Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

681–690 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#681
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

>kind of 2FA would be homeless-proof

What kind of 2FA would be human-proof?

Also, the tweet uses the word "permanent" but doesn't explain. How is it any more "permanent" than anyone else?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#682

As someone who uses 2FA extensively and even has 1Password autofill the OTP codes - 2FA is objectively fucking brutal. Half of you in here have never met a non-technical user. These folks should not have 2FA on ever, because they can't even use the damn thing with it on. Yes, those users run a higher risk and should be notified of that extremely clearly. But 2FA is a garbage solution to the problem and it should alwa…

>because they can't even use the damn thing with it on

Trump for example. Which is why his account was regularly hacked.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#683

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…

[deleted]

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#684

Earlier quoted context omitted.

I think there are possible solutions here for a library, off the top of my head, taking a picture of your face when dropping off the codes, so that when you come back and ask for your codes, the librarian can ID you against the picture they have. Basically what is done when verifying your ID card/passport when you travel/go to the bank etc... It wouldn't be a librarian doing someone a favour, but rather a service tha…

Yes this is sort of what I was envisioning. Not as much one trusted librarian doing a favour, but a librarian team having a filing cabinet full of backup codes and an ID process that they trust and that is appropriate for their community. This is the sort of thing that I think Google could support explicitly with more access control around it, but I don't think that's entirely necessary to get the benefits.

It would be too much of a target for hackers.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#685
2FA needs to be implemented in a more human-friendly manner. Apple does better with their "friend or family member" account recovery. 2FA needs to be something you know not something you have. Or at least needs to support that. Yes, this would be a problem for someone who doesn't know someone to be their backup. But that's a real edge case.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#686
post #601

Earlier quoted context omitted.

> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…

> Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Well, it isn't solving this one. Option to opt out would be nice. > aren't capable of keeping track of a physical device for more than N weeks? Bit ignorant of you. They could be just plainly stolen by someone else. A piece of rag working as a tent doesn't exactly have best physical security... > I'm not unsympathetic to…

Also they're frequently arrested, and if their "belongings" are unsafe (biologically contaminated, disgusting) they'll be discarded or ignored by police, if the person hasn't seen the police coming and thrown their belongings aside in the hopes of coming back for them later. Sad all around.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#687

Earlier quoted context omitted.

> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…

Frame challenge - 2FA doesn’t solve any problems that are actually problems for the homeless. A homeless person has a vastly different cybersecurity paradigm, specifically, they don’t need much in the way of cybersecurity. Nobody is stealing a homeless person’s identity. Given that, just let them disable it, and let them just use a password. It’s fine to rate limit them if they forget the password a few times, but le…

Wouldn’t a homeless persons identity be ideal to steal? There are lots of illegal immigrants that pay big money for a clean social security number and other things. It would probably take a homeless person longer to realize their identity has been stolen than a non-homeless person.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#688
post #665

Personally, I find it particularly infuriating that more and more companies are demanding to use phone-based 2FA even when I already have 2FA authentication set up . This applies to Google, too, which has forced me to add a phone number and get a SMS 2FA code for accounts that already had non-SMS 2FA configured. The whole reason I use an authenticator app is so that my accounts aren't dependent on having the same pho…

I'm sure you won't blame it on the "big bad tech" once you drop your phone in the pool and lose access to your accounts because they never asked you to create an SMS backup

I already have my own backups. Chaining me to a specific phone number on top of that isn't a backup, it's a liability.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#689
post #510
post #495

Earlier quoted context omitted.

I get funny looks when people ask for my email. I have @protonmail.com email

My sympathies go out to you, I get similar looks for not having a phone.

Likewise, I've never had a cellphone and I have no intention of ever getting one. Interacting with a website should never require a portable device.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#690
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

We will need to design it, but India has a biometrics system (yes big bad privacy issues) called aadhaar which is used for authentication in so many systems. As long as you can build and secure such a system, and people get used to it, as they are used to Socials now, it can be used to unlock a whole lot of things.
Post reply on HN