Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

631–640 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#631
post #362
post #112

Earlier quoted context omitted.

So the choice is for them to permanently lose access to their email? Homeless people aren't stupid and strong password don't have to be incredibly hard to remember. I'd rather get my accounts hacked because of password reuse than lose access to my email, forever. There is literally nothing more important than your email. Even stuff like your bank account has secondary means of recovery, whereas if you lose access to…

> I'd rather get my accounts hacked because of password reuse than lose access to my email, forever. step 1: get your account hacked step 2: hacker changes password step 3: lose access to your email, forever What you've presented is not in fact a dichotomy, for any practical purposes.

Except that they're already losing access to email, forever. A small chance of it happening because of a hacker is better than a statistical guarantee of it happening from phone theft.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#632
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

I've often wondered that with a valid ID, that the gov does not give us an email noawdays. Especially one that does not require this asinine phone-validity garbage. I'd even suggest that maybe not use email-addresses as a login-name along with plenty of alias's for inbound and outbound that do not expose your "main" or account. And google is not alone here; many other major "free" email providers require a phone as w…

> I've often wondered that with a valid ID, that the gov does not give us an email noawdays. Especially one that does not require this asinine phone-validity garbage.

Can you even imagine the nightmare of trying to police the usage of such a thing? Everything from simple spamming to harassment to child pornography, all complicated by the stricter scrutiny the government gets for who it can decide not to provide services to.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#633
post #486

Earlier quoted context omitted.

And to generalize, I'd say that... "There is an imperfect existing solution, with a problem, therefore we will ban the existing solution and move to a new, better one" ... should require extraordinary certainty in completeness of ones new solution before banning the previous. There are very few times when the legacy method should be deprecated, and Google is the poster child of someone who shouldn't be trusted to rec…

> Chrome mv2/3 hubris and implementation clusterfuck I'm not sure why you think MV3 is a clusterfuck, it seems like it's doing exactly what Google wants. If you're confused by that, remember, you're the product, not the customer.

At this point I'm not sure if this is cynicism or a legitimate opinion.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#634
post #15

Earlier quoted context omitted.

The phone number decision is stupid. I up and jump countries every few years. Each time, I'm switching to a new number. I'm the opposite of homeless, I'm that jet set elite. The idea that you want, need, should or will tie your identity to a phone number where people can always reach you is long outdated.

I've lived in different countries along the years, it's simple and best to just keep a permanent phone number in the country you consider the most like "home". Get a cheap phone-only plan, stick the SIM into a dumbphone or your second SIM slot. Done.

That phone number will not necessarily get reception when travelling in foreign countries.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#635
post #622

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

Lower in the same thread: https://twitter.com/chadloder/status/1577906942080598017?s=6... > PS: Many unhoused people access their email rarely, intermittently; they don't stay logged in. They often have to guess several times to remember their password. 2FA doesn’t work, and remembering passwords doesn’t work either. Checkmate.

Having to guess several times != having forgotten your password.

I think what this actually calls for though is a way to prove your identity by talking to an actual human. Something that used to be the standard before tech companies declared that it was too inefficient.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#636

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

As someone else pointed out, there is an unavoidable tradeoff that had to be made here between account security, accessibility, and privacy. Reasonable people can absolutely come to different conclusions, but I think it is arrogant to believe that a different decision from the one you would have made could only result from incompetence or ignorance.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#637
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

>So what kind of 2FA would be homeless-proof? Drop the password requirement. Use fingerprints + face. Very hard to lose these, but not impossible. Note, this solution is 1.5FA, but would solve the issue at hand. (pun alert)

Very easy to lose the features of those that tracking systems identify, however. Scar tissue makes most fingerprint systems fail over the smallest of changes, and facial scarring is also, unfortunately, not an uncommon issue among the homeless.

Ignoring the issue of device accessibility - which is the crux of the 2FA problem.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#638
post #183

Earlier quoted context omitted.

This is the sort of performative response that is the problem. Let's say we force Google to switch off 2FA. Now we have exposed millions of people who don't know any better to phishing attempts and financial loss. And the group we are trying to help isn't really better off. There are so many other questions we could be asking. Why are they directed towards picking Gmail by default? Why is the system to give a replace…

> Why is the system to give a replacement phone every 12 weeks instead of investing in a dedicated device that's much harder to damage or lose? Why is keeping the same number a hassle? If you're homeless, you're getting robbed. It doesn't matter that a yubikey would be worthless to a person mugging you, they'll take everything including the worthless stuff. Or you're being picked up by an ambulance and taken to a beh…

The downvotes are strange to me, because absolutely pointless thefts absolutely do happen in urban spaces, even for the non-homeless. Why would someone smash a car window just to steal a pair of prescription sunglasses that would be completely useless to 99.9% of people? I have no idea, but it happened to me.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#639

Earlier quoted context omitted.

Google is a multi-billion dollar company, they barely have to lift a finger. They simply have to provide an option to opt out of 2FA. Add a bunch of warnings if you must. Even if Google was a small startup it would be trivial for them to do this.

There is already an option to opt out of 2FA: https://support.google.com/accounts/answer/1064203

If you turn off 2FA, it will still force you to add a phone number and use an SMS verification code sent to it whenever the big machine feels like it.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#640
post #599

Earlier quoted context omitted.

Or just let people to disable 2FA. That's simplest and easiest solution. Slap a red warning label if you need to.

For better or worse, I can’t set my password to be “password” or any other number of weak words, and also need a number and symbol. Same principle in practice here.

It's realistic to expect people to remember a difficult password eventually. It's not realistic to expect them to recover the SIM card from a phone that was stolen from them in the middle of the night and pawned for drugs or broken down into parts.
Post reply on HN