Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

731–740 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#731
post #498

Earlier quoted context omitted.

That's almost exactly what Google has done. Here's how you turn off 2FA on your account: 1. Go to myaccount.google.com 2. Press "Security" 3. Press "2 step verification" 4. Enter your password 5. Press "Turn off" 6. Confirm the dialog that says "Turning off 2-Step Verification will remove the extra security on your account, and you’ll only use your password to sign in."

Those steps don’t actually turn off 2FA for Google accounts. If you login from a new computer or unrecognized IP, Google forces you to use the YouTube app on your phone to enter a “code” to login. It sometimes doesn’t even let you get a text code. God forbid I lose my phone or delete the YouTube app and login from a new IP. I don’t know how I would even get into my account. I don’t know how this isn’t a wider spread…

Yup. I had 2-factor turned off and tried to login to an old gmail account from maybe 5 years prior.

I had the right password and recovery email but I wanted to txt a code to a phone number I didn’t have any more.

That seems insane to me. Right password, access to “recovery email” and still blocked.

What ended up working for me was trying to login when I took a vacation back to the same city when I last logged in.

Didn’t get asked for the OTP code, so could get in and update the number.

I wouldn’t have such an issue if Google had customer support and let you send other proof of identity. But they don’t.

And now I’m getting weird requests to confirm I logged in from the YouTube app on other devices. YouTube?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#732

As someone who uses 2FA extensively and even has 1Password autofill the OTP codes - 2FA is objectively fucking brutal. Half of you in here have never met a non-technical user. These folks should not have 2FA on ever, because they can't even use the damn thing with it on. Yes, those users run a higher risk and should be notified of that extremely clearly. But 2FA is a garbage solution to the problem and it should alwa…

Oh please. Every business I’ve ever worked for has enforced MFA for corporate access. You’re acting as if “non technical users” are illiterate subhuman morons. Even my 90 year old grandparents trivially figured it out on their own.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#733
post #3

I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system h…

> very, very niche audience The homeless are certainly not a niche audience. There might be between 13 and 26 million people in the US alone who have experienced homelessness at some point in their lives [0]. Besides, issues around permanent access to security devices are not exclusive to the homeless. The problem described in TFA impacts a far larger segment of society. Critical services are increasingly only availa…

That headline number is garbage. It’s 550,000 people at any given time.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#734

Earlier quoted context omitted.

How about an option for in person account recovery provided by a government official?

Only works if you live in a major city. Sounds like the DMV but 10 times worse.

USPS? Used as an alternative. Not ideal but better than nothing.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#735
post #570

Earlier quoted context omitted.

I just buy new $90 mint prepaid sims for cash. They work for three months. I have never talked to a CSR.

That sounds like the dream. What do you do for 2FA stuff that requires a consistent number?

Most of those I simply make new accounts after 90 days, or I don’t use those services.

For some things I have a Google Voice number, the Google account for which uses Advanced Protection (hardware 2fa only).

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#737

As someone who uses 2FA extensively and even has 1Password autofill the OTP codes - 2FA is objectively fucking brutal. Half of you in here have never met a non-technical user. These folks should not have 2FA on ever, because they can't even use the damn thing with it on. Yes, those users run a higher risk and should be notified of that extremely clearly. But 2FA is a garbage solution to the problem and it should alwa…

Oh please. Every business I’ve ever worked for has enforced MFA for corporate access. You’re acting as if “non technical users” are illiterate subhuman morons. Even my 90 year old grandparents trivially figured it out on their own.

I'm claiming the reverse - the human ones are the normal people who just want to use email without it berating them every time they log in.

Then your grandparents are technical users. Curiously, so are mine. Sorry to tell you that you're wrong though and you have not met the non-technical users.

I've had to try to help my aunt and uncle recover old Apple and Google accounts with complete failure because they've changed cell phone providers and didn't care that their phone numbers changed. At no point are they adequately warned this is the case, and recovery codes are a confusing additional layer that they don't understand.

So they basically lose everything and nobody is willing to help them. You are making a grand assumption about accessibility - not everyone has the capability to grok such a convoluted login process. The non-technical users often aren't morons - they are just differently abled. Maybe they are immigrants who didn't grow up with computers much because they were poor, or have a mental condition.

2FA fails spectacularly on accessibility.

Your reply is an example of the problem - completely oblivious to the users that are horribly underserved by 2FA as it exists.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#739

As someone who uses 2FA extensively and even has 1Password autofill the OTP codes - 2FA is objectively fucking brutal. Half of you in here have never met a non-technical user. These folks should not have 2FA on ever, because they can't even use the damn thing with it on. Yes, those users run a higher risk and should be notified of that extremely clearly. But 2FA is a garbage solution to the problem and it should alwa…

Oh please. Every business I’ve ever worked for has enforced MFA for corporate access. You’re acting as if “non technical users” are illiterate subhuman morons. Even my 90 year old grandparents trivially figured it out on their own.

there are as many meanings of "technical" as there are crafts[0], a corporate job likely include many hours each day working at a computer where you will encounter a lot of the various UX patterns that anyone else would encounter.

You do not need to be a programmer or work in IT to know how to use a computer effectively.

On the other hand there are people that do not use computers nor smartphone features that aren't also offered in feature phones.

[0] https://www.etymonline.com/word/technical#etymonline_v_7660

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#740

Why not make 2FA opt-out? This would work for most cases or am I missing something?

No you are not missing anything in my opinion.

The reason this is not offered (IMHO) is that a lot the use (on the users side) of 2FA is from people that want better security, while a lot of the push (on the developer side) for 2FA is from people that would like to see the use of passwords almost disappear.

Post reply on HN