Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

571–580 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#571
post #486

Earlier quoted context omitted.

2fa is a good option, but there are many situations where a plain password is just superior. if you ignore this reality, that passwords are legitimately more secure and better for a lot of people, then you're undermining an existing working security system and will just cause chaos and loss for people.

And to generalize, I'd say that... "There is an imperfect existing solution, with a problem, therefore we will ban the existing solution and move to a new, better one" ... should require extraordinary certainty in completeness of ones new solution before banning the previous. There are very few times when the legacy method should be deprecated, and Google is the poster child of someone who shouldn't be trusted to rec…

> Chrome mv2/3 hubris and implementation clusterfuck

I'm not sure why you think MV3 is a clusterfuck, it seems like it's doing exactly what Google wants. If you're confused by that, remember, you're the product, not the customer.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#572
post #551
post #286

Earlier quoted context omitted.

It seems to me that Google is in full control of what they've built here. They've chosen not to put in the effort to find a way to meet the needs of this portion of their user community. On the one hand, this can be quite reasonably derided as a lack of imagination. Surely there must be a way to do it! On the other hand, well, we as a society accept that businesses are generally allowed to decide they just don't want…

It seems likely that enabling insecure account usage would be a net negative to huge swaths of their user base. Gmail is functionally the root of trust / skeleton key to millions of people's online lives. The only real competitor is Facebook and, for some, Apple. I think Gmail is far better (more secure, more privacy respecting, less capricious) than Facebook. With the admission by Chad that that homeless he advocate…

I have the nagging sense that what we're seeing amounts to throwing one's hands in the air and exclaiming "There must be a way!"

As others have pointed out, turning off 2FA is available. Apparently that doesn't work either because the people in question forget their passwords. So I guess we should add passwords and biometrics (not available on all hardware) to the list of things that aren't going to work.

Like you, I'm left wondering what there is to anchor any level of security.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#573
post #559
post #546

Earlier quoted context omitted.

If a person can remember a password that is a minimum of 8-digits, they can remember an 8-digit backup code that is already provided by google. They are functionally equivalent, but a backup code is one-time use.

Using a password multiple times helps you remember it.

[deleted]

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#574

Earlier quoted context omitted.

This is a result of taking a product made by someone else for a certain purpose and then using it for one it isn't intended. Its not Google's fault gmail is a bad fit here. They didn't design it with this use case in mind. The solution is to use one that is. Why are case workers directing the homeless to setup gmail accounts? Because they haven't been provided with a better solution by the system they work within. So…

Should users with poor vision also have to use a special blind-person email provider? Because, I'd expect supporting screen readers to take significantly more effort than adding the setting I outlined. Also, if I was homeless, I wouldn't want my email address to indicate I was homeless. I broadly agree that it isn't Google's job to cater to everyone , but in this instance, the ask seems overwhelmingly reasonable—and…

What is the ask that is overwhelmingly reasonable? As has been pointed out to me and others, Google already offers a way to turn off 2FA - https://support.google.com/accounts/answer/1064203 Naively this seems like it should solve the 2FA problem for the unhoused community members in question.

With this in mind, what else should Google do?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#575

Earlier quoted context omitted.

This is a result of taking a product made by someone else for a certain purpose and then using it for one it isn't intended. Its not Google's fault gmail is a bad fit here. They didn't design it with this use case in mind. The solution is to use one that is. Why are case workers directing the homeless to setup gmail accounts? Because they haven't been provided with a better solution by the system they work within. So…

If Google is going to position itself as the face of the internet, then it has to live up to that responsibility; it can’t go, hm yes, use our browser and our email service and our phones, but only if you fit into this category of prescribed users.

Of course they can. It's the only thing they've ever done. I honestly can't think of a company that thinks less of its users than Google does - that's because in their view, they have no users - they only have eyeballs, that are worth anywhere from fractional cents to hundreds of dollars every time they can grab them.

Using "support" and "Google" in the same sentence is laughable. They barely support the ad clients that pay their freight. Google's entire business model is built around NEVER providing support for the users of their technologies, and killing off any products that don't monetize.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#576

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

If we all spent our collective efforts to make sure everything in this world is accessible to every single human being, we would have zero progress as a society. We are not even guaranteed the right to live in this world and yet you are advocating for the right to email service? It is shocking that someone could even have a thought process like this and receive so many upvotes.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#577

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

If we all spent our collective efforts to make sure everything in this world is accessible to every single human being, we would have zero progress as a society. We are not even guaranteed the right to live in this world and yet you are advocating for the right to email service? It is shocking that someone could even have a thought process like this and receive so many upvotes.

This is entirely untrue. We can build an accessible society for everyone. We clearly have the resources for it.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#578

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…

OK, so what solution are you proposing for someone who doesn't have permanent, safe storage for their property?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#579
I don't even know what this has to do with the homeless. I don't want ANY of my internet accounts to depend on my phone (which I can lose, and I just don't want it to be a big deal) or, worst of all on "my" phone number, which IS NOT, never was and never will be controlled by me — but by my cellphone operator. Who isn't my friend. Both problems seem to be so obvious, that I don't see how pointing out (also rather obvious thing) — that life out there on the streets is a bit different than in your [home-sized] cubicles — can help.

And since it's always more productive to assume malice, not stupidity — obviously, this is the point. Somebody wants you to depend on your phone number, something you don't really control and cannot easily change. This isn't about comfort and security, it never was. What else is new.

But, I mean, if I have to pretend that it's not about me, but about homeless people for something to be changed — I guess I'm homeless' rights supporter #1 from now on.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#580
post #111

Earlier quoted context omitted.

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…

While your proposal is perfectly reasonable, I couldn't help but notice that your opening was an example of the "'think of the kids + terrorism'" mentioned by GP.

> Look, I'd love to stop CP distribution in America! Really, I would! But Google's encryption policies are preventing law enforcement from intercepting pedophile communications now, today.

It's the same "think of [vulnerable group]" type of statement.

Post reply on HN