Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

691–700 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#691
post #661

side question from the tweet: is "unhoused" the politically correct version of "homeless"? How is it any better?

Yes and the other new terminology is "persons experiencing homelessness"

It's all so tiresome honestly. One of the absolute worst things about western culture is the apparent creeping obsession with political correctness that has been escalating for the past few decades.

If only more westerners were like the great George Carlin. Grateful for once to live in the third world.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#692
post #3

I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system h…

> and warn fellow homeless to avoid gmail

Besides the fact that this doesn't scale at all, not using gmail is arguably a bad decision. If you have an email address at shiftydomain.com, some services won't accept it because its low barriers to entry may have been exploited by spammers or similar.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#693
post #181

You lose your entire Google account if you lose your 2FA device or number (assuming it's a phone number), for any reason. Even if your Google account is set up with a non-Google email address which you still have access to, and you still know the correct password. And there's nobody you can reach at Google about it, no appeals process, nothing. https://news.ycombinator.com/item?id=33098261

That link involves someone with no backup email address connected to their google account for recovery purposes, for what it's worth.

I lost access to a Gmail account for which I had the correct password and a recovery email with a different email service. I was still unable to convince the Google machine that the account was mine. My suspicion is that because I'd changed operating systems on my desktop, I appeared to be 'someone else' as far as Gmail was concerned.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#694
There is a very simple flaw in the "Obamaphone" system that is the root cause of this catch-22 dilemma. I was homeless and had to use an Obamaphone, so I saw first hand how this flaw works.

My solution to this problem was simple: don't use Google. Use Yandex instead because they never require a phone for 2FA and they allow you to set your own custom security questions for account recovery as well as link a backup email account to reset your password. It would be trivial for Google to have these features too, but they won't because this is about spying and tracking and controlling users by forcing everyone to use a SIM card.

The Federal Govt doesn't "give" you a free phone. Cellular carriers give you the phone and the service when you sign up at one of their kiosks usually setup outside local Govt offices that provide services to the homeless. Like the food stamps office.

So you sign up witg T-Mobile or Verizon or smaller carriers nobody has heard of and you get your cheapo off-brand phone with low specs like 1GB of RAM and 3GB of cellular data per month. Great, that is an amazing way to help the homeless since doing everything requires a cell phone now.

But when you sign up, the carriers require you to provide a cirrebtly valid food stamps EBT card and a govt ID like a drivers license with your mailing address on it. They mail a form to that address within 60 days that you must sign and mail back to them to prove you are who you claim to be. I guess this is for fraud detection.

But if you are homeless, then obviously you will never be able to receive that form in the mail to prove you are who you claim to be. Then after 90 days if you have not returned your form in the mail, your free phone service is terminated.

You can immediately go and get a new Obamaphone, but you will have a new number and a new account. There is no way to port your old number because each carrier has totally separate systems to store your account.

This whole Obamaphone program is extremely wasteful because it is intended to help the homeless, but it is implemented to force the homeless to constantly churn through getting new phones every 90 days. I went through several different Obamaphones because of this. Typical Big Govt inefficiency I guess.

It is too bad that Google is so obsessed with spying on people and blibdly trusting SIM cards because you can still use Wifi on an Obamaphone that has been deactivated for cellular service. I don't know why Google refuses to base 2FA on something other than a SIM card. They already control the hardware through Android, so the phone hardware IMEI ID itself should be able to be used as a unique identifier.

Unmoored, trillion dollar megacorporations on autopilot like Google who are managed by multimillionaires Executives living in Silicon Valley and who are staffed by millionaire developers designing these systems of global information control do not think of the use case needs of the poorest, disadvantaged users who fall through the cracks.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#695

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

> How about the homeless person remembers a good password, and that's all that's needed for authentication? Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place? Passwords alone are a bad solution (often forgotten, easily re-used insecurely) for people without all of the challenges and frequent mental issues that accompany homelessness, why would you think they'd be a good so…

> Gosh, I don't know, how about literally all of the problems that 2FA solves in the first place?

It is clearly failing for this use case.

Security can't be seen as a one-size-fits all threat models. That will never be satisfactory, as requirements vary.

For most people in most scenarios 2FA is a net positive.

But denial of service is also a component of evaluating threat models. Here we're discussing cases where 2FA causes denial of service which is worse than any risk of getting the account stolen by password guessing.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#696
post #15
post #3

I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system h…

The phone number decision is stupid. I up and jump countries every few years. Each time, I'm switching to a new number. I'm the opposite of homeless, I'm that jet set elite. The idea that you want, need, should or will tie your identity to a phone number where people can always reach you is long outdated.

I'm in the same boat; it's always a pain for services you don't login to that often but do need every 1-2 years. Account recovery ranges from "a pain" to "damn near impossible". I wasn't able to recover my PayPal account for example.

I also don't use my phone much, and the only reason I even have one of those things is because it's "needed" for so many things.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#697
post #523

Earlier quoted context omitted.

> Here's the solution: Since OP is regularly in contact with 30+ homeless people, he can offer to be their backup email account. He can then confirm the identity of people if they lose access to their account and help them get it back. > Or, he can safely store their 2FA backup codes in his house. Why even have security? Your solution practically screams for those 30+ people to be taken advantage of. Just use a diffe…

Why would Chad Loder take advantage of them? Yes, it gives him the ability to, but that doesn't mean he will. Why have security? So some random, untrusted person can't compromise the account. If Chad holds the codes, then only he can compromise the account, and maybe their relationships are good enough that they would trust him. Using a different email provider also works, but I assumed there would be some reason tha…

> Why have security? So some random, untrusted person can't compromise the account.

I know why there should be security. I was pointing out that what you suggested would degrade security.

It's not whether one specific person would do anything with 30 phones' backup codes but that such a list would exist. There are many other valid security practices that can be used.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#698

Earlier quoted context omitted.

Was just reading about how Overwatch 2 won't let people register with a prepaid phone number. I'm sure there is some good reason to want to avoid people spinning up free or ultra low cost phone numbers to make extra accounts but some users were like, "I've been using TracPhone for a decade" or something like that. Also pretty surprised that it's this easy to detect the carrier. Guessing we'll see this more and more!

The problem will solve itself. People unwilling to sign up for a mobile plan for playing a game will automatically boycott the likes of Overwatch 2, which will result in revenue lost (perhaps to competing games that allow prepaid cards). I have only ever used prepaid cards. I would rather be cut off from communication (or buy a local prepaid card) than get a surprise bill of hundreds of euros for visiting a country o…

Is the loss of income enough to offset against the benefits (fewer trolls, spammers, scams, etc.)? I'm betting it's probably not.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#699
I very explicitly do not have 2FA enabled on my email account, and it's also the only account that's not a random password from my password manager but rather a (very) strong password I memorized.

Maybe my house will get burgled, maybe I will lose all my stuff in travel, or a fire, or ... I don't know. Email is kind of the key to everything, which makes 2FA important, but can also a huge pain in all sorts of exceptional situations, and losing access to your email often means losing access to lots of other stuff, too.

I feel account access is still an unsolved problem; 2FA is a meh stop-gap solution at best with lots of trade-offs. Ideally your account should be tied to your identity (e.g. passport or the like) in a privacy-secure manner.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#700
post #498

Earlier quoted context omitted.

Those steps don’t actually turn off 2FA for Google accounts. If you login from a new computer or unrecognized IP, Google forces you to use the YouTube app on your phone to enter a “code” to login. It sometimes doesn’t even let you get a text code. God forbid I lose my phone or delete the YouTube app and login from a new IP. I don’t know how I would even get into my account. I don’t know how this isn’t a wider spread…

Have you actually tried disabling 2FA? Because I just did. I followed the steps above then signed in to Google from a clean browser profile with password only. No problem. Then I connected to a VPN in a different country and signed in from another clean profile. Again, no problem. If you have 2FA enabled, then yes, of course it will ask you for the second factor if you're doing something unusual. But with 2FA disable…

Yes, I’ve tried turning it off and on multiple times and it still makes me do 2FA.
Post reply on HN