Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

471–480 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#471

"Unhoused people" The newspeak is strong with this one. There was never anything wrong with the word homeless. Have progressives gone too far?

Back in Seattle the lingo was "persons experiencing homelessness". I feel like the more syllables you can get in there, the more PC it gets.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#472

I agree there should be more explicit support here, but can this not be "solved" with backup codes? One or more could be given to a trusted person – a family member, a friend, or even a trusted librarian – or a backup code could be remembered. The tough issue here is that these access edge cases look a lot like malicious use. The aren't but authenticating someone who has no device or ID or really much else to authent…

Backup codes could work - but if they have the support of a trusted person they likely can be assisted in other ways, too. Defining a state-sponsored email account that can only be logged in from specific government machines (imagine a kiosk at the DMV, say) where there are trained clerks who can identify homeless in some way could work.

An interesting idea, but I suspect it just pushes the issue back one more step. How do you authenticate for login to that email account? Specific machines limits but doesn't fundamentally change the attack surface.

If the person has ID, then many options work, but if they don't what can a DMV and trained clerks do that others can't in some way?

Lastly, I'm not from the US but even I've heard that the DMV is a hellish place with queues hours long. Putting more barriers in front of those who are already in a tough spot (and may need to spend that time working, queueing for shelters, etc) is a big ask.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#473

Earlier quoted context omitted.

I definitely vividly remember needing it a few years ago, but right now I can try to sign up and it says "Mobile Number (optional)" (Maybe that's based on some security heuristics).

Yeah and it also only works on your phone (or if you know how to make Google think you are on your phone) and in certain countries. All to my knowledge and based on my tests.

I just did it from Firefox on Linux in a private tab near Washington, D.C.. Fake name, no phone, no backup email. I was able to log out, sign back in, and send an email without any trouble.

No doubt they're letting me through because some security heuristic says I'm a real human, and I'm sure they'd eventually make me provide a number if I continued using the account (this happened to me with my university G Suite account a couple years ago and I needed to contact my IT department to manually disable the phone challenge), but so far I can't see any evidence that they're doing anything unreasonable.

Perhaps they're requiring you to use a number because you've tested it a lot.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#474

Earlier quoted context omitted.

this feels like a workaround. We should not be treating phonenumbers as SSN round two, where everyone relies on it for your identity, and it should never be changed because of how much shit was needlessly tied to it. I rue the day I need to change my phone number and my digital identity becomes a huge headache, especially for far flung services that decided they wanted my phone number, but I wouldn't have considered…

The correct solution to this and a shitload of other problems is a real, national ID program. But there's enough resistance to it in both US political parties that it can't happen. The lack of it causes a ton of stress, over the population, and is a drag on the economy, but we're just never gonna fix it. Instead we'll de-facto have one (or more) anyway, including 99% of the risks that a real one would carry with it t…

There was a bill to improve digital identity in the us Congress but I don't think it went anywhere. I wrote my congressman about it more than once.

https://www.congress.gov/bill/117th-congress/house-bill/4258

edit: Actually there is a similar bill being sponsored in the senate now this year. So something is happening

https://www.congress.gov/bill/117th-congress/senate-bill/452...

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#475

Earlier quoted context omitted.

> In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. This is not a technical problem and should not be automated away. Rely on trustworthy third parties. Universal utilities like Google should have retail outlets which are adapted to local conditions and can exercise educated judgement. In some cou…

I don’t think there’s any universe where a company runs an international chain of retail outlets in order to support a free email service. If that were the standard, free email providers just wouldn’t exist outside of bundles with other services.

We treat email almost as we used to treat postal mail: we expect it to be available to all ("digital transition" replacing human-fronted public services with digital one).

If we treat it as a utility, it's fine to regulate it as such. If want to make money, directly or indirectly, by offering email service, they should have some standard of service. If they can't we can just make it public service, which wouldn't let make money out of it, but would also guarantee it's available to all.

Either way, eating the cake and leaving it whole, like it is now, shouldn't be an option.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#476

Earlier quoted context omitted.

> How about the homeless person remembers a good password, Which would go one of two ways: 1. One uses the same password one uses everywhere else, and now one is much more vulnerable to credential stuffing 2. One is reliant on a book of passwords or a password management app on one's phone, resulting in the same exact problem we're trying to solve

being homeless doesn't mean you don't have the ability to remember a good password. good means not duplicated.

Even people not dealing with the stress and trauma of being unhoused have trouble remembering passwords - even when they're shared across accounts, let alone when they're unique. This ain't a "homeless people are dumb" argument; it's a "humans gonna human" argument.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#477

Earlier quoted context omitted.

> Actually giving homes to the homeless would probably be cheaper than whatever we are doing now, even taking into account the mental illness and drug-abuse problems that factor into this. This point is worth reiterating. Homelessness can be solved by providing housing. Yes, homelessness is a complex multi-faceted problem, but the first order solution to the problem is to provide housing. Homelessness is a problem wi…

Some homeless people don't want to deal with the maintenance of a home. Some homeless people aren't capable of the maintenance of a home due to mental or physical issues. Some homeless people refuse to accept help for mental issues for fear of being trapped in a psych ward. Simply put, you need to split homelessness into temporary and chronic populations. For the temporary group, homelessness is the problem. For the…

> Some homeless people don't want to deal with the maintenance of a home.

You've got a good point. These leaves are really starting to pile up, and the snow will be upon us soon. I think I'll just say fuck it and sleep under a bridge, and leave the grounds keeping to the parks department.

You did set up a straw man solely to get knocked down, right? In actuality, the idea of giving "housing to everyone" doesn't mean an idyllic single family stick-and-drywall dwelling with a yard, but rather something communal - like a less-populous more-dignified shelter with a modicum of persistent personal space. The maintenance would be institutional, and come out of the same operating budget as administration, utilities, etc.

I feel like most of the "some homeless just want to be homeless" argument revolves around baking in assumptions that public housing should come with a bunch of strings attached, to make the residents' lives "better". In your comment, this is the responsibility for maintenance or mental health treatment. Such conditions are what turns people off, not some intrinsic love for sleeping rough.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#478

Earlier quoted context omitted.

If the service is truly vital it should be provided by the government, not Google. The government would also be free to set security policies and provide support at the level and cost demanded by the public. It is not and should not be the role of a private enterprise to act as a backstop for the fabric of society when it is not in their interests or their customers' overall interests.

The vital services are provided by the government, but require an email address. Some people have trusted Google to be their email provider, and Google is failing some of those people by denying them access unnecessarily.

I'm saying that if the public/government doesn't feel like Google's security policies are compatible with the homeless, the simplest solution is to set up a government-run email host.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#479
post #294

Earlier quoted context omitted.

> The problem here is that misapplied empathy can lead to terrible decisions. That's not the problem, that's a vague wave at a generic class of innuendo that could be used just as easily to rationalize not allowing your child to eat ice cream or Japanese internment. You have to make the case why Google changing their 2FA system is so much more important than the homeless having phone service, you can't just say "some…

I can make a very specific case for it. Out of 1.5+ billion users, millions of which are barely tech-literate and vulnerable, with gmail a constant target for malicious entities. That means intuitively at least hundreds of thousands of vulnerable people getting cleaned out of their life savings. Changing things for billions in exchange for a marginal benefit to thousands is bizarre. It's not a 'gish gallop' but a fra…

So you don't want Google to do anything or what is the purpose of all this verbiage? Which moreover, unjustly dismisses whole issue as "marginal benefit to thousands". Being able to keep/recover email address is so much more than a marginal benefit, and there are many more than thousands of homeless in the US alone.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#480
post #451
post #111

Earlier quoted context omitted.

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

>In this case, we actually aren't being ambitious enough. Why are we having a system where we give out phones every 12 weeks to each homeless person? We'd probably save money for the program by developing some sort of dedicated device designed to be harder to steal or lose. Maybe a high-autonomy low-powered KaiOS smartphone that can be attached as a strap? It's not like the current devices are working. You're putting…

I agree that it would be a good start. What I'm saying is that the system of having to replace phones every 12 weeks is dysfunctional on its own and probably should be looked at.
Post reply on HN