Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

551–560 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#551
post #286
post #279

Earlier quoted context omitted.

What do you think the moral of Jurassic Park was? If you dont know how to control what happens in the park you build, then the park will be shutdown. In the case of Google its not hard to speed up the process of shutdown. I just encourage them to keep working on more and more mindless ivory tower trash like Pixel phones, watches etc and inject more Ads into everything. They dont have the imagination for anything else…

It seems to me that Google is in full control of what they've built here. They've chosen not to put in the effort to find a way to meet the needs of this portion of their user community. On the one hand, this can be quite reasonably derided as a lack of imagination. Surely there must be a way to do it! On the other hand, well, we as a society accept that businesses are generally allowed to decide they just don't want…

It seems likely that enabling insecure account usage would be a net negative to huge swaths of their user base.

Gmail is functionally the root of trust / skeleton key to millions of people's online lives. The only real competitor is Facebook and, for some, Apple. I think Gmail is far better (more secure, more privacy respecting, less capricious) than Facebook.

With the admission by Chad that that homeless he advocates for can't retain mobile numbers, or ID cards, or 2fa keys, I have no idea how he thinks any secure access could possibly work.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#552
post #398

Your phone number is also your permanent cross-app tracking advertising identifier. This is why every app and vendor asks you for it. I change mine every 90 days.

Do you just go into the carrier's store and ask them to change it, or do you have some streamlined way of changing it? Every time I go into one of those stores it seems to take hours to get even the simplest thing done.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#553

Earlier quoted context omitted.

That's a bad example. The unoccupied hotel was vandalized before the homeless were moved in. Yes, it a boondoggle, but nothing to do with homeless.

I don't think it was the local homeowners stealing live copper from the walls.

Where do you suspect that homeless are storing their caches of copper? Do you think they're carrying them around with them at all times?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#554
post #455

Earlier quoted context omitted.

I verify that this is true at the time of posting. In previous volunteer work at a non-profit run by university students, the organization assigned a free Gmail account to each executive. Each year, we ran into a problem where the executives would change, and we needed to transfer the Gmail account to the new person. Problems would happen when the new person tried to log in to the account. Since the login was from an…

FWIW, if you're the administrator of the organization, you can disable 2FA from the admin console for that user's next login. I've done this a few times for similar reasons.

Thanks for the tip, though this just works for a paid Google Workspace email plan (or a free Google Workspace for Nonprofits plan) [1]. We couldn't do this because we were using free personal Gmail accounts at the time (by transferring the credentials from retired executives to new executives) as we lacked budget and formal non-profit registration (to be eligible for the Nonprofits plan) since the group was fairly small and undergraduate student-run.

The difficulties were to be expected as personal Gmails weren't meant to be used like this (the goal was just to share an anecdote about the difficulties of phone numbers used for two-factor authentication with the free service even once a year). The long-term solution we used was to pay for a reliable but low-cost (in comparison to Outlook and Google) email host initially recommended on HN and a few sysadmin forums, to gain access to organization-wide admin features.

[1] https://support.google.com/a/answer/2537800?hl=en#zippy=%2Cc...

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#555
The USPS should operate a free public email service and provide support at every post office.

The government has the resources to navigate complex situations that digital safeguards can’t.

If someone has no paperwork, lost the device they made their account with, and cannot remember a password they made—no tech company has the resources or expertise to handle this at scale as well as local institutions can. If someone needs to take over an account of a loved one that they have legal guardianship of, you don’t want a support agent at a call center to make these decisions.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#556
post #111

Earlier quoted context omitted.

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…

The state could run an email service.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#557

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

I have a sibling who's "no fixed abode". Teaching him how to use 2fa isn't the problem. It's that all property is transient, so the 2nd-factor can't be tied to property. It doesn't matter if that's his phone or his socks. "Something you know and something you have" does not account for those who have nothing.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#558

Google's 2FA is dreadful. 2FA is a good idea when it's added with consent, but Google adds it behind your back in ways that are both infuriating and brain-dead. I've been caught out recently twice: once I was away on work and had to access my email. Google demanded that I verify it using my phone that I'd previously accessed my work email with. However, this phone was just a phone I use for development, had never had…

Yeah I had a similar issue. I had TOTP 2FA set up on my google account, and connected an android phone to it purely to download something from the app store.

Google then decided that it was going to ignore TOTP set up and prefer the "Trusted mobile device."

In a way it actually made my account less secure, since that was a testing device and had no passcode on it.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#559
post #546

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

If a person can remember a password that is a minimum of 8-digits, they can remember an 8-digit backup code that is already provided by google. They are functionally equivalent, but a backup code is one-time use.

Using a password multiple times helps you remember it.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#560

Wtf is "unhoused".

It is the next step on the euphemism treadmill. Apparently, "homeless" is tainted or declasse now.

I wonder what the next step will be. Probably an acronym, PWFA (Person Without Fixed Abode).
Post reply on HN