment plan, and getting a job. You can graduate when you’re able to pay your own way.

For non-addict/mentally ill homeless, it’s housing contingent on employment, graduate when you can pay your own way.

This would solve 90% of the problem.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#428

Earlier quoted context omitted.

The problems are downstream of that. Not having 2FA is going to allow some portion of users to get hacked. When those users do get hacked they will need a way to regain control of the account. Methods of regaining access to an account are notorious for bad actors social engineering their way to gaining control of accounts. 2FA relieves some of that, because even if you do get hacked you can provide a token from the a…

> I don't find it paternalistic. The goal is to cut down on support costs by reducing the number of users who get hacked and need assistance regaining access to their accounts, and to force users to have a method of demonstrating they own the account even if they can't log in. That it confers some additional security to users is nice, but not really the end goal. So we should be mindful of Google's profit margins, in…

Is Google a vital service or is email a vital service?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#429

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

More people ought to read this: https://blog.jaibot.com/the-copenhagen-interpretation-of-eth....

Google is already providing a free service to homeless people. It's not empathy to tell someone else to solve a problem that you care about. That's virtue signaling. If he cares, he should take matters into his own hands.

Is it too much to ask a single person to build a free email service for all homeless people? Perhaps, but the good news is that he doesn't have to. Google already allows you to disable 2FA [1]. He could have started a campaign to disable 2FA on homeless people's phones, but instead he uses this as an opportunity to shame Google to boost his own Twitter follower count.

I think that empathy is highly overrated. I doubt anyone notorious for flashing their big Johnson is particularly empathetic, yet LBJ expanded social services more than any other President. The problem isn't that people have too little empathy these days. It's that people are too easily impressed by broadcasting their intentions rather than actually trying to solve a problem.

[1] https://support.google.com/accounts/answer/1064203

Post reply on HN