Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

521–530 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#521
post #111

Earlier quoted context omitted.

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…

[deleted]

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#522
post #498

Earlier quoted context omitted.

That's almost exactly what Google has done. Here's how you turn off 2FA on your account: 1. Go to myaccount.google.com 2. Press "Security" 3. Press "2 step verification" 4. Enter your password 5. Press "Turn off" 6. Confirm the dialog that says "Turning off 2-Step Verification will remove the extra security on your account, and you’ll only use your password to sign in."

Those steps don’t actually turn off 2FA for Google accounts. If you login from a new computer or unrecognized IP, Google forces you to use the YouTube app on your phone to enter a “code” to login. It sometimes doesn’t even let you get a text code. God forbid I lose my phone or delete the YouTube app and login from a new IP. I don’t know how I would even get into my account. I don’t know how this isn’t a wider spread…

[deleted]

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#523

Here's the solution: Since OP is regularly in contact with 30+ homeless people, he can offer to be their backup email account. He can then confirm the identity of people if they lose access to their account and help them get it back. Or, he can safely store their 2FA backup codes in his house. The homeless make up like 0.1% of society. And not every homeless person has this issue. It would be insane to make any featu…

> Here's the solution: Since OP is regularly in contact with 30+ homeless people, he can offer to be their backup email account. He can then confirm the identity of people if they lose access to their account and help them get it back.

> Or, he can safely store their 2FA backup codes in his house.

Why even have security? Your solution practically screams for those 30+ people to be taken advantage of.

Just use a different email provider whose procedures align with how you regularly change your phone number.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#524
post #495
post #300

Earlier quoted context omitted.

I took one step: 1) Don't use anything Google.

I get funny looks when people ask for my email. I have @protonmail.com email

I have that too! : ) That is dedicated for the important things.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#525

Earlier quoted context omitted.

That's a bad example. The unoccupied hotel was vandalized before the homeless were moved in. Yes, it a boondoggle, but nothing to do with homeless.

I don't think it was the local homeowners stealing live copper from the walls.

Sounds like it could be a ring of criminals who are connected to those who can buy copper.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#526
post #450

Earlier quoted context omitted.

I recall that the problem was broader than 2FA. They also re-verify accounts that have been idle, or that are being accessed from a new location. Or issues if you've forgotten the password and don't have a phone.

This is exactly it. And if you don't have a verification method on file, Google will just lock the account if it thinks something about your browser or IP address is unusual. Even if you know your password.

Speaking as a long-time Gmail user who doesn't have a mobile, this is kind of terrifying. Sounds like I need to look into moving to Fastmail or somesuch pronto.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#527

Not only Google. A much less critical or important thing but underlines the bad attitudes: I just tried to renew my cancelled Netflix membership yesterday. I am not allowed to do that without providing a phone number (I used Netflix for ca. 8 years without it). I do not provide that because I do not want to. I do not tie every aspect of my life to my phone number. In fact I do not want to tie any aspect of it to my p…

>A much less critical or important thing but underlines the bad attitudes: I just tried to renew my cancelled Netflix membership yesterday. I am not allowed to do that without providing a phone number (I used Netflix for ca. 8 years without it).

If you've got some spare time, have you considered taking them to small-claims court for refusing to cancel your membership and still charging you? It'll cost them a huge amount if they show up, and if they don't then you get a judgement against them by default. Or if you signed some contract agreeing to only use specified some Netflix-specified legal intermediator, use that.

If everybody who was screwed over by tech companies took legal action against them, it'd cost the companies a huge amount of money and they'd have to improve the way they treated people.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#528

Earlier quoted context omitted.

That's a bad example. The unoccupied hotel was vandalized before the homeless were moved in. Yes, it a boondoggle, but nothing to do with homeless.

I don't think it was the local homeowners stealing live copper from the walls.

But it also wasn't homeless people being legally housed there. If your point is "people who live there take better care of the space", then that's what Austin is trying to do. Convert squatters stealing copper to the kind of people who live there.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#530
post #523

Here's the solution: Since OP is regularly in contact with 30+ homeless people, he can offer to be their backup email account. He can then confirm the identity of people if they lose access to their account and help them get it back. Or, he can safely store their 2FA backup codes in his house. The homeless make up like 0.1% of society. And not every homeless person has this issue. It would be insane to make any featu…

> Here's the solution: Since OP is regularly in contact with 30+ homeless people, he can offer to be their backup email account. He can then confirm the identity of people if they lose access to their account and help them get it back. > Or, he can safely store their 2FA backup codes in his house. Why even have security? Your solution practically screams for those 30+ people to be taken advantage of. Just use a diffe…

Why would Chad Loder take advantage of them? Yes, it gives him the ability to, but that doesn't mean he will.

Why have security? So some random, untrusted person can't compromise the account. If Chad holds the codes, then only he can compromise the account, and maybe their relationships are good enough that they would trust him.

Using a different email provider also works, but I assumed there would be some reason that doesn't work - android effectively has a built in gmail client, non-tech people might just autocomplete "@gmail.com" and mess up someone's address if it is a non-expected domain, etc.

Post reply on HN