Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

671–680 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#671
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

Apparently there is great concern about nation-state-level attacks against the unhoused.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#672
post #649

Earlier quoted context omitted.

> Universal utilities like Google should have retail outlets which are adapted to local conditions and can exercise educated judgement. Sorry but this just isn't happening, and if there is regulation to make something like this happen, companies will just turn off their services. Plus this would essentially seal off competition: want to run an email hosting startup? Guess you have to manage real estate all over the w…

> Guess you have to manage real estate all over the world and work with every government. Or, you know, pass a deal with post offices or banks. Bank ID is pretty widespread in nordic countries for instance. But as with other topics (e.g. banking services) we're getting the usual HN answer where anything unheard of in SV but common elsewhere is considered luxury science fiction.

This still isn’t totally a tech fix, you still need government buy in to build the infrastructure and make it usable.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#673
post #300

Earlier quoted context omitted.

I took one step: 1) Don't use anything Google.

You took a step that requires a lot of skill, wealth, and privilege.

Privilege?

Really?

Or did you just toss that in for the free upvotes?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#674

Earlier quoted context omitted.

> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…

Frame challenge - 2FA doesn’t solve any problems that are actually problems for the homeless. A homeless person has a vastly different cybersecurity paradigm, specifically, they don’t need much in the way of cybersecurity. Nobody is stealing a homeless person’s identity. Given that, just let them disable it, and let them just use a password. It’s fine to rate limit them if they forget the password a few times, but le…

I think this comes from a supportive mindset, but working with homeless populations over the years I think they often were more at risk than many other groups. Significant numbers deal with domestic violence or otherwise abusive relationships, as one example, where these kinds of security issues can be life or death, and they often lack the digital hygiene skills many folks take for granted (I think half the folks in a computer lap I worked with left their password saved when chrome offered to remember it, or even wrote it down in a text file).

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#675

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

Quite simply there are multiple factors at play here. Do you force 2FA on almost everyone and reduce hostile account takeovers to negligible? Do you allow for no 2FA and permit the homeless use case? I think Google faced a trolley problem and made the right decision. You need a different tool "homeless mail" for them. It's Gmail. You don't have to use it. There's a lot of mail providers out there. Whatever, if this g…

You don't solve a trolley problem. The entire point is that it's unresolvable from most ethical paradigms other than naïve utilitarianism (which is why it exists - to mock that way of thinking).

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#676
post #181

You lose your entire Google account if you lose your 2FA device or number (assuming it's a phone number), for any reason. Even if your Google account is set up with a non-Google email address which you still have access to, and you still know the correct password. And there's nobody you can reach at Google about it, no appeals process, nothing. https://news.ycombinator.com/item?id=33098261

This is what one-time backup codes are for. Alternatively you can purchase a hardware key and store it in a trusted place, but admittedly they are expensive, so OTBC is the usual route.

yes I am confused why people aren't discussing OTBC ... is it an assumption that if you lose all your possessions then you lost these as well? Doesn't seem valid as you can certainly give them to a trusted person for safe keeping as well. Or bury them in the ground if you want somewhere.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#677
post #3

I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system h…

> I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? Almost every free email service I've tried now requires a phone number to setup. Even protonmail required it for a brief while, although they now are back to captch…

Fastmail doesn't require a phone number for 2FA.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#679

Why can't they use Fastmail? It's as if Gmail is the only email provider any more.

By definition homeless person doesn’t have much money and most likely no credit card or bank account. Who and how they are going to pay for fastmail?
Post reply on HN