Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

431–440 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#431

Is homeless a temporary or permanent state? How many homeless have been so for longer than four months?

It is temporary because they can just buy / rent a home

Just stop being poor or mentally ill, easy.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#432

Earlier quoted context omitted.

If your face hurts, maybe you should stop punching yourself in the face. Update your software.

Equating lack of software updates to punching oneself in the face is part of the whole problem.

It's not though. No one writes perfect software on first release. Even perfect software adapts to the changing realities of our world. Staying up to date is not optional.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#433
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

> How about the homeless person remembers a good password,

Which would go one of two ways:

1. One uses the same password one uses everywhere else, and now one is much more vulnerable to credential stuffing

2. One is reliant on a book of passwords or a password management app on one's phone, resulting in the same exact problem we're trying to solve

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#434
post #429

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

More people ought to read this: https://blog.jaibot.com/the-copenhagen-interpretation-of-eth... . Google is already providing a free service to homeless people. It's not empathy to tell someone else to solve a problem that you care about. That's virtue signaling. If he cares, he should take matters into his own hands. Is it too much to ask a single person to build a free email service for all homeless people? Perhaps…

looks like loder is talking about problems their own friends face, and the post is not directed at anyone in particular. venting is not virtue signaling

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#435
They should try other free email services. It’d be nice if Google voice was still free and somebody could help set that up as their persistent number. That said, Google 2FA is mission critical for many people’s online identity and is protecting them from a world of online evils, this is not a reason to step back from a security posture that Google has rightly decided protects its users.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#436

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…

2fa is a good option, but there are many situations where a plain password is just superior. if you ignore this reality, that passwords are legitimately more secure and better for a lot of people, then you're undermining an existing working security system and will just cause chaos and loss for people.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#437

Earlier quoted context omitted.

> I don't find it paternalistic. The goal is to cut down on support costs by reducing the number of users who get hacked and need assistance regaining access to their accounts, and to force users to have a method of demonstrating they own the account even if they can't log in. That it confers some additional security to users is nice, but not really the end goal. So we should be mindful of Google's profit margins, in…

If the service is truly vital it should be provided by the government, not Google. The government would also be free to set security policies and provide support at the level and cost demanded by the public. It is not and should not be the role of a private enterprise to act as a backstop for the fabric of society when it is not in their interests or their customers' overall interests.

The vital services are provided by the government, but require an email address. Some people have trusted Google to be their email provider, and Google is failing some of those people by denying them access unnecessarily.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#438
How about building a solution (or a possible solution)?

I think it is fair to guess that many people reading this have achieved some level of success building solutions to technology problems. Much like solving for malicious use for the average user with 2FA - or privacy with things like protonmail - why shouldn't some of us attempt to solve this rather than expect/complain that Google hasn't?

Mail hosting isn't particularly expensive - companies like mxroute are sub $1 per GB per year with deliverability, etc taken care of - or at least well enough to make it better than constantly changing addresses.

I know that I personally would be willing to invest time and non-trivial amounts of money to offer a solution and gauge adoption and feedback.

Some opinions (open to feedback!) on where to start:

1. Use existing mail provider from the start - mxroute looks like a possibility

2. Overprovision storage by some reasonable factor - say 1GB accounts with 10x overprovisioning - interested to hear from those who know more than me about this but I wonder if more unhoused/homeless people generally use email for mostly transactional purposes not 20mb JPEGs, etc.

3. Ensure the webmail interface (possibly build it) is Ultra simple and Super accessible - screen readers, text to speech, and of course mobile first. Again I (perhaps naively) imagine that features like tagging, rich content composing, and filtering are super low priority here.

4. Have a sign up flow that is mildly fraud resistant - mobile number verification (VoIP not accepted) with a cool off before it can be used for another account (how often do Obamaphone numbers rotate/deactivate once stolen?) and an (accessible) captcha type system to avoid mass sign ups. This could then in V2 be expanded to include more corner cases - possibly invites in lieu of phone numbers, etc. If fraud/spam became an issue it should be easy to detect given these will generally be low volume users.

5. Require only a modestly secure password for login. Use malicious use detection to trigger recovery/verification mode (see next).

6. Have a recovery/verification mode that fits the user group - need ideas here - but 5 questions that you have to answer 4 of and have some verification that the answers are not just simple words at setup? Combine that with verify with a real (but possibly different) mobile (non-VOIP) number that hasn't been used in X days to verify another account? Trusted friend recovery address? Seems like lots of possible solutions to explore here, and no doubt lots of people smarter then me who could provided ideas.

Is there interest in doing this? Am I the only one that feels frustrated when we (including myself) debate what google should do, or why people are unhoused (or what to call people how are) when many of us are capable and financially able to at least try to offer a solution?

With 500k-1M homeless/unhoused in the US (no reason it couldn't be international, just starting somewhere) - let's say it was crazy successful and had a 10% adoption rate of actual active usage. Maybe that's 7.5 TB of storage. I'm sure a reputable provider would be willing to partner to provide that at $1/gb/year or less (plus hosting webmail, etc) - I'd be willing to pay that bill personally for that kind of adoption/benefit. Would others? Would others dedicate their time?

Homelessness is multifaceted - that seems to be the one thing everyone agrees on - so offering possible solutions to any given facet - from fragmented communications to safe shelter - is at least a start and possibly a small part of making a difficult life situation a little easier to overcome/deal with.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#439
post #112

Earlier quoted context omitted.

People can't remember many good passwords. So they start reusing them. If one site has a leak, everything is lost without 2FA.

So the choice is for them to permanently lose access to their email? Homeless people aren't stupid and strong password don't have to be incredibly hard to remember. I'd rather get my accounts hacked because of password reuse than lose access to my email, forever. There is literally nothing more important than your email. Even stuff like your bank account has secondary means of recovery, whereas if you lose access to…

> So the choice is for them to permanently lose access to their email?

If an attacker breaks in and changes your password, you already do very likely permanently lose access to your email. Account recovery from that point is a hairy process even for people who have a place to safely store important documents, let alone those who don't.

> Even stuff like your bank account has secondary means of recovery

Those rely on forms of identification that the unhoused disproportionately lack (for the same reasons that they are more prone to lose access to phone numbers). This is also among the reasons why being unhoused tends to correlate with being unbanked.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#440

Earlier quoted context omitted.

> I don't find it paternalistic. The goal is to cut down on support costs by reducing the number of users who get hacked and need assistance regaining access to their accounts, and to force users to have a method of demonstrating they own the account even if they can't log in. That it confers some additional security to users is nice, but not really the end goal. So we should be mindful of Google's profit margins, in…

Is Google a vital service or is email a vital service?

Neither. Gmail is an email provider which has provided access to an account that these people have registered with providers of vital services.
Post reply on HN