Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

601–610 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#601

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…

> Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place?

Well, it isn't solving this one. Option to opt out would be nice.

> aren't capable of keeping track of a physical device for more than N weeks?

Bit ignorant of you. They could be just plainly stolen by someone else. A piece of rag working as a tent doesn't exactly have best physical security...

> I'm not unsympathetic to the problems of the homeless ant the burdens 2FA entails, but I'm also not willing to ignore the huge problems the 2FA solves, and realizing there will often be a tradeoff between making it very difficult to hack into accounts and making it easy for people with mental and other problems access their accounts.

It's not either or.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#602
Just one more way in which being on a lower rung of the socioeconomic ladder is a self-reinforcing situation.

In this case it’s not even a criticism of Google. I don’t see an easy solution here that couldn’t introduce a more gameable system for hackers.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#603
post #486

Earlier quoted context omitted.

And to generalize, I'd say that... "There is an imperfect existing solution, with a problem, therefore we will ban the existing solution and move to a new, better one" ... should require extraordinary certainty in completeness of ones new solution before banning the previous. There are very few times when the legacy method should be deprecated, and Google is the poster child of someone who shouldn't be trusted to rec…

> Chrome mv2/3 hubris and implementation clusterfuck I'm not sure why you think MV3 is a clusterfuck, it seems like it's doing exactly what Google wants. If you're confused by that, remember, you're the product, not the customer.

Assume I'm talking about something deeper than generic HN cliches. ;)

Pushing an implementation cutover by +6 months, and changing it from a hard to a soft date, because it has so many unresolved issues, incomplete APIs, and angry developers seems a fair definition of "clusterfuck."

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#604
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> So what kind of 2FA would be homeless-proof? Almost certainly is a bad idea. But the first thing that seems like it could work would be an implantable nfc yubikey. Then making more devices support nfc. I know I would be pretty tempted to get an implantable 2FA device if one was available and seemed like it would have both broad and long term support.

No post body was provided.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#605
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

>Maybe the solution should be to have some basic free state-paid email provider for those people. They are not forced to use Gmail specifically (albeit the number of non-sucking and free email providers is probably close to zero). You don't need to use Gmail. There are a lot of good free mail providers.

Yea till they add 2FA too...

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#606
post #580

Earlier quoted context omitted.

Look, I'd love to fix homelessness in America! Really, I would! But Google's policies are causing people to get locked out of their accounts now , today. Google could put a toggle in Google Account settings titled something like "Allow anyone who knows my password to log in to my Google account (less secure)." It could sit above a description of the risks involved. It would need to be disabled by default, and it woul…

While your proposal is perfectly reasonable, I couldn't help but notice that your opening was an example of the "'think of the kids + terrorism'" mentioned by GP. > Look, I'd love to stop CP distribution in America! Really, I would! But Google's encryption policies are preventing law enforcement from intercepting pedophile communications now , today. It's the same "think of [vulnerable group]" type of statement.

The purpose of that sentence was to bring us back to the issue at hand. GP was essentially saying (as I interpreted it) that we should focus on the root causes of homelessness instead of worrying about day-to-day concerns like how the homeless access email. I think we should do both, especially when the latter would be relatively simple.

But also, yes, there are in fact many times when it's important to consider the needs of different groups of people! That isn't to say that the ends always justify the means—it depends on what the means are—but reasonable accommodations should be made where possible.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#607

Just one more way in which being on a lower rung of the socioeconomic ladder is a self-reinforcing situation. In this case it’s not even a criticism of Google. I don’t see an easy solution here that couldn’t introduce a more gameable system for hackers.

Perhaps an opt-out version for homeless users?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#608
post #15
post #3

I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system h…

The phone number decision is stupid. I up and jump countries every few years. Each time, I'm switching to a new number. I'm the opposite of homeless, I'm that jet set elite. The idea that you want, need, should or will tie your identity to a phone number where people can always reach you is long outdated.

> The idea that you want, need, should or will tie your identity to a phone number where people can always reach you is long outdated.

Yeah I have no idea why phones still use numbers. It would be so easier if same address for e-mail worked for voice, just add some DNS records that point at my phone provider to domain and done.

Then again, spam calls would probably be so much worse...

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#609

Earlier quoted context omitted.

What’s painful is that I’ve ported my phone number out to a VoIP provider similar to Google Voice for exactly this purpose, but something like 25% of providers now block using SMS for 2FA unless it’s tied to an approved mobile phone operator. Turns out 2FA is also being used as a low-effort form of a captcha in addition to being a tool for data harvesting and “device identification”. I wouldn’t be surprised if legiti…

Was just reading about how Overwatch 2 won't let people register with a prepaid phone number. I'm sure there is some good reason to want to avoid people spinning up free or ultra low cost phone numbers to make extra accounts but some users were like, "I've been using TracPhone for a decade" or something like that. Also pretty surprised that it's this easy to detect the carrier. Guessing we'll see this more and more!

The problem will solve itself. People unwilling to sign up for a mobile plan for playing a game will automatically boycott the likes of Overwatch 2, which will result in revenue lost (perhaps to competing games that allow prepaid cards).

I have only ever used prepaid cards. I would rather be cut off from communication (or buy a local prepaid card) than get a surprise bill of hundreds of euros for visiting a country outside the EU.

I guess a lot of people have the same thought process as me around Europe, because there are lots of smartphones available with dual SIM cards.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#610
post #15

Earlier quoted context omitted.

The phone number decision is stupid. I up and jump countries every few years. Each time, I'm switching to a new number. I'm the opposite of homeless, I'm that jet set elite. The idea that you want, need, should or will tie your identity to a phone number where people can always reach you is long outdated.

Sticking my German sim card into my phone for fifteen minutes in all sorts of random countries and continents and waiting for a number to come through always feels absurd. I pray for the rise of esims! I feel like it's on the cards.

Eh, I greatly prefer ability to move the very reliable thing from one phone to another, just use another phone instead of going into paperwork to move it if my phone gets damaged or something
Post reply on HN