Earlier quoted context omitted.
I don't think it's difficult! • The people who want security get to keep all the security they get today. • The people who don't think about security and leave default settings intact keep all the security they get today. • The people who explicitly ask for less security get less security. • Some of the homeless will get increased access to vital services. It's a win-win—unless you believe, for some reason, that peop…
> The people who explicitly ask for less security get less security. The problem with that is less security is almost always more usable than more security, which leads to the greater amount of people being in that state, which is not just a danger to the user making the choice, it is a danger to others.
Gmail 2FA causes the homeless to permanently lose access 3 times a year
501–510 of 770 posts
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#502I mean I've always fantasized about getting NFC into everything so that NFC-based tags could provide convenient "something you have" taps. Like, give me a simple ring on my finger to tap-in to a scanner on my keyboard rather than having to meander through an app on my phone.
The other problem is that with every org running their own auth systems, if you're trying to help a person with this problem you have to set them up on a dozen services. I really wish something like Mozilla Persona had took off.
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#503Earlier quoted context omitted.
> to help a small minority In this case the people asking for 2FA are the "small minority", and the rest of us have to suffer through 2FA-authentication hell because of them.
> In this case the people asking for 2FA are the "small minority", and the rest of us have to suffer through 2FA-authentication hell because of them. How many people don't like 2fa because they don't know about all the times it's saved them from total account takeover?
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#504Earlier quoted context omitted.
>But I assume he implicitly talked about Google (which doesn't provide that option). Google provides backup codes. You can print them on any kind of paper you want. Regardless, OP argued that printed backup codes don't work because everything is lost every few weeks.
Oh really? I didn't see that option. Maybe it's new? If so, that's good!
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#505In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…
> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#506Earlier quoted context omitted.
>But we don't do it, because, in America, our sense of what government can or should provide is atrophied, and we, mistakenly, look to private actors to provide basic public services. I don't think this matches reality. The US government is doing more today than any time point in the past. Spending and taxation as a percent of dgp is at an all time high. There's also a sense that nobody should have to do anything the…
That's fair that I shouldn't make such an unqualified statement. While public spending as a % of GDP has indeed increased, that's primarily driven by two things: increased defence (and related) spending, and increased spending on health costs. In the US, the growth in social assistance spending over the last 3 decades is driven almost entirely by the latter: https://ourworldindata.org/grapher/social-expenditure-as-pe…
This excludes military spending and is adjusted for the purchasing power of those dollars.
I don't know about you, but I don't feel like we are getting 450% more value out of the government services. The numbers are pretty clear that the government is collecting more and more inflation adjusted dollars from people's income than ever before.
I Suspect we would probably agree that the government is not being a responsible steward of this money that it is collecting.
My primary point was that I don't think that the belief that a decrease in government spending and Revenue is reflected in the numbers. Further, I think it is important to push back on the idea that the systemic issues we see can simply be solved by throwing more money into an increasingly inefficient system.
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#507You mean 4 times a year…every 12 wks
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#508This is a non-issue. When signing up for 2FA google provides a set of backup codes and instructions on how to use them when access to your phone number is lost. I don't work for google, and recognize they have many other issues, but this person on twitter is incorrect. There are other methods in addition to backup codes. There are voice authentication and id upload. I've even had Google call me back, and I spoke to a…
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#509Or, he can safely store their 2FA backup codes in his house.
The homeless make up like 0.1% of society. And not every homeless person has this issue. It would be insane to make any feature for like 0.02% of the population. Especially a feature which diminished security. Because yes, those 0.02% of people might have an easier time accessing their accounts, but probably 100x that amount of people are going to end up getting tricked into de-securing their account, or do it by accident, and end up getting compromised.