Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

441–450 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#441

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

> How about the homeless person remembers a good password, Which would go one of two ways: 1. One uses the same password one uses everywhere else, and now one is much more vulnerable to credential stuffing 2. One is reliant on a book of passwords or a password management app on one's phone, resulting in the same exact problem we're trying to solve

being homeless doesn't mean you don't have the ability to remember a good password. good means not duplicated.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#442

Earlier quoted context omitted.

To be fair, some of us have been calling attention to this problem for a long ass time, and nothing is being done about it. E-mail needs to be a regulated utility, given that getting locked out of one’s email happens all the time with catastrophic consequences.

Why does email need to be a regulaty utility when there are other methods of communication?

Great question!

The long version (if it’s patronising please skim forward, I’m writing as an explainer for anyone else that comes along):

E-mail was originally a means to communicate informally between two participants over the Internet.

In this early version of the system the message would leave your machine, go to your Mail server, then the recipients mail server, then their inbox. This would complete the transmission and a copy would exist at both ends.

Companies providing ostensibly free online e-mail inboxes have slick sign-up funnels that on the surface seem to be offering a very similar system as the one above, with very little in the way of regulation around either the sign-up funnel or the mailbox (and which do not explain the catastrophic life consequences that can occur as a result of losing access to your mailbox).

These new mailboxes work differently from those of the early Internet, though:

1) Your mail is sent to your mail server. A copy may or may not be retained locally.

2) Your mail server transmits the message to the recipients mail server as before.

3) The recipient receives a notification of the e-mail and may or may not retain a copy locally.

This infrastructure is ubiquitous and now not quite 30 years after the early Internet we have an issue where you’ll be required to have an e-mail address for almost all public services and common accounts that have little to no online component. Your entire life, more or less, may pass through that inbox.

If one day you lose access to the account (in that you insert your password and the provider says no), you will lose access to your entire e-mail history.

You may attempt to reset some passwords for essential services, but you can’t, because they’re sending e-mails to verify your identity - which you’ll never be able to receive.

You move on, create a new account, and attempt to start over. However, e-mails - potentially important e-mails containing personal information - continue to be delivered to a mailbox that you can’t access ever again. Maybe you miss some important alerts.

Perhaps it was a gmail account that had your entire photo and video history in google photos. That’s now gone too. With your passwords, if you’re using chrome passwords.

You rebuild, and a couple of years pass, and perhaps someone else gets access to your account (either through a hack, or a rogue employee with access rights, or someone who guessed a badly thought out password).

You never find out that the account was accessed, so have no-one to complain to, and maybe you end up with savings or 401K/pensions getting emptied. Which in a lot of cases wouldn’t be discovered until they’re due to be collected.

Some of the above might sound far-fetched, but you’d be surprised how much having access to an email inbox is accepted proof-of-identity in 2022.

Hence the need for regulation.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#443

Earlier quoted context omitted.

Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…

This is a result of taking a product made by someone else for a certain purpose and then using it for one it isn't intended. Its not Google's fault gmail is a bad fit here. They didn't design it with this use case in mind. The solution is to use one that is. Why are case workers directing the homeless to setup gmail accounts? Because they haven't been provided with a better solution by the system they work within. So…

Gmail is a perfect fit in theory. Google provides a product, workspace, where you can hand out gmail addresses and reset them at need. Given that the cost of providing such accounts is actually less because the support burden falls on the city it might be possible to convince Google to provide them at less than the standard cost.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#444

Earlier quoted context omitted.

and thus does the problem continue because those who could help are too busy making themselves feel better with as little effort as possible. It's 2FA ... for homeless people.

Partial solutions that take minimum effort are great. It's like replacing a single incandescent light with an LED. Sure it doesn't solve climate change, but it definitely helps, and doing easy helpful things is way better than not doing them and complaining that the problem is big.

pretty much every ineffective strategy has been rationalized at some point.

email implies internet, 2FA implies realtime internet. The lack implies very poor at the very least up to and including homelessness.

"this one company uses 2FA, we should bitch at them until they remove that need" doesn't actually help anything.

This person who posted the tweet could offer their personal phone, email, and internet for these homeless friends they have. Why don't they? I bet they'll say it's because it doesn't solve the "real" problem.

Yeah, neither does asking google to spend money on removing 2FA for the homeless.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#445

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

> How about the homeless person remembers a good password, Which would go one of two ways: 1. One uses the same password one uses everywhere else, and now one is much more vulnerable to credential stuffing 2. One is reliant on a book of passwords or a password management app on one's phone, resulting in the same exact problem we're trying to solve

No. One can just remember a good password for gmail, and either use other passwords elsewhere (maybe bad, re-used, ones, or maybe good ones, not relevant if we're talking about gmail), or just always authenticate elsewhere using your gmail account.

Remembering one good password is not too onerous. Easier, it seems, that keeping any physical object in your possession if you're homeless. (I would assume that most losses are not due to cognitive failure, but instead are things like thefts when one is asleep.)

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#446
post #111

Earlier quoted context omitted.

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…

That's almost exactly what Google has done. Here's how you turn off 2FA on your account:

1. Go to myaccount.google.com

2. Press "Security"

3. Press "2 step verification"

4. Enter your password

5. Press "Turn off"

6. Confirm the dialog that says "Turning off 2-Step Verification will remove the extra security on your account, and you’ll only use your password to sign in."

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#447
post #429

Earlier quoted context omitted.

More people ought to read this: https://blog.jaibot.com/the-copenhagen-interpretation-of-eth... . Google is already providing a free service to homeless people. It's not empathy to tell someone else to solve a problem that you care about. That's virtue signaling. If he cares, he should take matters into his own hands. Is it too much to ask a single person to build a free email service for all homeless people? Perhaps…

looks like loder is talking about problems their own friends face, and the post is not directed at anyone in particular. venting is not virtue signaling

Loder has 130k Twitter followers without any claim to fame besides Twitter, so he knows exactly what he's doing. If he had vented about his friends cutting themselves with a knife that's too sharp, he would have been ridiculed, but in this case he can hide behind the Google hate bandwagon.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#448

Earlier quoted context omitted.

Who's to say that your email account getting hacked is less dire than losing access to it? Attackers can easily search your inbox for 'verify your email', visit any website of value, and use their access to change the account away from your email to an address that they own, effectively removing your access to your third-party website accounts entirely.

I don't know that it is less dire, but I do think it's less likely. Are homeless people's email accounts getting hacked three times per year? Also... maybe getting hacked is worse, or maybe loosing access is worse, but the user should have the right to make that decision! Google can set the default, but the user knows his or her own life.

> Are homeless people's email accounts getting hacked three times per year?

The aversion to 2FA makes them seem like easy targets if I'm looking for addresses to use for spam.

> maybe getting hacked is worse, or maybe loosing access is worse, but the user should have the right to make that decision

Getting hacked makes losing access considerably more likely. This ain't one or the other.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#449

Earlier quoted context omitted.

It's security vs homeless access to vital services. I think it's a diffiult line to draw

I don't think it's difficult! • The people who want security get to keep all the security they get today. • The people who don't think about security and leave default settings intact keep all the security they get today. • The people who explicitly ask for less security get less security. • Some of the homeless will get increased access to vital services. It's a win-win—unless you believe, for some reason, that peop…

>The people who explicitly ask for less security get less security.

The problem with that is less security is almost always more usable than more security, which leads to the greater amount of people being in that state, which is not just a danger to the user making the choice, it is a danger to others.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#450

Earlier quoted context omitted.

Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…

That's almost exactly what Google has done. Here's how you turn off 2FA on your account: 1. Go to myaccount.google.com 2. Press "Security" 3. Press "2 step verification" 4. Enter your password 5. Press "Turn off" 6. Confirm the dialog that says "Turning off 2-Step Verification will remove the extra security on your account, and you’ll only use your password to sign in."

I recall that the problem was broader than 2FA. They also re-verify accounts that have been idle, or that are being accessed from a new location. Or issues if you've forgotten the password and don't have a phone.
Post reply on HN