Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

621–630 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#621
post #3

I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system h…

And what, find every system that has your existing email address and change it?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#622
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

Lower in the same thread: https://twitter.com/chadloder/status/1577906942080598017?s=6...

> PS: Many unhoused people access their email rarely, intermittently; they don't stay logged in. They often have to guess several times to remember their password.

2FA doesn’t work, and remembering passwords doesn’t work either. Checkmate.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#623
post #599
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

Or just let people to disable 2FA. That's simplest and easiest solution. Slap a red warning label if you need to.

For better or worse, I can’t set my password to be “password” or any other number of weak words, and also need a number and symbol. Same principle in practice here.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#624

Earlier quoted context omitted.

Was just reading about how Overwatch 2 won't let people register with a prepaid phone number. I'm sure there is some good reason to want to avoid people spinning up free or ultra low cost phone numbers to make extra accounts but some users were like, "I've been using TracPhone for a decade" or something like that. Also pretty surprised that it's this easy to detect the carrier. Guessing we'll see this more and more!

The problem will solve itself. People unwilling to sign up for a mobile plan for playing a game will automatically boycott the likes of Overwatch 2, which will result in revenue lost (perhaps to competing games that allow prepaid cards). I have only ever used prepaid cards. I would rather be cut off from communication (or buy a local prepaid card) than get a surprise bill of hundreds of euros for visiting a country o…

I'm not so sure the free market will resolve things here, because people who use prepaid mobile plans are also typically lower income. They might not be considered a significant loss on net.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#625

Earlier quoted context omitted.

> Are homeless people's email accounts getting hacked three times per year? The aversion to 2FA makes them seem like easy targets if I'm looking for addresses to use for spam. > maybe getting hacked is worse, or maybe loosing access is worse, but the user should have the right to make that decision Getting hacked makes losing access considerably more likely. This ain't one or the other.

> The aversion to 2FA makes them seem like easy targets if I'm looking for addresses to use for spam. If you want to spam people, why not just sign up for your own gmail account?

Because then it'd be tied to my number (assuming I haven't figured out some workaround) and could then be traced back to me.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#626
Ticketmaster started requiring 2FA, but they only allow phone numbers connected to a SIM card.

For over a decade, I've been using my Google Voice number as my identity, with whatever number is on whatever SIM I happen to have at the time being an implementation detail. Ticketmaster doesn't accept that, so now I have to schlep myself over to the venue (which often includes a bridge toll) to buy tickets at the box office. It's infuriating.

I believe Credit Karma Tax also had this problem, which is moot now that Square owns it (since Square doesn't have this problem).

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#627
post #600

Earlier quoted context omitted.

OK. That raises all sorts of follow-up questions, as turning off security measures can be expected to have consequences. What should Google do in the scenario that this purposely-low-security-for-the-unhoused account is breached? What about abuse? Are we OK with Google just shutting off accounts in that scenario? Are we prepared to accept that the members of our community experiencing being unhoused will find themsel…

> Are we OK with Google just shutting off accounts in that scenario? Are we prepared to accept that the members of our community experiencing being unhoused will find themselves constantly creating new accounts as their old ones are shut off or rendered unusual from the consequences of purposely-low-security-for-the-vulnerable? I am, yes, if the alternative is that they loose access to their account every few months!…

> I am, yes, if the alternative is that they loose access to their account every few months!

Good to hear, though I confess to a bit of confusion. The issue I pointed to is that they're going to lose access to their accounts frequently as their accounts get breached, abused, and shut off. As opposed to losing access because they lost their phone number.

> Also, at least this way people have the ability to keep their accounts truly safe if they choose a strong, unique password. If Google just locks them out no matter what, there's no recourse.

As described in the Twitter thread, we're talking about people who already struggle to remember their passwords. I doubt this will improve if we require basically regular people to have strong passwords, but perhaps you have reason to think differently.

Basically I think you're trading one cause of lockout without recourse for another cause of lockout without recourse with this proposal. This does not strike me as progress. For my own part, I think Google is the wrong place to be trying to address this issue - perhaps porting phone numbers within the Lifeline phone program would be better.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#628
post #112

Earlier quoted context omitted.

So the choice is for them to permanently lose access to their email? Homeless people aren't stupid and strong password don't have to be incredibly hard to remember. I'd rather get my accounts hacked because of password reuse than lose access to my email, forever. There is literally nothing more important than your email. Even stuff like your bank account has secondary means of recovery, whereas if you lose access to…

> I'd rather get my accounts hacked because of password reuse than lose access to my email, forever. When your account is stolen the attacker changes your password. You lose access to your email forever and lose access to all of the services that use your email as a recovery platform.

The point here is that that happens to these people already. I'm sure they'd much rather have only a chance of it happening than it being a guarantee.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#629
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> So what kind of 2FA would be homeless-proof?

There is none. That's the entire point of the post: "something you have" doesn't work if you're at risk of losing all of your possessions at any time. So let them disable 2FA and rely on passwords - or even better yet, provide some way to actually talk to a person and verify identity.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#630

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…

No one is wanting to take 2FA away from you. It's just about giving the option to disable 2FA.
Post reply on HN