In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…
> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?
Gmail 2FA causes the homeless to permanently lose access 3 times a year
671–680 of 770 posts
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#672Earlier quoted context omitted.
> Universal utilities like Google should have retail outlets which are adapted to local conditions and can exercise educated judgement. Sorry but this just isn't happening, and if there is regulation to make something like this happen, companies will just turn off their services. Plus this would essentially seal off competition: want to run an email hosting startup? Guess you have to manage real estate all over the w…
> Guess you have to manage real estate all over the world and work with every government. Or, you know, pass a deal with post offices or banks. Bank ID is pretty widespread in nordic countries for instance. But as with other topics (e.g. banking services) we're getting the usual HN answer where anything unheard of in SV but common elsewhere is considered luxury science fiction.
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#673Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#674Earlier quoted context omitted.
> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…
Frame challenge - 2FA doesn’t solve any problems that are actually problems for the homeless. A homeless person has a vastly different cybersecurity paradigm, specifically, they don’t need much in the way of cybersecurity. Nobody is stealing a homeless person’s identity. Given that, just let them disable it, and let them just use a password. It’s fine to rate limit them if they forget the password a few times, but le…
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#675Earlier quoted context omitted.
> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?
Quite simply there are multiple factors at play here. Do you force 2FA on almost everyone and reduce hostile account takeovers to negligible? Do you allow for no 2FA and permit the homeless use case? I think Google faced a trolley problem and made the right decision. You need a different tool "homeless mail" for them. It's Gmail. You don't have to use it. There's a lot of mail providers out there. Whatever, if this g…
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#676You lose your entire Google account if you lose your 2FA device or number (assuming it's a phone number), for any reason. Even if your Google account is set up with a non-Google email address which you still have access to, and you still know the correct password. And there's nobody you can reach at Google about it, no appeals process, nothing. https://news.ycombinator.com/item?id=33098261
This is what one-time backup codes are for. Alternatively you can purchase a hardware key and store it in a trusted place, but admittedly they are expensive, so OTBC is the usual route.
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#677I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system h…
> I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? Almost every free email service I've tried now requires a phone number to setup. Even protonmail required it for a brief while, although they now are back to captch…
Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#678Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year
#679Why can't they use Fastmail? It's as if Gmail is the only email provider any more.