Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

581–590 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#581

Personally, I find it particularly infuriating that more and more companies are demanding to use phone-based 2FA even when I already have 2FA authentication set up . This applies to Google, too, which has forced me to add a phone number and get a SMS 2FA code for accounts that already had non-SMS 2FA configured. The whole reason I use an authenticator app is so that my accounts aren't dependent on having the same pho…

Being strongarmed into giving up your phone number is as much "for your security" as manifest v3 is "for your privacy". They could care less that you have 2FA enabled, they want that phone number. Many people never change their numbers and enter them into hundreds of sites, creating a wealth of data which can then be profitably correlated with your email content, google account activity, searches, location, etc.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#582
post #498

Earlier quoted context omitted.

That's almost exactly what Google has done. Here's how you turn off 2FA on your account: 1. Go to myaccount.google.com 2. Press "Security" 3. Press "2 step verification" 4. Enter your password 5. Press "Turn off" 6. Confirm the dialog that says "Turning off 2-Step Verification will remove the extra security on your account, and you’ll only use your password to sign in."

Those steps don’t actually turn off 2FA for Google accounts. If you login from a new computer or unrecognized IP, Google forces you to use the YouTube app on your phone to enter a “code” to login. It sometimes doesn’t even let you get a text code. God forbid I lose my phone or delete the YouTube app and login from a new IP. I don’t know how I would even get into my account. I don’t know how this isn’t a wider spread…

That's Weird, I've never had to do that. I can just login to Google with my username/password. If it doesn't recognize the device it just pushes a notification of the sign in to my phone

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#583

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…

If you forget your password — it's YOUR fault. If you reuse your password and it gets leaked — it's YOUR fault. If for some reason you cannot fix yourself, and have to rely on Google 2FA for that — good. Somebody who can manage their own passwords alright shouldn't suffer because of you. How about his just using his password, and lose his accounts because he fucked up, not because Google (or anybody else) suddenly thinks (incorrectly) that it's not him anymore, who uses that login and password.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#584

Earlier quoted context omitted.

Some homeless people don't want to deal with the maintenance of a home. Some homeless people aren't capable of the maintenance of a home due to mental or physical issues. Some homeless people refuse to accept help for mental issues for fear of being trapped in a psych ward. Simply put, you need to split homelessness into temporary and chronic populations. For the temporary group, homelessness is the problem. For the…

Yes, some of them -- but not most of them. Most homeless people do not have a severe mental illness (around 70%) [1]. For most homeless people, it's primarily an issue of housing affordability. The solution is to reduce the cost of housing. For the people who need more support -- due to mental illness or otherwise -- the affordable, effective solution is permanent supportive housing [2]. [1] https://www.treatmentadvo…

Wait, what? That's precisely opposite of what your source [1] says:

“70% were receiving mental health treatment or had in the past.” "An April 2016 survey of New York City’s homeless population reported that unsheltered homeless individuals were most likely to be severely mentally ill single males." Something like 1 in 5 of the homeless in San Francisco have a traumatic brain injury.

None of these people are going to be fixed with mere "housing".

Even worse, putting these people who desperately need medical treatment in "mere housing" is very likely to cause the "mere housing" program to fail when it could have succeeded. The homeless who need "mere housing" don't want to be near the homeless who need "significant medical treatment" any more than anybody else does.

Homelessness has an "Amdahl's Law" nature to it. You have to separate out the different types of homelessness and apply the correct solution. And you will only gain the improvement for the group you "solved".

Consequently, you can solve 20% of the homeless problem and people will still say you "failed" because 80% of the homeless are still in their vision.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#585
post #300

Earlier quoted context omitted.

I took three steps against this happening: 1) Not providing phone number for 2FA. Never. 2) Using multiple (3 pcs.) physical keys for 2FA (like Yubikey and similar). Authentication app is an alternative for one choice of 2FA (but not the sole one!) 3) Only using a limited set of Google functionality. Use for secondary purposes mostly. Well, the last one is mainly to mitigate the consequences if happens anyway, for ot…

I took one step: 1) Don't use anything Google.

You took a step that requires a lot of skill, wealth, and privilege.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#586
post #111

Earlier quoted context omitted.

This is missing the forest for the trees. Of course we'd be more emotionally involved if it was someone we knew, that's not hypocritical. Most people aren't against fixing societal problems, either. As it stands, homelessness is definitely something that affects a ton of people so it definitely is our problem as long as we are city dwellers. The problem here is that misapplied empathy can lead to terrible decisions.…

Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…

I can understand your statement, but by doing that you will find that A LOT of people will check the insecure options because “that a not going to happen to me”.

Remember you have the “rescue keys” from google to avoid these kind of problems.

The bigger problem is how you teach those people how to use the services in their situation.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#587
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> So what kind of 2FA would be homeless-proof? Almost certainly is a bad idea. But the first thing that seems like it could work would be an implantable nfc yubikey. Then making more devices support nfc. I know I would be pretty tempted to get an implantable 2FA device if one was available and seemed like it would have both broad and long term support.

Ah, yes

I can read the headline now

“GOVERNMENT PROGRAM TO CHIP HOMELESS PEOPLE LIKE DOGS TO PROVE IDENTITY”

I implore you to read The Scarlet Letter and perhaps read up on [similar such things](https://en.wikipedia.org/wiki/Identification_of_inmates_in_G...).

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#588
post #567
post #429

Earlier quoted context omitted.

More people ought to read this: https://blog.jaibot.com/the-copenhagen-interpretation-of-eth... . Google is already providing a free service to homeless people. It's not empathy to tell someone else to solve a problem that you care about. That's virtue signaling. If he cares, he should take matters into his own hands. Is it too much to ask a single person to build a free email service for all homeless people? Perhaps…

But many people consider LBJ to have been an empathetic president? I don't see how it's supposed to be self-evident that, because Johnson liked bragging about his johnson, that his focus on the Great Society must have been driven by hard-headed pragmatism. U.S. presidents have a wide array of problems to solve. LBJ didn't have to pick causes that are commonly associated with empathy for the downtrodden.

He didn't just brag about his dick. He went out of the way to show it off to his colleagues. I mean it's possible that his fetish outweighed his empathy, but it's more likely that he simply didn't care about making people feel uncomfortable.

He did progressive things, but to me it sounds like he was influenced by philosophical ideals rather than empathy. They based Frank Underwood from House of Cards on an exaggerated version of LBJ.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#589
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> So what kind of 2FA would be homeless-proof? I don't see a solution.

There are three factor categories, what you know, what you are, and what you have. A password is what you know. A phone is what you have. Biometrics are what you are - facial recognition, thumbprints, etc.

2FA in one manner or another is used by various services, because the security recommendation is to pillar identification by at least two of the three factors.

For your question, there are any two from the three factor categories that could be used.

However, there are also limited versions of a single category that are often used as a backup when 2fa is not available. In this case, google uses backup codes when "what you have" is not available. Backup codes are functionally equivalent to passwords, except that they are limited to a single-time use. Limiting use is often a method of using a single factor category, when another factor is not available.

Another method is to rely upon another authority, such as using a physical ID card that can be validated in order to let a person back in.

And so forth.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#590
post #582
post #498

Earlier quoted context omitted.

Those steps don’t actually turn off 2FA for Google accounts. If you login from a new computer or unrecognized IP, Google forces you to use the YouTube app on your phone to enter a “code” to login. It sometimes doesn’t even let you get a text code. God forbid I lose my phone or delete the YouTube app and login from a new IP. I don’t know how I would even get into my account. I don’t know how this isn’t a wider spread…

That's Weird, I've never had to do that. I can just login to Google with my username/password. If it doesn't recognize the device it just pushes a notification of the sign in to my phone

That's exactly what they are describing - the push notification to the phone _that the user has lost_.
Post reply on HN