Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

701–710 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#701
post #498

Earlier quoted context omitted.

Those steps don’t actually turn off 2FA for Google accounts. If you login from a new computer or unrecognized IP, Google forces you to use the YouTube app on your phone to enter a “code” to login. It sometimes doesn’t even let you get a text code. God forbid I lose my phone or delete the YouTube app and login from a new IP. I don’t know how I would even get into my account. I don’t know how this isn’t a wider spread…

Then don’t use Google for email. There are plenty of other free email providers that do not employ that much security. Problem solved

My problem isn’t that gmail is too secure, it’s that the 2FA setting doesn’t actually turn off what it’s supposed to turn off. Not sure if this is a bug or intended behavior.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#702
post #589
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> So what kind of 2FA would be homeless-proof? I don't see a solution. There are three factor categories, what you know, what you are, and what you have. A password is what you know. A phone is what you have. Biometrics are what you are - facial recognition, thumbprints, etc. 2FA in one manner or another is used by various services, because the security recommendation is to pillar identification by at least two of th…

[deleted]

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#703
post #622

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

Lower in the same thread: https://twitter.com/chadloder/status/1577906942080598017?s=6... > PS: Many unhoused people access their email rarely, intermittently; they don't stay logged in. They often have to guess several times to remember their password. 2FA doesn’t work, and remembering passwords doesn’t work either. Checkmate.

> They often have to guess several times to remember their password.

I think pointless password rules are at the heart of this problem for many non-technical people who probably haven't been operating with a password storage solution and might not be used to that system or trust it.

Every platform has their own special requirements for passwords: some require a mix of capital and uppercase letters, some require numbers, some require a special symbol, some require a special symbol but no not that one, some restrict you from entering 3 of the same character in a row, some passwords have a short max character limit, some prevent certain characters like spaces, some require you to change it every so often, etc. Eventually, the password is forgotten or confused with another because of these pointless password rules.

I called them pointless password rules because they reduce the possible number of combinations required for an attacker to guess the password because any guessing program knows what can't possibly be valid combinations.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#704
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

So if there are certain vulnerable categories of people who cannot use any form of 2FA, where does that leave 2FA? Seems to me it should mean that it has to be optional, at least until we solve that problem.

That depends greatly on if the systems in question are expected to provide universal service or not. This is perhaps the crux of the question - do we expect Google to operate as a public service capable of delivering service in a way that meets the needs of 100% of the population? Or do we think it's acceptable for Google to decide that they're happy with 98%, modulo things like the ADA?

USPS serves every US address. Lone Star Overnight is allowed to mostly serve Texas without a requirement to also serve Maine.

Which category do we want Google to fall into? This kinda smells like we're expecting it to be a universally provisioned public service, but provided by a private entity with private funding.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#705

Earlier quoted context omitted.

Quite simply there are multiple factors at play here. Do you force 2FA on almost everyone and reduce hostile account takeovers to negligible? Do you allow for no 2FA and permit the homeless use case? I think Google faced a trolley problem and made the right decision. You need a different tool "homeless mail" for them. It's Gmail. You don't have to use it. There's a lot of mail providers out there. Whatever, if this g…

You don't solve a trolley problem. The entire point is that it's unresolvable from most ethical paradigms other than naïve utilitarianism (which is why it exists - to mock that way of thinking).

That's exactly the point here as well - well, without mocking the utilitarianism. It is natural that a corporation optimizes to its customers within the envelope of regulatory constraints.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#706
post #362

Earlier quoted context omitted.

> I'd rather get my accounts hacked because of password reuse than lose access to my email, forever. step 1: get your account hacked step 2: hacker changes password step 3: lose access to your email, forever What you've presented is not in fact a dichotomy, for any practical purposes.

Except that they're already losing access to email, forever. A small chance of it happening because of a hacker is better than a statistical guarantee of it happening from phone theft.

Th GGP was speaking in the first person. I personally have had hackers try to break into my account before, but have never lost my phone number. Furthermore, notwithstanding the policies of the "obamaphone" program, I would be able to recover my phone number if I lost my phone. So, speaking for the vast majority of people, it would be preferable to have losing my phone number lock me out of my account than having my password leaked lock me out of my account. If that is the dichotomy, and if we still care about the welfare of the average person, the correct choice is incredibly clear.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#707
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> So what kind of 2FA would be homeless-proof? I don't see a solution.

Biometric? Amazon One's hand recognition would be a decent solution here, though I'll be damned if I've ever met someone willing to try it. And I ask, every time I go to Whole Foods.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#708
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> So what kind of 2FA would be homeless-proof? I don't see a solution. Biometric? Amazon One's hand recognition would be a decent solution here, though I'll be damned if I've ever met someone willing to try it. And I ask, every time I go to Whole Foods.

what if they lost their eye or their arms?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#709

Not only Google. A much less critical or important thing but underlines the bad attitudes: I just tried to renew my cancelled Netflix membership yesterday. I am not allowed to do that without providing a phone number (I used Netflix for ca. 8 years without it). I do not provide that because I do not want to. I do not tie every aspect of my life to my phone number. In fact I do not want to tie any aspect of it to my p…

It's bullshit like this that makes The Pirate Bay a better option.

No ads, easy to use, free, and doesn't require a phone number or email.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#710

Earlier quoted context omitted.

I've often wondered that with a valid ID, that the gov does not give us an email noawdays. Especially one that does not require this asinine phone-validity garbage. I'd even suggest that maybe not use email-addresses as a login-name along with plenty of alias's for inbound and outbound that do not expose your "main" or account. And google is not alone here; many other major "free" email providers require a phone as w…

> I've often wondered that with a valid ID, that the gov does not give us an email noawdays. Especially one that does not require this asinine phone-validity garbage. Can you even imagine the nightmare of trying to police the usage of such a thing? Everything from simple spamming to harassment to child pornography, all complicated by the stricter scrutiny the government gets for who it can decide not to provide servi…

Yes, with actual police. Why anyone would use a government- issue email tied to their identity to traffic CP is absolutely beyond me.
Post reply on HN