Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

651–660 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#651
post #644

Earlier quoted context omitted.

You're reducing the concept to an absurdly simplistic level in order to create simple vulnerabilities. As I wrote, THIS WOULD NOT BE THE DEFAULT. It is quite possible to pre nominate the specific groups that can allow unlocking of an individual account. And that's all it is, account unlock when they use a new device, or putting the account into PW only mode for a period. If the PW is forgotten you require a higher le…

Gmail already has a system for using one account to unlock another, so no changes required there. A bank, USPS, or DMV generally requires ID or other identifying documents. The people we're trying to help often struggle to retain physical possessions like ID. It's not that I'm determined to not find solutions. It's that I am determined to find solutions that don't create a degraded security state ready-made to abuse…

It's routine in disaster relief situations that people lose all their documents but then governments step in and allow identity verification via vouching: this other person Alice says you're Bob. Then Bob gets his photo on a temporary ID document and gets a DR payment.

Social workers, shelters, libraries etc are well placed to support that. They know these people because they see them every day.

If you choose to enrol in the "community assisted recovery" process then you could enrol a new device into your email with their help. Put a big red banner at the top of the email client saying "Community recovery via Topeka Library, Kansas".

Lifeline numbers aren't portable because people have no way to prove their ownership of the previous number, because they have no ID.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#652
post #635
post #622

Earlier quoted context omitted.

Lower in the same thread: https://twitter.com/chadloder/status/1577906942080598017?s=6... > PS: Many unhoused people access their email rarely, intermittently; they don't stay logged in. They often have to guess several times to remember their password. 2FA doesn’t work, and remembering passwords doesn’t work either. Checkmate.

Having to guess several times != having forgotten your password. I think what this actually calls for though is a way to prove your identity by talking to an actual human. Something that used to be the standard before tech companies declared that it was too inefficient.

Sadly, SIM cloning attacks start by social engineering a cell phone support person into sending the attacker a replacement for the SIM they "lost".

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#653
post #599

Earlier quoted context omitted.

Or just let people to disable 2FA. That's simplest and easiest solution. Slap a red warning label if you need to.

For better or worse, I can’t set my password to be “password” or any other number of weak words, and also need a number and symbol. Same principle in practice here.

Why would a strong password and needing an entirely different communication channel be the same thing? That's like saying walking to work and needing to drive a car to work are the same thing.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#654

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…

Frame challenge - 2FA doesn’t solve any problems that are actually problems for the homeless.

A homeless person has a vastly different cybersecurity paradigm, specifically, they don’t need much in the way of cybersecurity. Nobody is stealing a homeless person’s identity.

Given that, just let them disable it, and let them just use a password. It’s fine to rate limit them if they forget the password a few times, but let them keep trying to log in until they remember it.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#655
post #644

Earlier quoted context omitted.

Gmail already has a system for using one account to unlock another, so no changes required there. A bank, USPS, or DMV generally requires ID or other identifying documents. The people we're trying to help often struggle to retain physical possessions like ID. It's not that I'm determined to not find solutions. It's that I am determined to find solutions that don't create a degraded security state ready-made to abuse…

It's routine in disaster relief situations that people lose all their documents but then governments step in and allow identity verification via vouching: this other person Alice says you're Bob. Then Bob gets his photo on a temporary ID document and gets a DR payment. Social workers, shelters, libraries etc are well placed to support that. They know these people because they see them every day. If you choose to enro…

This feels ever-increasingly like asking Google to cover the role of a government agency. Universal service is something we expect of government agencies. It's rarely something we expect of private enterprise.

The whole "community recovery" concept sets my teeth on edge. It's a whole alternative authentication avenue ripe for exploitation. Anything that positive and innocuous sounding is going to be the target of many an abuse campaign - think Cambridge Analytica and all the people who handed over their info to innocuous-looking things. Telling people all their info has been stolen isn't all that helpful for protecting them and knowing the specific library or shelter that authorized it will do very little to help.

Plus it turns the people designated as recovery agents into high-value targets.

Again, I'm not trying to avoid finding a solution. I'm trying to avoid finding a "solution" that puts a large number of people at risk unnecessarily.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#656
As someone who uses 2FA extensively and even has 1Password autofill the OTP codes - 2FA is objectively fucking brutal.

Half of you in here have never met a non-technical user. These folks should not have 2FA on ever, because they can't even use the damn thing with it on.

Yes, those users run a higher risk and should be notified of that extremely clearly. But 2FA is a garbage solution to the problem and it should always be possible to disable it.

I'm going to continue using 2FA happily like most of those in here - but man the lack of empathy is outstanding in here. I feel bad for your users.

And fuck Discord for not allowing me to reset my account with my own damn email address when my phone broke that one time. Total morons, through and through. I'd never want to work with anyone so objectively ignorant and unwilling to admit their ass backwards position.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#657
post #599
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

Or just let people to disable 2FA. That's simplest and easiest solution. Slap a red warning label if you need to.

You mean like this?

https://support.google.com/accounts/answer/1064203?hl=en

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#658
post #18

Earlier quoted context omitted.

Maybe we don't need to meet all those requirements simultaneously. The on boarding process could try to determining if 2fa would actually benefit you or not.

>The on boarding process could try to determining if 2fa would actually benefit you or not. How?

By the complexity of the password you choose?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#659

Earlier quoted context omitted.

Quite simply there are multiple factors at play here. Do you force 2FA on almost everyone and reduce hostile account takeovers to negligible? Do you allow for no 2FA and permit the homeless use case? I think Google faced a trolley problem and made the right decision. You need a different tool "homeless mail" for them. It's Gmail. You don't have to use it. There's a lot of mail providers out there. Whatever, if this g…

Many people exist and use email before becoming homeless. When that email is gmail - they actually do have to use it when they become homeless!

I think if you trolley-problem this you'll still end up with Google's choice being the right one.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#660
post #15
post #3

I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system h…

The phone number decision is stupid. I up and jump countries every few years. Each time, I'm switching to a new number. I'm the opposite of homeless, I'm that jet set elite. The idea that you want, need, should or will tie your identity to a phone number where people can always reach you is long outdated.

Fortunately Google doesn't require phone numbers for account access. See, for example: https://www.androidauthority.com/gmail-without-phone-number-...

You do need to be able to receive a texted code at a phone number to create a brand-new account. This is to deter spammers from creating lots of accounts. But once that's done, you can remove the phone number from the account.

Post reply on HN