Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

661–670 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#662

Earlier quoted context omitted.

The average person cannot remember a good password without some help, be it using it everywhere, writing it down, or using a password manager. Homeless individuals, on average, have many more stressors in life, much higher rates of traumatic brain injury, and a number of other factors that make their ability to remember good passwords much worse than the average person. Given this solution doesn't work for the averag…

How many passwords does an homeless person need to remember ? I’m with you that an average person is probably using at least dozens of services that need credentials, but these people are probably not login on Amazon or checking their 401k online for instance, nd can probably get by with a a very limited set of stuff to remember.

If they're relying on government social services, they may well have a whole plethora of accounts to manage that.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#663
post #15
post #3

I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system h…

The phone number decision is stupid. I up and jump countries every few years. Each time, I'm switching to a new number. I'm the opposite of homeless, I'm that jet set elite. The idea that you want, need, should or will tie your identity to a phone number where people can always reach you is long outdated.

you can also use a security key or a onetime password from an authenticator app (plenty of options for each) or a separate device logged into Google as your second factor. You have plenty of options

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#664

Earlier quoted context omitted.

> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…

OK, so what solution are you proposing for someone who doesn't have permanent, safe storage for their property?

How about an option for in person account recovery provided by a government official?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#665

Personally, I find it particularly infuriating that more and more companies are demanding to use phone-based 2FA even when I already have 2FA authentication set up . This applies to Google, too, which has forced me to add a phone number and get a SMS 2FA code for accounts that already had non-SMS 2FA configured. The whole reason I use an authenticator app is so that my accounts aren't dependent on having the same pho…

I'm sure you won't blame it on the "big bad tech" once you drop your phone in the pool and lose access to your accounts because they never asked you to create an SMS backup

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#666

Why is this guy mad at Google for implementing security (which I guarantee has saved a lot of homeless from account takeovers), when he could be mad at the government program for failing to provide people with a stable phone number? Constantly changing your phone number has a lot of other bad consequences which have nothing to do with Google. And maybe the government should consider providing an email account too. Th…

because that's what you get with a 140 character attention economy

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#667
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

Nothing a good old barcode on the wrist can't fix.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#668
post #526

Earlier quoted context omitted.

This is exactly it. And if you don't have a verification method on file, Google will just lock the account if it thinks something about your browser or IP address is unusual. Even if you know your password.

Speaking as a long-time Gmail user who doesn't have a mobile, this is kind of terrifying. Sounds like I need to look into moving to Fastmail or somesuch pronto.

If you have a backup email on your account, that's sufficient (assuming you can get into the backup email), at least in my experience.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#669
post #498

Earlier quoted context omitted.

Those steps don’t actually turn off 2FA for Google accounts. If you login from a new computer or unrecognized IP, Google forces you to use the YouTube app on your phone to enter a “code” to login. It sometimes doesn’t even let you get a text code. God forbid I lose my phone or delete the YouTube app and login from a new IP. I don’t know how I would even get into my account. I don’t know how this isn’t a wider spread…

Have you actually tried disabling 2FA? Because I just did. I followed the steps above then signed in to Google from a clean browser profile with password only. No problem. Then I connected to a VPN in a different country and signed in from another clean profile. Again, no problem. If you have 2FA enabled, then yes, of course it will ask you for the second factor if you're doing something unusual. But with 2FA disable…

I have no idea what part of Google's fingerprinting panopticon decided it was okay to let you in from a clean profile, but I can promise you that in the past, I have been locked out. Yes, 2FA was turned off. And there are lots of other reports of this happening around the web, and even here on HN, so I'm not unique.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#670

Earlier quoted context omitted.

Yeah and it also only works on your phone (or if you know how to make Google think you are on your phone) and in certain countries. All to my knowledge and based on my tests.

I just did it from Firefox on Linux in a private tab near Washington, D.C.. Fake name, no phone, no backup email. I was able to log out, sign back in, and send an email without any trouble. No doubt they're letting me through because some security heuristic says I'm a real human, and I'm sure they'd eventually make me provide a number if I continued using the account (this happened to me with my university G Suite ac…

We are talking about creating an new account, not about signing in.
Post reply on HN