Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

531–540 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#531
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> So what kind of 2FA would be homeless-proof?

Almost certainly is a bad idea. But the first thing that seems like it could work would be an implantable nfc yubikey. Then making more devices support nfc.

I know I would be pretty tempted to get an implantable 2FA device if one was available and seemed like it would have both broad and long term support.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#532

Earlier quoted context omitted.

If the service is truly vital it should be provided by the government, not Google. The government would also be free to set security policies and provide support at the level and cost demanded by the public. It is not and should not be the role of a private enterprise to act as a backstop for the fabric of society when it is not in their interests or their customers' overall interests.

The vital services are provided by the government, but require an email address. Some people have trusted Google to be their email provider, and Google is failing some of those people by denying them access unnecessarily.

umm you DO know that Gmail isn't only free email, right? Like, just use another one which doesn't force 2FA. Why is this become an issue? I don't get it

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#533
post #181

You lose your entire Google account if you lose your 2FA device or number (assuming it's a phone number), for any reason. Even if your Google account is set up with a non-Google email address which you still have access to, and you still know the correct password. And there's nobody you can reach at Google about it, no appeals process, nothing. https://news.ycombinator.com/item?id=33098261

This is what one-time backup codes are for.

Alternatively you can purchase a hardware key and store it in a trusted place, but admittedly they are expensive, so OTBC is the usual route.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#534
post #243

Earlier quoted context omitted.

Authy recovery requires you to have access to the same phone number when you want to restore to a new device.

Oh, interesting, I didn't even realize that when I used it! I guess that goes to show how easy it is to take something like that for granted

I did some more research. It looks like there is a way to recover if you don't have the phone number or the old device. They have an online form you fill out with your old phone number and new phone number. Then they have some process to verify ownership of the phone numbers which they say will take several days for security purposes.

https://support.authy.com/hc/en-us/articles/115001953247-Pho...

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#535

Earlier quoted context omitted.

Is Google a vital service or is email a vital service?

Neither. Gmail is an email provider which has provided access to an account that these people have registered with providers of vital services.

And? Not every service is homeless-friendly. That's fine. There are literally hundreds of free email services.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#536
post #73
post #23

Earlier quoted context omitted.

How do you use Authy if you lose all of your possessions every few months?

From what I remember when I used Authy briefly (Google Authenticator finally added the ability to mass import/export codes shortly after I ended up trying Authy), you create a login and set a master password, and then you have access to your codes on any device when you log into the app. Of course, this means that you have to trust Authy with your codes being stored externally, but this might be one of the sets of ci…

Authy doesn't store your codes. They store encrypted copies. They are encrypted on your device and only decrypted with your password which does not leave your device. As long as their encryption is not broken your codes are secure.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#537

Maybe we can build some sort of a "reverse proxy" solution where you can get a number from Twilio etc and just forward to an actual phone number from your carrier. Bonsu, you can add some "firewall" rules and boom. If you lose your phone from your carrier, your twilio number is the same. Just change the rule in Twilio ? Isn't there a service like this already ? If not, there is your billion dollar startup idea.

And how do you authenticate to Twilio?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#539
I'll accept the downvotes, but I don't feel like optimizing for the subset of homeless people who regularly lose their phones and their recovery codes is a good use of resources. I'd change my mind if someone could cite reliable sources that say this is actually a large community that Google as a corporation should really be paying more attention to, but just this one guy on Twitter is not enough for me.
Post reply on HN