Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

481–490 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#481
I feel for these folks. I'm housed and never wanted my email (and a host of other services) to become dependant on my phone number. I've gone so far as telling service providers "I don't have a phone, deal with it" (which is getting harder and harder).

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#482

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

The average person cannot remember a good password without some help, be it using it everywhere, writing it down, or using a password manager. Homeless individuals, on average, have many more stressors in life, much higher rates of traumatic brain injury, and a number of other factors that make their ability to remember good passwords much worse than the average person. Given this solution doesn't work for the averag…

How many passwords does an homeless person need to remember ?

I’m with you that an average person is probably using at least dozens of services that need credentials, but these people are probably not login on Amazon or checking their 401k online for instance, nd can probably get by with a a very limited set of stuff to remember.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#484
post #373

Earlier quoted context omitted.

Reinstall the app and restore private keys from off device backup. The lack of key backup and restore is one big reason not to use Google's authenticator app. Other compatible apps are not so brain dead. I backup every time I add a new sign in. If you don't have the ability to sign in from multiple devices and the ability to install access onto any new device, then you're doing it wrong. Phones are highly portable de…

The problem here boils down to this: how does this help people who don't have secure, reliable storage for off device backup?

pcloud.com

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#485

Earlier quoted context omitted.

> Not having 2FA is going to allow some portion of users to get hacked. When those users do get hacked they will need a way to regain control of the account. I don't think they do! This would be part of the tradeoff. Currently, people who cannot use or rely on 2FA are getting locked out of their accounts even if they weren't hacked and knew their password! Isn't that worse?

> Currently, people who cannot use or rely on 2FA are getting locked out of their accounts even if they weren't hacked and knew their password! Isn't that worse? I don't think so. You seem to presume the end state of both is that the user is locked out, which is only half true. With a lost 2FA device, the user and everyone else is locked out of the account. With a compromised account, the user may be locked out but t…

But the locked account is much more likely than the compromised password in the real world.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#486

Earlier quoted context omitted.

> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…

2fa is a good option, but there are many situations where a plain password is just superior. if you ignore this reality, that passwords are legitimately more secure and better for a lot of people, then you're undermining an existing working security system and will just cause chaos and loss for people.

And to generalize, I'd say that...

"There is an imperfect existing solution, with a problem, therefore we will ban the existing solution and move to a new, better one"

... should require extraordinary certainty in completeness of ones new solution before banning the previous.

There are very few times when the legacy method should be deprecated, and Google is the poster child of someone who shouldn't be trusted to recognize them.

(Looks pointedly at Chrome mv2/3 hubris and implementation clusterfuck)

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#487

Earlier quoted context omitted.

The problems are downstream of that. Not having 2FA is going to allow some portion of users to get hacked. When those users do get hacked they will need a way to regain control of the account. Methods of regaining access to an account are notorious for bad actors social engineering their way to gaining control of accounts. 2FA relieves some of that, because even if you do get hacked you can provide a token from the a…

> I don't find it paternalistic. The goal is to cut down on support costs by reducing the number of users who get hacked and need assistance regaining access to their accounts, and to force users to have a method of demonstrating they own the account even if they can't log in. That it confers some additional security to users is nice, but not really the end goal. So we should be mindful of Google's profit margins, in…

We should probably not force private companies to spend (or lose, no difference) money to solve societal problems that they are in no way responsible for.

That's like forcing pepboys to change the tires of senior citizens for free because social security isn't paying enough.

Maybe we should put our efforts towards fixing problems instead of asking private companies to put a bandaid on it at their expense.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#488

Earlier quoted context omitted.

The correct solution to this and a shitload of other problems is a real, national ID program. But there's enough resistance to it in both US political parties that it can't happen. The lack of it causes a ton of stress, over the population, and is a drag on the economy, but we're just never gonna fix it. Instead we'll de-facto have one (or more) anyway, including 99% of the risks that a real one would carry with it t…

There was a bill to improve digital identity in the us Congress but I don't think it went anywhere. I wrote my congressman about it more than once. https://www.congress.gov/bill/117th-congress/house-bill/4258 edit: Actually there is a similar bill being sponsored in the senate now this year. So something is happening https://www.congress.gov/bill/117th-congress/senate-bill/452...

Yeah, it's brought up from time to time but the right hates national ID programs and enough on the left don't like it (including elected officials, not just voters—the distinction's worth mentioning) that it'd take an implausibly-huge supermajority of Democrats to ever pass such a thing.

Never mind that all the things they're worried about would barely even be easier with an official national ID versus what exists now. Let alone hard/impossible without one.

But no, we just suffer though tons of wasted time for all bureaucratic processes and all kinds of hassle keeping our documents in order and tons of fraud and abuse instead. For no benefit. So we can pretend the government can't already "make a database" about dissidents or gun owners or Christians or whoever very nearly as easily and effectively as if we had an official national ID, if they wanted to. Sigh.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#489

Earlier quoted context omitted.

Why does email need to be a regulaty utility when there are other methods of communication?

Great question! The long version (if it’s patronising please skim forward, I’m writing as an explainer for anyone else that comes along): E-mail was originally a means to communicate informally between two participants over the Internet. In this early version of the system the message would leave your machine, go to your Mail server, then the recipients mail server, then their inbox. This would complete the transmiss…

Really Original e-mail, the mail server was your computer (mainframe) where your account was. It's Greg@ because that's Greg's username when he logs in. Greg doesn't need outlook because his mail is just a folder of text files. There's a mail agent but it's running on Greg's computer.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#490

Earlier quoted context omitted.

That's also a bad response. The tech industry literally exists to invent things. That's its entire purpose. Why should we satisfied with a status quo that neglects the most vulnerable among us? What is the point of technology if not to solve these problems?

Is there a solution? The claim in the link is that homeless people lose every single one of their possessions after a period of time. They also have minimal access to support structures that could be used as a recovery system. We've had decades of work on authentication and pretty much every solution either involves using a password manager to create unique passwords or having possession of a physical thing.

The 3-2-1 backup strategy requires an offsite backup. It's unclear what advantage was forseen by the homeless when the decision was made to forgo this guidance.
Post reply on HN