Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

511–520 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#511
post #111

Earlier quoted context omitted.

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…

> Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)."

Google allows someone of your choosing, who must also have a GMail account, to takeover one's account after x months of inactivity. It's not great but it's better than nothing and it has the benefit of being an option that exists today.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#512
post #15

Earlier quoted context omitted.

The phone number decision is stupid. I up and jump countries every few years. Each time, I'm switching to a new number. I'm the opposite of homeless, I'm that jet set elite. The idea that you want, need, should or will tie your identity to a phone number where people can always reach you is long outdated.

What’s painful is that I’ve ported my phone number out to a VoIP provider similar to Google Voice for exactly this purpose, but something like 25% of providers now block using SMS for 2FA unless it’s tied to an approved mobile phone operator. Turns out 2FA is also being used as a low-effort form of a captcha in addition to being a tool for data harvesting and “device identification”. I wouldn’t be surprised if legiti…

Was just reading about how Overwatch 2 won't let people register with a prepaid phone number.

I'm sure there is some good reason to want to avoid people spinning up free or ultra low cost phone numbers to make extra accounts but some users were like, "I've been using TracPhone for a decade" or something like that. Also pretty surprised that it's this easy to detect the carrier. Guessing we'll see this more and more!

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#513
Just the other day had an experience where someone in need, freshly moved to a new country, asked to use my phone to email a relative asking for money to buy a phone. When I realized they would need to log in to their gmail, I felt sorry knowing it almost certainly won't work. It didn't. Thankfully Facebook worked.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#514

Earlier quoted context omitted.

Even if this is the case, this isn't a problem for the poster. They have a phone number, it just changes frequently. They can sign up, enroll in a TOTP or U2F system, and then they are set.

Except if you're using e.g. Google Authenticator and you lose that phone, you've now lost your TOTPs. The most unhoused-friendly solution there would be to use something like Authy instead (which is another password to remember, but at least it makes it easy to recover your TOTP keys on a new device without needing the old one); next best would be to use something like andOTP which supports backups (but then you'd ne…

The context for this post is a person who moves between countries frequently and therefore gets new phone numbers. This person has consistent access to the same phone.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#515
post #111

Earlier quoted context omitted.

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…

How about just don't use Google services, Tutanota is free and is just as good.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#516
It seems to me that the government service responsible for providing the phone should be expanded to provide a permanent digital identity, including email, and a lasting phone number. A permanent address (open and scan, with selective forwarding) for physical mail would also be worth investigating.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#517
post #493

This is a non-issue. When signing up for 2FA google provides a set of backup codes and instructions on how to use them when access to your phone number is lost. I don't work for google, and recognize they have many other issues, but this person on twitter is incorrect. There are other methods in addition to backup codes. There are voice authentication and id upload. I've even had Google call me back, and I spoke to a…

The article mentions that "maintaining possession of anything physical is difficult" for the homeless. Let's say they print out the backup codes...but then their backpack gets stolen. Or it just rains and ruins the paper.

[deleted]

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#518

Earlier quoted context omitted.

> They hadn’t started collecting social security due to some debts and was worried it would ALL be garnished. Is this common? I knew a guy who had the same mindset. I ended up paying him in cash for some work, he was convinced that if he made any money in a traditional role it would be instantly garnished.

It is unfortunately common. We're not perfectly rational robots, and so for a decent subset of the population, they go off what has happened to them. And being paid $1k and assuming they'd have $1k and then discovering they only had $500 because of garnishment tells them "don't accept checks, cash is the only safe method". And then it's not a step much further to be "it's not worth setting up social security because…

Don't you still leave jail with new debts because they charge you for your stay?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#519

Google's 2FA is dreadful. 2FA is a good idea when it's added with consent, but Google adds it behind your back in ways that are both infuriating and brain-dead. I've been caught out recently twice: once I was away on work and had to access my email. Google demanded that I verify it using my phone that I'd previously accessed my work email with. However, this phone was just a phone I use for development, had never had…

Disclaimer: I work at Google. I've never seen this issue. I don't have 2FA enabled for any personal Google account. There are some dark patterns to try and get you to enable 2FA that I don't agree with, e.g. a big "add a phone number to your account" page after you log in, with a small "skip for now" button at the bottom.

This doesn't involve a phone number, and I haven't enabled 2FA either. This is a security check that's activated under some combination of unfamiliar location, WiFi network, or device. It requires you to confirm your identity by using the app.

If you delve though GMail's settings, under "Sign-in and recovery":

  Trusted mobile devices
  Google can verify that it's you by sending sign-in notifications to a private 
  phone or tablet. You can remove it in your recently used devices.
There's no way to turn it off as far as I can see. You can remove a device from the authorised list, but that's not very helpful if you don't realise that it's been added.

It's idiotic. It's essentially: "confirm that you're allowed to access your email by confirming that you already have access to your email".

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#520
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

Over on /r/sysadmin there was a discussion this morning about email systems for dementia patients. How do you provide for someone that is forgetting that they are forgetting?

Pretty much EVERYONE will have cognitive decline in their twilight years. It would be nice if we could have communication systems that are compatible with basic human biology.

Post reply on HN