Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

541–550 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#541
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> So what kind of 2FA would be homeless-proof? Almost certainly is a bad idea. But the first thing that seems like it could work would be an implantable nfc yubikey. Then making more devices support nfc. I know I would be pretty tempted to get an implantable 2FA device if one was available and seemed like it would have both broad and long term support.

How could you possibly come to the conclusion that a homeless person could afford a surgically implanted 2fa token?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#542
post #36

I'm a bit surprised, homeless people have phones and email addresses? Sorry for question, but it is a bit mind blowing for me, in my country homeless people are rare and the ones I see don't worry about anything besides something to eat and alcohol. So having a mobile for them would be like having cash to buy the mentioned things.

I was walking to a convenience store two nights ago and I saw a girl venmo'ing a homeless man money. Realistically it's hard to exist without a phone and bank account, and there are a lot of financial aid/benefit programs for homeless people to pay for these sorts of things

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#543

Earlier quoted context omitted.

That's a bad example. The unoccupied hotel was vandalized before the homeless were moved in. Yes, it a boondoggle, but nothing to do with homeless.

I don't think it was the local homeowners stealing live copper from the walls.

We also don't know it was the homeless, that kind of thing is often actual gang activity

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#545

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…

>why would you think they'd be a good solution for people who aren't capable of keeping track of a physical device for more than N weeks

Homeless people have no physically secure place to store their possessions. The reason so many of them lose cell phones is because they get stolen or destroyed. It's not because they're incapable of "keeping track" of them.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#546
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

If a person can remember a password that is a minimum of 8-digits, they can remember an 8-digit backup code that is already provided by google. They are functionally equivalent, but a backup code is one-time use.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#547

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

Over on /r/sysadmin there was a discussion this morning about email systems for dementia patients. How do you provide for someone that is forgetting that they are forgetting? Pretty much EVERYONE will have cognitive decline in their twilight years. It would be nice if we could have communication systems that are compatible with basic human biology.

> It would be nice if we could have communication systems that are compatible with basic human biology.

At some point, this becomes a problem better suited to the government.

Imagine you have a loved one who has dementia or is homeless and incapable of administering their digital accounts with traditional authentication methods. You want to take over their accounts.

You will need to present evidence that:

- they are indeed incapacitated

- they are who they say they are, aside from you vouching for them

- you are who you say you are

- you legitimately represent this person

- there isn’t somebody else who has a better claim at representing that person

I personally don’t want any tech company in the position to sort through all of that on a case-by-case basis and decide which accounts to unlock or transfer ownership to. Let the government or the courts figure that out.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#550

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…

Many of the reasons 2FA is added by product managers and engineers is because they are too lazy to actually solve the problem in a way that is empathetic to actual, breathing humans and instead bulldoze through the problem in the least usable method possible, call the problem "solved" and move on to shinier problems.

Just because 2FA "solves" the extremely narrowly defined problem, doesn't mean it is the best solution or even something that people can and will actually use. Upon those metrics alone, 2FA is usually one of the worst "solutions" to the problem.

Post reply on HN