Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

611–620 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#611
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

I've often wondered that with a valid ID, that the gov does not give us an email noawdays. Especially one that does not require this asinine phone-validity garbage. I'd even suggest that maybe not use email-addresses as a login-name along with plenty of alias's for inbound and outbound that do not expose your "main" or account.

And google is not alone here; many other major "free" email providers require a phone as well (dagger eyes at you, MS, yahoo, ect); and the icing on the cake are some websites even require a particular set of domains to register with them to prevent multi-accounts/bots/spammers/ect => just a big ol download-spiral of decisions that feed into eachother, just to put a physical ID on anybody to tag-em-to-sell-em

The biggest gripe is that it is mandatory; it is not an option and nothing we can do about it other than "vote with our wallets" - and google does not even allow ToTP use as an alternative to phones, lol

The beatings will continue until morale improves; always has been, always will

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#612
post #183

Earlier quoted context omitted.

Wtf Calling homelessness a "niche" .. peak apres moi le deluge

This is the sort of performative response that is the problem. Let's say we force Google to switch off 2FA. Now we have exposed millions of people who don't know any better to phishing attempts and financial loss. And the group we are trying to help isn't really better off. There are so many other questions we could be asking. Why are they directed towards picking Gmail by default? Why is the system to give a replace…

> This is the sort of performative response that is the problem. Let's say we force Google to switch off 2FA. Now we have exposed millions of people who don't know any better to phishing attempts and financial loss.

Could be just option hidden somewhere in the settings. Don't need to turn it off for all

> And the group we are trying to help isn't really better off.

That's just your assumption

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#613

Earlier quoted context omitted.

this feels like a workaround. We should not be treating phonenumbers as SSN round two, where everyone relies on it for your identity, and it should never be changed because of how much shit was needlessly tied to it. I rue the day I need to change my phone number and my digital identity becomes a huge headache, especially for far flung services that decided they wanted my phone number, but I wouldn't have considered…

The correct solution to this and a shitload of other problems is a real, national ID program. But there's enough resistance to it in both US political parties that it can't happen. The lack of it causes a ton of stress, over the population, and is a drag on the economy, but we're just never gonna fix it. Instead we'll de-facto have one (or more) anyway, including 99% of the risks that a real one would carry with it t…

Uh, no, that's even worse thing to give to the for-profit companies as indentifier.

Now they have country-unique ID of a person that will never change so it can be linked to a person regardless of where that person logs in

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#615
post #181

You lose your entire Google account if you lose your 2FA device or number (assuming it's a phone number), for any reason. Even if your Google account is set up with a non-Google email address which you still have access to, and you still know the correct password. And there's nobody you can reach at Google about it, no appeals process, nothing. https://news.ycombinator.com/item?id=33098261

It’s this sort of thing that has prevented me from activating 2FA on my gmail account. I pay for Google Drive (as a tertiary backup) and would be willing to pay more for service that include actual customer service. At this point though I feel locked in. I could switch (any suggestions on paid email with *real* support available?) but it’s a pretty big burden to go through every site & service that uses my email as either a login or password reset vector and change things over.

Heck, here’s an idea for a startup: a digital “moving” service. IRL I could pay a company to take everything I own, pack it up, ship it somewhere else, and even unpack it too. I’d like to see a digital equivalent.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#616

Wtf is "unhoused".

It is the next step on the euphemism treadmill. Apparently, "homeless" is tainted or declasse now.

My city government here in California calls them "people who live outside".

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#617

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

Quite simply there are multiple factors at play here. Do you force 2FA on almost everyone and reduce hostile account takeovers to negligible? Do you allow for no 2FA and permit the homeless use case? I think Google faced a trolley problem and made the right decision. You need a different tool "homeless mail" for them. It's Gmail. You don't have to use it. There's a lot of mail providers out there. Whatever, if this g…

Many people exist and use email before becoming homeless. When that email is gmail - they actually do have to use it when they become homeless!

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#618
post #600

Earlier quoted context omitted.

Even when 2FA is disabled, Google will insist on additional verification (phone, recovery email, etc) if it thinks something about your browser or IP address is unusual, even if you know your password. If you don't have a verification method (or cannot access it), Google will literally just lock you out. I have personally experienced this. It should be possible to turn this off!

OK. That raises all sorts of follow-up questions, as turning off security measures can be expected to have consequences. What should Google do in the scenario that this purposely-low-security-for-the-unhoused account is breached? What about abuse? Are we OK with Google just shutting off accounts in that scenario? Are we prepared to accept that the members of our community experiencing being unhoused will find themsel…

> Are we OK with Google just shutting off accounts in that scenario? Are we prepared to accept that the members of our community experiencing being unhoused will find themselves constantly creating new accounts as their old ones are shut off or rendered unusual from the consequences of purposely-low-security-for-the-vulnerable?

I am, yes, if the alternative is that they loose access to their account every few months!

Also, at least this way people have the ability to keep their accounts truly safe if they choose a strong, unique password. If Google just locks them out no matter what, there's no recourse.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#619

Earlier quoted context omitted.

And what happens if I've already been using that gmail address and then become homeless? I guess too bad! Should have thought of my future homelessness when I was signing up for an email service a decade ago!

OK ... who are you arguing with? OP stated "Maybe the solution should be to have some basic free state-paid email provider for those people." I replied that there are a lot of good free email providers already.

You, when you said “they don’t have to use Gmail”.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#620

Earlier quoted context omitted.

I don't know that it is less dire, but I do think it's less likely. Are homeless people's email accounts getting hacked three times per year? Also... maybe getting hacked is worse, or maybe loosing access is worse, but the user should have the right to make that decision! Google can set the default, but the user knows his or her own life.

> Are homeless people's email accounts getting hacked three times per year? The aversion to 2FA makes them seem like easy targets if I'm looking for addresses to use for spam. > maybe getting hacked is worse, or maybe loosing access is worse, but the user should have the right to make that decision Getting hacked makes losing access considerably more likely. This ain't one or the other.

> The aversion to 2FA makes them seem like easy targets if I'm looking for addresses to use for spam.

If you want to spam people, why not just sign up for your own gmail account?

Post reply on HN