Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

721–730 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#721

Earlier quoted context omitted.

I think if you trolley-problem this you'll still end up with Google's choice being the right one.

I did and I don’t. Absolutely depends on the value and risk weighting you give to homeless people needing their email, of course.

Based on Google documentation you can still turn off 2fa, so we are weighing the account security of the hundreds of millions of users who would never turn on 2fa but really should, versus the people who lose their 2FA verification method and are locked out of their account. Maybe the harm of not being able to login is worse than having your identity stolen but whose to say.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#722

Earlier quoted context omitted.

I've often wondered that with a valid ID, that the gov does not give us an email noawdays. Especially one that does not require this asinine phone-validity garbage. I'd even suggest that maybe not use email-addresses as a login-name along with plenty of alias's for inbound and outbound that do not expose your "main" or account. And google is not alone here; many other major "free" email providers require a phone as w…

> I've often wondered that with a valid ID, that the gov does not give us an email noawdays. Especially one that does not require this asinine phone-validity garbage. Can you even imagine the nightmare of trying to police the usage of such a thing? Everything from simple spamming to harassment to child pornography, all complicated by the stricter scrutiny the government gets for who it can decide not to provide servi…

This literally sounds like an FBI honeypot, they would love it.

The almost complete inability to moderate due to 1A is the largest of many fatal flaws in government run email

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#723
post #57

sorry but why are they losing their phones ? stolen ? sell it for drugs?

Shit gets stolen nonstop, and not just by fellow unhoused. When the police come and tear down camps, there's no expectation of recovering anything left behind. 9 times out of 10 they're followed by a public works crew throwing everything into dumpsters. Good luck getting your phone (or any of your other possessions) back.

i thought in california there's a recent law stopping police from tearing down camps because exactly homeless people's property is now considered same "class" as normal people's hence you can't just throw it out.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#724
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. This is not a technical problem and should not be automated away. Rely on trustworthy third parties. Universal utilities like Google should have retail outlets which are adapted to local conditions and can exercise educated judgement. In some cou…

Google’s advanced protection program is probably the most secure way to have an email address if you believe you are likely to be targeted by a sophisticated attacker. It requires a security key to sign in every time, limits sign in with Google, and only lets you use Gmail, Apple Mail, or Thunderbird as your email client.

Why Senators? They’re high ranking US government officials, they’re a prime target for state sponsored attackers.

Other than Protonmail I wouldn’t trust anyone else with my email. Gmail is close to if not the #1 non-governmental target for state sponsored attackers. The NSA runs secure email for TS-SCI communications but they don’t want to have to teach John Podesta how to not get phished, and Google has the best defense against those attacks if you enable advanced protection.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#725
post #662

Earlier quoted context omitted.

How many passwords does an homeless person need to remember ? I’m with you that an average person is probably using at least dozens of services that need credentials, but these people are probably not login on Amazon or checking their 401k online for instance, nd can probably get by with a a very limited set of stuff to remember.

If they're relying on government social services, they may well have a whole plethora of accounts to manage that.

I don't know how dire it is in general, but there's at least a fighting chance to have some kind of unified login at that level. NThinking about it, now that many "casual" sites also accept google login the number of accounts needed might really be minimal.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#726
post #649

Earlier quoted context omitted.

> Guess you have to manage real estate all over the world and work with every government. Or, you know, pass a deal with post offices or banks. Bank ID is pretty widespread in nordic countries for instance. But as with other topics (e.g. banking services) we're getting the usual HN answer where anything unheard of in SV but common elsewhere is considered luxury science fiction.

This still isn’t totally a tech fix, you still need government buy in to build the infrastructure and make it usable.

Bank ID doesn't involve governments.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#727
post #710

Earlier quoted context omitted.

> I've often wondered that with a valid ID, that the gov does not give us an email noawdays. Especially one that does not require this asinine phone-validity garbage. Can you even imagine the nightmare of trying to police the usage of such a thing? Everything from simple spamming to harassment to child pornography, all complicated by the stricter scrutiny the government gets for who it can decide not to provide servi…

Yes, with actual police. Why anyone would use a government- issue email tied to their identity to traffic CP is absolutely beyond me.

funny, USPS is still on the federal level last i was aware; and all your phone calls are monitored

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#728
post #3

I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system h…

> very, very niche audience

The homeless are certainly not a niche audience. There might be between 13 and 26 million people in the US alone who have experienced homelessness at some point in their lives [0].

Besides, issues around permanent access to security devices are not exclusive to the homeless. The problem described in TFA impacts a far larger segment of society.

Critical services are increasingly only available online -- and online services are increasingly critical. The people governing access to critical services are willfully ignorant to the difficulties that vulnerable people face, and often make those difficulties worse.

[0] https://www.ncbi.nlm.nih.gov/books/NBK519593/

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#729
> unhoused people face extreme challenges when it comes to retaining physical items.

Reminds me of a case in Moscow (iirc): a homeless guy bought a gym pass that came with a locker, and was storing his things in said locker. The gym administration decided to deny him this arrangement, but he sued them and the court said “since the locker is in the contract, it's his privilege now”.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#730
post #662

Earlier quoted context omitted.

How many passwords does an homeless person need to remember ? I’m with you that an average person is probably using at least dozens of services that need credentials, but these people are probably not login on Amazon or checking their 401k online for instance, nd can probably get by with a a very limited set of stuff to remember.

If they're relying on government social services, they may well have a whole plethora of accounts to manage that.

You really only need one very secure password (to your Gmail account) and you can store all the others there.
Post reply on HN