Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

51–60 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#51

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

No, people like you really highlight the “If they don’t help everyone then they are being immoral” mentality. Which is wrong. Down grading security for the benefit of a tiny minority with an especially ridiculous use case is not the greater good. If the homeless people think they are at risk of losing their phone then they should pick another free email vendor.

This is a simplification of the problem. Both:

1. Vulnerable populations need more assistance accessing essential services required to participate in society

2. Service providers need to maintain a reasonable level of security for their customers

Can both be true. Saying that maximum (or minimum) levels of security are required at all time completely misses the point of security--which is to mitigate risk. How much risk is appropriate varies a lot by context.

Beyond the context of risk, there is reasonable debate to be had on how to best provide access to essential services to vulnerable populations. It's pretty important to have an email nowadays and if you're not tech savvy or an individual/community has little to no money to spend it's not unreasonable to have the reality of the matter be that there may simply not be many good alternatives (or awareness of alternatives) to GMail.

I'm not sure what a correct answer here looks like, but I don't think ignoring the need is an approach that gets us to a better society or enables vulnerable populations to better care for themselves.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#52
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

So if there are certain vulnerable categories of people who cannot use any form of 2FA, where does that leave 2FA?

Seems to me it should mean that it has to be optional, at least until we solve that problem.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#53
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

>The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile dissidents, journalists, and senators who will inevitably have accounts; and at the same time to homeless people who can't keep any physical thing. It's kinda difficult to meet those conflicting requirements well at the same time.

It's only hard if you adopt a one size fits all approach to security.

Google's proclivity towards treating its users as an undifferentiated commodity isnt proof that its users couldnt be treated differently.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#54

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

"Not-my-problem" is a bad response, but the actual response is that without 2FA even more people lose access to their accounts. Anything that makes it harder for adversaries to take over an account almost necessarily adds friction for the users themselves. This isn't a "fuck the people who don't have regular access to a phone, they don't matter" situation. It is a "there is an aggravating balancing act in this situat…

Yep, reducing standards for everyone in an attempt to help a small minority is also a growing trend in the west. Schools dumbing down so everyone gets A’s type of top level decision making.

Sometimes you have to make hard choices where some people get burned because the alternatives are worse. That doesn’t mean you don’t care.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#55
post #35

Won't using e.g. Authy with Gmail for 2FA alleviate the need for a phone number after the initial setup (i.e. requiring a number only once, to initially enable 2FA)? https://authy.com/guides/googleandgmail/

The issue is described further in the Tweet chain: Physical property retention is more or less impossible; these people typically end up getting their phones stolen every month to 4 months. The same would be true of IDs or other paperwork that could be used to prove their identity. They get phones from a government program. Each new phone has a new number, and due to the above challenges, it'd be challenging to port…

[deleted]

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#56
An authenticator app is a much better 2FA solution that I opt for at every opportunity.

Google's authenticator app is brain dead because they want to encourage 2FA over SMS. Why? Because it has the wonderful side effect of destroying your privacy. With your phone number, Google can easily identify you personally. Ain't that special --- privacy invasion wrapped up in security clothing! Much too tempting for Google to resist.

Google didn't invent OTP so there are other apps that are perfectly compatible.

Word to the wise, it should be obvious by now that all things "Google" are synonymous with "privacy invasion".

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#58
I hate services that forcibly enable 2fa on you. Even if you have it disabled, if they detect that you have changed browsers, IP addresses, etc. they make you go through 2fa whether you want it or not. Or just lock you out, or even suspend your account. Fuck that.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#59

Won't using e.g. Authy with Gmail for 2FA alleviate the need for a phone number after the initial setup (i.e. requiring a number only once, to initially enable 2FA)? https://authy.com/guides/googleandgmail/

There are various approaches to 2FA, from backup codes, to SMS, to external physical keys - none of them workable for the specific use-case OP defined: person is homeless and losses their stuff every few weeks.

For that situation no 2FA solution is going to work.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#60
post #38
post #32

Earlier quoted context omitted.

I've been using eSIMs for the past couple of years for this specific use case, and while they certainly help, it's really just a stop-gap measure: You still need your phone and cell signal to receive them (at least many European carriers don't support SMS over VoWIFI); the eSIM is "stuck" in your phone if it physically breaks (and on many carriers, you can't re-use an eSIM QR activation code in any case); in many cou…

> the eSIM is "stuck" in your phone if it physically breaks Wait, does this happen?

That's overly dramatic, of course you can re-create it on the other phone. But what's true is that you can't physically transfer it.
Post reply on HN