Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

591–600 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#591
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

One possibility would be to solve the "can't keep anything on them" problem with a bracelet or something like that, like they do in hospitals. Something more durable and less valuable than a cell phone.

If they truly can't keep anything on them, someone who recognizes them needs to represent them. (A locker won't do - they'll lose the key.)

And if they have no friends they can trust (which is likely) then it probably needs to be a government worker of some sort, who has their photo on the computer.

I mean, unless you want to have retina scans to log into library computers or something. Or really reliable face recognition.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#592

Earlier quoted context omitted.

The case workers could have an email account to use as the recovery email account. This already exists.

While I don't think that's a bad idea in some situations, it means trusting the case worker with access to the entire account (as they could use the recovery email to reset the password). It's also an extra burden to put on the case worker, and the individual who has to coordinate with the case worker.

Additionally, this only exists in some magical, fantastical world where the unhoused only have one case worker. In reality the unhoused bounce between a patchwork of government and non-profit services, and because of the soul-crushing workload and emotional labor of those jobs the individuals in each role are also subject to frequent turnover. So the only way this would work is an account that's shared between everyone who might work with that unhoused client at each organization (there are often multiple handling different aspects such as housing, mental health, money for groceries, etc.), and as clients move geographically or do other things that make them eligible or ineligible for each organization's services, that recovery account would also need to change or transition to some new org. Even a single recovery email address is just a totally unworkable solution for the reality they face.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#593
post #590
post #582

Earlier quoted context omitted.

That's Weird, I've never had to do that. I can just login to Google with my username/password. If it doesn't recognize the device it just pushes a notification of the sign in to my phone

That's exactly what they are describing - the push notification to the phone _that the user has lost_.

It's just a notification, it can be ignored (for me). I don't usually even notice its there until hours later. You don't have to acknowledge it in any way.

It also has nothing to do with the YouTube app, and there is no code I have to enter anywhere.

I've never had any form of 2FA on my Google account.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#594
post #394

Earlier quoted context omitted.

That's fair that I shouldn't make such an unqualified statement. While public spending as a % of GDP has indeed increased, that's primarily driven by two things: increased defence (and related) spending, and increased spending on health costs. In the US, the growth in social assistance spending over the last 3 decades is driven almost entirely by the latter: https://ourworldindata.org/grapher/social-expenditure-as-pe…

Looking at your numbers or just social spending, it is increased 50% since 1990 as a portion of GDP. Real GDP adjusted for inflation itself has increased more than 3x since 1990. This means that us social spending in terms of inflation adjusted purchases has gone up more than 450% from 1990 levels. This excludes military spending and is adjusted for the purchasing power of those dollars. I don't know about you, but I…

Sure. My point was indeed to suggest we rethink what government can do.

Can governments (not necessarily the federal government) run a public service internet system? Sure, and probably more easily than we can, as another poster suggested, regulate tech companies into providing the right tradeoffs for housed and unhoused users.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#595

Earlier quoted context omitted.

The problems are downstream of that. Not having 2FA is going to allow some portion of users to get hacked. When those users do get hacked they will need a way to regain control of the account. Methods of regaining access to an account are notorious for bad actors social engineering their way to gaining control of accounts. 2FA relieves some of that, because even if you do get hacked you can provide a token from the a…

> Not having 2FA is going to allow some portion of users to get hacked. When those users do get hacked they will need a way to regain control of the account. I don't think they do! This would be part of the tradeoff. Currently, people who cannot use or rely on 2FA are getting locked out of their accounts even if they weren't hacked and knew their password! Isn't that worse?

Doesn’t Google offer the option of disabling 2FA?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#596
post #574

Earlier quoted context omitted.

Should users with poor vision also have to use a special blind-person email provider? Because, I'd expect supporting screen readers to take significantly more effort than adding the setting I outlined. Also, if I was homeless, I wouldn't want my email address to indicate I was homeless. I broadly agree that it isn't Google's job to cater to everyone , but in this instance, the ask seems overwhelmingly reasonable—and…

What is the ask that is overwhelmingly reasonable? As has been pointed out to me and others, Google already offers a way to turn off 2FA - https://support.google.com/accounts/answer/1064203 Naively this seems like it should solve the 2FA problem for the unhoused community members in question. With this in mind, what else should Google do?

Even when 2FA is disabled, Google will insist on additional verification (phone, recovery email, etc) if it thinks something about your browser or IP address is unusual, even if you know your password. If you don't have a verification method (or cannot access it), Google will literally just lock you out. I have personally experienced this.

It should be possible to turn this off!

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#597
post #498

Earlier quoted context omitted.

That's almost exactly what Google has done. Here's how you turn off 2FA on your account: 1. Go to myaccount.google.com 2. Press "Security" 3. Press "2 step verification" 4. Enter your password 5. Press "Turn off" 6. Confirm the dialog that says "Turning off 2-Step Verification will remove the extra security on your account, and you’ll only use your password to sign in."

Those steps don’t actually turn off 2FA for Google accounts. If you login from a new computer or unrecognized IP, Google forces you to use the YouTube app on your phone to enter a “code” to login. It sometimes doesn’t even let you get a text code. God forbid I lose my phone or delete the YouTube app and login from a new IP. I don’t know how I would even get into my account. I don’t know how this isn’t a wider spread…

Then don’t use Google for email. There are plenty of other free email providers that do not employ that much security. Problem solved

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#598
post #593
post #590

Earlier quoted context omitted.

That's exactly what they are describing - the push notification to the phone _that the user has lost_.

It's just a notification , it can be ignored (for me). I don't usually even notice its there until hours later. You don't have to acknowledge it in any way. It also has nothing to do with the YouTube app, and there is no code I have to enter anywhere. I've never had any form of 2FA on my Google account.

You may have never experienced it, but it does happen. Not just a notification.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#599
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

Or just let people to disable 2FA. That's simplest and easiest solution. Slap a red warning label if you need to.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#600
post #574

Earlier quoted context omitted.

What is the ask that is overwhelmingly reasonable? As has been pointed out to me and others, Google already offers a way to turn off 2FA - https://support.google.com/accounts/answer/1064203 Naively this seems like it should solve the 2FA problem for the unhoused community members in question. With this in mind, what else should Google do?

Even when 2FA is disabled, Google will insist on additional verification (phone, recovery email, etc) if it thinks something about your browser or IP address is unusual, even if you know your password. If you don't have a verification method (or cannot access it), Google will literally just lock you out. I have personally experienced this. It should be possible to turn this off!

OK. That raises all sorts of follow-up questions, as turning off security measures can be expected to have consequences.

What should Google do in the scenario that this purposely-low-security-for-the-unhoused account is breached? What about abuse? Are we OK with Google just shutting off accounts in that scenario? Are we prepared to accept that the members of our community experiencing being unhoused will find themselves constantly creating new accounts as their old ones are shut off or rendered unusual from the consequences of purposely-low-security-for-the-vulnerable?

Remember, things like gmail accounts are under constant attack. Security measures, the very ones we're talking about disabling, help keep those attacks at bay. Each of those things that triggers verification actually lines up with real attack patterns.

So while this may be a small-ish thing to ask for, I'm a little concerned about the consequences. We're literally asking to offer the most vulnerable and marginalized members of society shittier security and ignoring the effects of this.

Post reply on HN