Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

751–760 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#751
post #15
post #3

I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system h…

The phone number decision is stupid. I up and jump countries every few years. Each time, I'm switching to a new number. I'm the opposite of homeless, I'm that jet set elite. The idea that you want, need, should or will tie your identity to a phone number where people can always reach you is long outdated.

Absolutely true. I am a serial expat who has lost numerous numbers over the years by switching countries. I at least hope to keep the same basic online services running when crossing borders, but I swear, in the last couple of years, it has become an absolute nightmare. It is getting harder and harder.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#752

Earlier quoted context omitted.

> very, very niche audience The homeless are certainly not a niche audience. There might be between 13 and 26 million people in the US alone who have experienced homelessness at some point in their lives [0]. Besides, issues around permanent access to security devices are not exclusive to the homeless. The problem described in TFA impacts a far larger segment of society. Critical services are increasingly only availa…

That headline number is garbage. It’s 550,000 people at any given time.

It's certainly not garbage, read it again: people who have "experienced homelessness at some point in their lives".

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#753
post #627

Earlier quoted context omitted.

> Are we OK with Google just shutting off accounts in that scenario? Are we prepared to accept that the members of our community experiencing being unhoused will find themselves constantly creating new accounts as their old ones are shut off or rendered unusual from the consequences of purposely-low-security-for-the-vulnerable? I am, yes, if the alternative is that they loose access to their account every few months!…

> I am, yes, if the alternative is that they loose access to their account every few months! Good to hear, though I confess to a bit of confusion. The issue I pointed to is that they're going to lose access to their accounts frequently as their accounts get breached, abused, and shut off. As opposed to losing access because they lost their phone number. > Also, at least this way people have the ability to keep their…

I don't think people's accounts are getting hacked anywhere near three times per year. And while remembering passwords is a problem, surely it's easier than remembering a password and keeping track of a second factor device?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#754

Earlier quoted context omitted.

I don't think it was the local homeowners stealing live copper from the walls.

Where do you suspect that homeless are storing their caches of copper? Do you think they're carrying them around with them at all times?

Oh they sell it as soon as they can (copper is easy to recycle and carries direct value) and then use the money for whatever.

The risk of course is that you are ripping potentially live circuits out of a building. It usually requires you to already be impaired and desperate to do it. It's that fun combo of illegal and dangerous.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#755
post #662

Earlier quoted context omitted.

If they're relying on government social services, they may well have a whole plethora of accounts to manage that.

I don't know how dire it is in general, but there's at least a fighting chance to have some kind of unified login at that level. NThinking about it, now that many "casual" sites also accept google login the number of accounts needed might really be minimal.

Unfortunately (at least in the US) these types of services tend to be a patchwork of different agencies at different levels of government... you'll potentially see local, regional, state, and federal all for one person. If you're lucky agencies at the same level might share a unified login of some sort, but good luck finding that across different levels.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#756
post #655

Earlier quoted context omitted.

It's routine in disaster relief situations that people lose all their documents but then governments step in and allow identity verification via vouching: this other person Alice says you're Bob. Then Bob gets his photo on a temporary ID document and gets a DR payment. Social workers, shelters, libraries etc are well placed to support that. They know these people because they see them every day. If you choose to enro…

This feels ever-increasingly like asking Google to cover the role of a government agency. Universal service is something we expect of government agencies. It's rarely something we expect of private enterprise. The whole "community recovery" concept sets my teeth on edge. It's a whole alternative authentication avenue ripe for exploitation. Anything that positive and innocuous sounding is going to be the target of man…

You could easily limit this program to people using Lifeline phones, or enrolled with a geolocated homeless support organisation. The vouching agents can't be high value targets if they're protecting the identity of impoverished people.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#757
post #627

Earlier quoted context omitted.

> I am, yes, if the alternative is that they loose access to their account every few months! Good to hear, though I confess to a bit of confusion. The issue I pointed to is that they're going to lose access to their accounts frequently as their accounts get breached, abused, and shut off. As opposed to losing access because they lost their phone number. > Also, at least this way people have the ability to keep their…

I don't think people's accounts are getting hacked anywhere near three times per year. And while remembering passwords is a problem, surely it's easier than remembering a password and keeping track of a second factor device?

You're right, people's accounts aren't getting hacked that often. This is because of a wide array of security measures - the ones you're suggesting be disabled. The frequency of breaches goes up significantly without those in place, especially when coupled with the kind of weak password likely to be chosen by struggling, marginalized, vulnerable people whose priority is not keeping bots at bay.

In short - yes, but the consequences defeat the point.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#758
post #593

Earlier quoted context omitted.

It's just a notification , it can be ignored (for me). I don't usually even notice its there until hours later. You don't have to acknowledge it in any way. It also has nothing to do with the YouTube app, and there is no code I have to enter anywhere. I've never had any form of 2FA on my Google account.

You may have never experienced it, but it does happen. Not just a notification.

I never said it doesn't happen?? I literally even specified "(for me)."

I believe you, I'm extremely surprised I didn't see this considering I've logged in from all sorts of sketchy IPs/VPNs.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#760

Earlier quoted context omitted.

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

That's literally how it was before 2FA. You can just look up the reasons for 2FA to answer your question.

So you are saying that the homeless using plain passwords is wrong because tech giants want to collect personally identifying information under the guise of security? How does that make sense?
Post reply on HN