Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

711–720 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#711
post #635

Earlier quoted context omitted.

Having to guess several times != having forgotten your password. I think what this actually calls for though is a way to prove your identity by talking to an actual human. Something that used to be the standard before tech companies declared that it was too inefficient.

Sadly, SIM cloning attacks start by social engineering a cell phone support person into sending the attacker a replacement for the SIM they "lost".

Your thinking of SIM swapping attacks. SIM cloning is much harder without breaching the SIM manufacturer (often Gemalto or another giant vendor).

Rerouting traffic with a malicious home location record (like what was done to Merkel for years), or changing the eSPID/NNID for a numbers texting enablement is much easier than doing a SIM swap and you can usually avoid detection too.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#712
post #570

Earlier quoted context omitted.

Do you just go into the carrier's store and ask them to change it, or do you have some streamlined way of changing it? Every time I go into one of those stores it seems to take hours to get even the simplest thing done.

I just buy new $90 mint prepaid sims for cash. They work for three months. I have never talked to a CSR.

That sounds like the dream. What do you do for 2FA stuff that requires a consistent number?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#713

Earlier quoted context omitted.

Many people exist and use email before becoming homeless. When that email is gmail - they actually do have to use it when they become homeless!

I think if you trolley-problem this you'll still end up with Google's choice being the right one.

I did and I don’t. Absolutely depends on the value and risk weighting you give to homeless people needing their email, of course.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#714
post #594

Earlier quoted context omitted.

Sure. My point was indeed to suggest we rethink what government can do. Can governments (not necessarily the federal government) run a public service internet system? Sure, and probably more easily than we can, as another poster suggested, regulate tech companies into providing the right tradeoffs for housed and unhoused users.

I've been on municipal Broadband and it was fine. I ended up moving to a private provider because it was better and cheaper. When it comes to the right trade-off for the housed and the unhoused in terms of email service, I'm skeptical that the solution is regulatory. It seems like there is a large number of email providers that already offer what the homeless need. The problem is simply setting them up with the corre…

Sure. I was also saying the solution is not regulatory.

But, look at that: the federal government already provides the homeless with cell phones. Yet instead of arguing that the government should also provide free email—which of course costs far less than cell service—the poster argues that existing commercial services should better serve the homeless.

Which, of course, would be nice! But my point was that this kind of argument seems to reflect a mistaken perception of free online services as some sort of social service, with commensurate obligations.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#715

Earlier quoted context omitted.

The vital services are provided by the government, but require an email address. Some people have trusted Google to be their email provider, and Google is failing some of those people by denying them access unnecessarily.

I'm saying that if the public/government doesn't feel like Google's security policies are compatible with the homeless, the simplest solution is to set up a government-run email host.

Sure, the government should.

But we should also expect Google to give a small crap about the troubles it's putting some of its users through, especially when this is so important to some of its most vulnerable users, and adding an option to disable 2FA is such a small feature for a Mega corporation.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#716

Earlier quoted context omitted.

Neither. Gmail is an email provider which has provided access to an account that these people have registered with providers of vital services.

And? Not every service is homeless-friendly. That's fine. There are literally hundreds of free email services.

Why is it fine? Why should we not ask and expect that one of the largest corporations on the planet make a tiny effort to improve the lives of some of its users at very little cost to them?

Sure, homeless people and those who help them should pick an alternate free email service. And the government should either set up its own email or stop requiring email contact for this sort of thing. But for people who are already Google users, Google should also try to make their lives significantly easier with a tiny bit of effort (allow someone to explicitly disable 2FA for gmail - with all the warnings and cautions that they can).

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#717

Earlier quoted context omitted.

I don't think it's difficult! • The people who want security get to keep all the security they get today. • The people who don't think about security and leave default settings intact keep all the security they get today. • The people who explicitly ask for less security get less security. • Some of the homeless will get increased access to vital services. It's a win-win—unless you believe, for some reason, that peop…

> The people who explicitly ask for less security get less security. The problem with that is less security is almost always more usable than more security, which leads to the greater amount of people being in that state, which is not just a danger to the user making the choice, it is a danger to others.

Unless the requirement is extremely onerous, very few people will go into settings to check if it can be circumvented. For homeless people, it seems that it is indeed extremely onerous, so they or those who help them will have a reason to do this, but few others.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#718

Earlier quoted context omitted.

OK, so what solution are you proposing for someone who doesn't have permanent, safe storage for their property?

How about an option for in person account recovery provided by a government official?

Only works if you live in a major city. Sounds like the DMV but 10 times worse.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#719

Earlier quoted context omitted.

Sadly, SIM cloning attacks start by social engineering a cell phone support person into sending the attacker a replacement for the SIM they "lost".

Your thinking of SIM swapping attacks. SIM cloning is much harder without breaching the SIM manufacturer (often Gemalto or another giant vendor). Rerouting traffic with a malicious home location record (like what was done to Merkel for years), or changing the eSPID/NNID for a numbers texting enablement is much easier than doing a SIM swap and you can usually avoid detection too.

The irony of SIM cards being a cryptographically strong smart card and then carriers let their employees give out replacement SIMs left and right. Ah, humans.

fun fact: SIM cards can run applets based on Java. That’s how mobile payments are able to work in developing nations. I think there was a DEFCON talk about it a few years ago.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#720
post #299

Earlier quoted context omitted.

>No the device auth prompts are completely independent of mobile number, you don't even need a Sim card. Sorry, I don't understand, I believed that the independence from the SIM for an app was for an app already installed and authenticated on the specific device. If you lose the smartphone (with the app), and the SIM, how can you install the app and be authenticated on another device? I mean short of a SMS or a code…

If you lose your device it's a problem, but at least you don't need a local cell phone plan. (I'm almost locked out of my Canadian bank because it won't accept international phone numbers for 2FA.) If you know this will be a problem you can enrol with TOTP, using an app but also writing down the initialisation code or printing out the QR code. This is almost the same as having 2FA recovery codes written down somewher…

Yep, but the issue (in the specific case of the homeless) is that the devices (and the - let's call it "optional" - SIM/local cell phone number) are lost/stolen, the written down emergency/recovery codes may work IF the other idea (luggage deposit) is implemented, let's call it EPBD (Essential Personal Belongings Deposit).
Post reply on HN