Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

641–650 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#641
post #238

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

OK. Let's play a game. Let's say I care. Let's say I care a lot . I care so much that I'm willing to make it my personal problem to address the very real, very pressing needs of a critically vulnerable and marginalized part of my community from inside Google. What am I going to do? Is anyone going to be happier if I stand up and proclaim loudly how much I care? Probably not. Could I say "Gee, what if we just let ever…

You're reducing the concept to an absurdly simplistic level in order to create simple vulnerabilities.

As I wrote, THIS WOULD NOT BE THE DEFAULT. It is quite possible to pre nominate the specific groups that can allow unlocking of an individual account. And that's all it is, account unlock when they use a new device, or putting the account into PW only mode for a period.

If the PW is forgotten you require a higher level of identity verification, like a bank/USPS/DMV process.

Facebook already has this enabled, you can have a friend/family member (or two of them!) validate your account.

If you're determined not to find solutions then you won't progress.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#642
post #498

Earlier quoted context omitted.

That's almost exactly what Google has done. Here's how you turn off 2FA on your account: 1. Go to myaccount.google.com 2. Press "Security" 3. Press "2 step verification" 4. Enter your password 5. Press "Turn off" 6. Confirm the dialog that says "Turning off 2-Step Verification will remove the extra security on your account, and you’ll only use your password to sign in."

Those steps don’t actually turn off 2FA for Google accounts. If you login from a new computer or unrecognized IP, Google forces you to use the YouTube app on your phone to enter a “code” to login. It sometimes doesn’t even let you get a text code. God forbid I lose my phone or delete the YouTube app and login from a new IP. I don’t know how I would even get into my account. I don’t know how this isn’t a wider spread…

Have you actually tried disabling 2FA? Because I just did. I followed the steps above then signed in to Google from a clean browser profile with password only. No problem. Then I connected to a VPN in a different country and signed in from another clean profile. Again, no problem.

If you have 2FA enabled, then yes, of course it will ask you for the second factor if you're doing something unusual.

But with 2FA disabled, logging in with just a password works fine.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#643
post #594

Earlier quoted context omitted.

Looking at your numbers or just social spending, it is increased 50% since 1990 as a portion of GDP. Real GDP adjusted for inflation itself has increased more than 3x since 1990. This means that us social spending in terms of inflation adjusted purchases has gone up more than 450% from 1990 levels. This excludes military spending and is adjusted for the purchasing power of those dollars. I don't know about you, but I…

Sure. My point was indeed to suggest we rethink what government can do. Can governments (not necessarily the federal government) run a public service internet system? Sure, and probably more easily than we can, as another poster suggested, regulate tech companies into providing the right tradeoffs for housed and unhoused users.

I've been on municipal Broadband and it was fine. I ended up moving to a private provider because it was better and cheaper.

When it comes to the right trade-off for the housed and the unhoused in terms of email service, I'm skeptical that the solution is regulatory. It seems like there is a large number of email providers that already offer what the homeless need. The problem is simply setting them up with the correct provider and user settings.

This seems like a job for people that work with the homeless.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#644
post #238

Earlier quoted context omitted.

OK. Let's play a game. Let's say I care. Let's say I care a lot . I care so much that I'm willing to make it my personal problem to address the very real, very pressing needs of a critically vulnerable and marginalized part of my community from inside Google. What am I going to do? Is anyone going to be happier if I stand up and proclaim loudly how much I care? Probably not. Could I say "Gee, what if we just let ever…

You're reducing the concept to an absurdly simplistic level in order to create simple vulnerabilities. As I wrote, THIS WOULD NOT BE THE DEFAULT. It is quite possible to pre nominate the specific groups that can allow unlocking of an individual account. And that's all it is, account unlock when they use a new device, or putting the account into PW only mode for a period. If the PW is forgotten you require a higher le…

Gmail already has a system for using one account to unlock another, so no changes required there. A bank, USPS, or DMV generally requires ID or other identifying documents. The people we're trying to help often struggle to retain physical possessions like ID.

It's not that I'm determined to not find solutions. It's that I am determined to find solutions that don't create a degraded security state ready-made to abuse people's email accounts. Sometimes finding a good solution requires looking somewhere other than under the streetlight.

Like others, I'm led to the conclusion that perhaps Google isn't the party best positioned to solve this particular pain point for our most vulnerable and marginalized community members. Maybe we should be paying more attention to why Lifeline numbers aren't portable.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#645

Earlier quoted context omitted.

> So what kind of 2FA would be homeless-proof? Almost certainly is a bad idea. But the first thing that seems like it could work would be an implantable nfc yubikey. Then making more devices support nfc. I know I would be pretty tempted to get an implantable 2FA device if one was available and seemed like it would have both broad and long term support.

Ah, yes I can read the headline now “GOVERNMENT PROGRAM TO CHIP HOMELESS PEOPLE LIKE DOGS TO PROVE IDENTITY” I implore you to read The Scarlet Letter and perhaps read up on [similar such things]( https://en.wikipedia.org/wiki/Identification_of_inmates_in_G... ).

Oh come on now, you're being a little harsh. They prefixed the comment with "Almost certainly would be a bad idea"

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#646
post #299

Earlier quoted context omitted.

No the device auth prompts are completely independent of mobile number, you don't even need a Sim card. Giving homeless people a secure and convenient place to stash documents would be a great outcome. Birth certificate, military discharge papers, licences, 2FA codes. Many homeless people live in cars and have all this stashed somewhere in the car, but then the car gets stolen/towed (e.g. because they haven't paid ca…

>No the device auth prompts are completely independent of mobile number, you don't even need a Sim card. Sorry, I don't understand, I believed that the independence from the SIM for an app was for an app already installed and authenticated on the specific device. If you lose the smartphone (with the app), and the SIM, how can you install the app and be authenticated on another device? I mean short of a SMS or a code…

If you lose your device it's a problem, but at least you don't need a local cell phone plan. (I'm almost locked out of my Canadian bank because it won't accept international phone numbers for 2FA.)

If you know this will be a problem you can enrol with TOTP, using an app but also writing down the initialisation code or printing out the QR code.

This is almost the same as having 2FA recovery codes written down somewhere.

A secure version of luggage deposit, but just for small things. We used to have safe deposit boxes at banks, though it doesn't need to be that secure. The key limitation is that the client can't travel far, and they have to be able to open it based on a matching photo, not an identity card.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#647

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

Hopefully we will be able to get digital credentials from state and local entities that will help with this sort of issue. It’s a problem all around - the elderly are most vulnerable to the types of account takeovers that MFA will prevent.

I think FIDO2 keys are probably ideal -- people understand the concept of keys.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#648
post #312

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

> Practically, we need ideas like to 2FA to gain tractionas widely as possible, while realising that isn't everywhere. thats just one opinion on security. you see this world where google is an identity provider, and you prove your identity to it via a librarian or bank. i dont. an internet service should absolutely never require any form of government id nor separate network like cell.

You're failing to read my argument: for some people normal 2FA is too hard, and they need help from a local organisation.

But not for ALL people. Just for the people who need it.

You keep using TOTP and GPG email all you want, just don't get in the way of them getting basic services like social security.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#649

Earlier quoted context omitted.

> In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. This is not a technical problem and should not be automated away. Rely on trustworthy third parties. Universal utilities like Google should have retail outlets which are adapted to local conditions and can exercise educated judgement. In some cou…

> Universal utilities like Google should have retail outlets which are adapted to local conditions and can exercise educated judgement. Sorry but this just isn't happening, and if there is regulation to make something like this happen, companies will just turn off their services. Plus this would essentially seal off competition: want to run an email hosting startup? Guess you have to manage real estate all over the w…

> Guess you have to manage real estate all over the world and work with every government.

Or, you know, pass a deal with post offices or banks. Bank ID is pretty widespread in nordic countries for instance.

But as with other topics (e.g. banking services) we're getting the usual HN answer where anything unheard of in SV but common elsewhere is considered luxury science fiction.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#650

Google's 2FA is dreadful. 2FA is a good idea when it's added with consent, but Google adds it behind your back in ways that are both infuriating and brain-dead. I've been caught out recently twice: once I was away on work and had to access my email. Google demanded that I verify it using my phone that I'd previously accessed my work email with. However, this phone was just a phone I use for development, had never had…

Apple does it too. I have three iPhones, one much older than the other two. Recently, in one of my new iPhones, Apple decided to ask me about my passcode I used in my “giggleupstairs’s iPhone” for some special verification scenario. Now, what? I have THREE iPhones, how will I remember which iPhone is this generic looking iPhone name referring to? I kept entering what I thought was the correct passcode for at least th…

fwiw, the passcode challenge is for decrypting your keychain. If you fail that, you lose your passwords and other E2E data, but for better or for worse, not that much stored stuff is E2E encrypted and so you don't lose too much. I don't know if it's still true, but a few years back if you lost everything (i.e. didn't know your passcodes, didn't have a device to approve the sign in from) you could still get back into your account by waiting two weeks and recreating your keychain. This also means that if you are ever away from the internet for two weeks and someone knows your password that they can jack your shit but that's quite the edge case imo.
Post reply on HN