Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

741–750 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#741
post #479
post #294

Earlier quoted context omitted.

I can make a very specific case for it. Out of 1.5+ billion users, millions of which are barely tech-literate and vulnerable, with gmail a constant target for malicious entities. That means intuitively at least hundreds of thousands of vulnerable people getting cleaned out of their life savings. Changing things for billions in exchange for a marginal benefit to thousands is bizarre. It's not a 'gish gallop' but a fra…

So you don't want Google to do anything or what is the purpose of all this verbiage? Which moreover, unjustly dismisses whole issue as "marginal benefit to thousands". Being able to keep/recover email address is so much more than a marginal benefit, and there are many more than thousands of homeless in the US alone.

Maybe Google can do something. Just it probably shouldn't be something that alters security measures for billions.

I'm not dismissing the whole issue, just that it was presented in a way that's not actually conducive to helping the homeless.

If you remove forced 2FA, you would be dismissing the hundreds of thousands (at minimum) of tech illiterate people out of the 1.5 billion users who would get cleaned out in the coming weeks. Why do their lives not factor into your calculus? Are they not vulnerable too? All of this for a measure that could be resolved in so many other ways.

This is the problem I'm trying to illustrate. This sort of moral appeal helps no one, and in fact endangers other populations. If the goal truly were to help people, no one would EVER suggest an alteration that would expose billions for the benefit of thousands.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#744
post #714

Earlier quoted context omitted.

I've been on municipal Broadband and it was fine. I ended up moving to a private provider because it was better and cheaper. When it comes to the right trade-off for the housed and the unhoused in terms of email service, I'm skeptical that the solution is regulatory. It seems like there is a large number of email providers that already offer what the homeless need. The problem is simply setting them up with the corre…

Sure. I was also saying the solution is not regulatory. But, look at that: the federal government already provides the homeless with cell phones. Yet instead of arguing that the government should also provide free email—which of course costs far less than cell service—the poster argues that existing commercial services should better serve the homeless. Which, of course, would be nice! But my point was that this kind…

I see, I think I read in haste and missed your position on regulating tech into somehow solving the problem.

It seems like we basically agree.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#745

Earlier quoted context omitted.

Oh please. Every business I’ve ever worked for has enforced MFA for corporate access. You’re acting as if “non technical users” are illiterate subhuman morons. Even my 90 year old grandparents trivially figured it out on their own.

I'm claiming the reverse - the human ones are the normal people who just want to use email without it berating them every time they log in. Then your grandparents are technical users. Curiously, so are mine. Sorry to tell you that you're wrong though and you have not met the non-technical users. I've had to try to help my aunt and uncle recover old Apple and Google accounts with complete failure because they've chang…

If your argument relies on classifying the elderly and virtually every corporate employee as technical users perhaps you should rethink your argument.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#746

Earlier quoted context omitted.

Except if you're using e.g. Google Authenticator and you lose that phone, you've now lost your TOTPs. The most unhoused-friendly solution there would be to use something like Authy instead (which is another password to remember, but at least it makes it easy to recover your TOTP keys on a new device without needing the old one); next best would be to use something like andOTP which supports backups (but then you'd ne…

The context for this post is a person who moves between countries frequently and therefore gets new phone numbers. This person has consistent access to the same phone.

The context of the overall post is the posted Twitter thread, wherein the specific issue is the phone itself being lost/stolen.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#747

Earlier quoted context omitted.

I'm claiming the reverse - the human ones are the normal people who just want to use email without it berating them every time they log in. Then your grandparents are technical users. Curiously, so are mine. Sorry to tell you that you're wrong though and you have not met the non-technical users. I've had to try to help my aunt and uncle recover old Apple and Google accounts with complete failure because they've chang…

If your argument relies on classifying the elderly and virtually every corporate employee as technical users perhaps you should rethink your argument.

You're reading what you want to read because your position has no strong foundation. At no point has a specific age or employee class been a cornerstone of the argument. You can simply wait for the day that you are screwed by bad 2FA and then it will be obvious how stupid it is. A mistake can happen to anyone - even the people that know what they're doing.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#748

Earlier quoted context omitted.

If your argument relies on classifying the elderly and virtually every corporate employee as technical users perhaps you should rethink your argument.

You're reading what you want to read because your position has no strong foundation. At no point has a specific age or employee class been a cornerstone of the argument. You can simply wait for the day that you are screwed by bad 2FA and then it will be obvious how stupid it is. A mistake can happen to anyone - even the people that know what they're doing.

[deleted]

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#749
post #701

Earlier quoted context omitted.

Then don’t use Google for email. There are plenty of other free email providers that do not employ that much security. Problem solved

My problem isn’t that gmail is too secure, it’s that the 2FA setting doesn’t actually turn off what it’s supposed to turn off. Not sure if this is a bug or intended behavior.

Just use another email provider. There are many other free ones and reasonably priced paid services. The paid services tend to better listen to their users since they’re the real customers

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#750

As someone who uses 2FA extensively and even has 1Password autofill the OTP codes - 2FA is objectively fucking brutal. Half of you in here have never met a non-technical user. These folks should not have 2FA on ever, because they can't even use the damn thing with it on. Yes, those users run a higher risk and should be notified of that extremely clearly. But 2FA is a garbage solution to the problem and it should alwa…

You are quite right. I have never owned a smart phone myself and never carry any type of phone with me. When I change countries, I try to use shitty pre-paid dumb phones. I was completely unaware that online services seem to hate this, and will lock you out forever if you change your phone number (or change countries - something that has gotten worse, I have noticed, as I have been crossing borders and logging into things for 20 years). It used to be easy. Now it's a nightmare.

I find it disturbing to imagine that people are stuck with phone numbers as de facto ID.

Post reply on HN