Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

761–770 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#761

Earlier quoted context omitted.

That headline number is garbage. It’s 550,000 people at any given time.

It's certainly not garbage, read it again: people who have "experienced homelessness at some point in their lives".

Yes and that “experienced homelessness” figure includes people who moved in with friends, family, or relatives. The headline number is garbage.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#762

Earlier quoted context omitted.

What‘s your speciality in programming? Keeping all your software, and that includes the OS, up to date, is one of the most important aspects of personal security.

I also don’t have a WiFi password at home, if it matters. Of course, I don’t have Internet banking nor do I do much (if at all) money-related things with my phone, something tells me that makes me more secure than people who trust Apple and Google with their money (at least the local banks have to answer to the authorities). What’s your employment specialty that makes you trust Apple and Google?

Having a Wifi password is honestly pretty important unless you're remote enough that there's just no chance someone can access your network. Remember, unencrypted WiFi doesn't just mean that someone can access your network, but also that they can collect your traffic.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#763

Earlier quoted context omitted.

Why does email need to be a regulaty utility when there are other methods of communication?

Great question! The long version (if it’s patronising please skim forward, I’m writing as an explainer for anyone else that comes along): E-mail was originally a means to communicate informally between two participants over the Internet. In this early version of the system the message would leave your machine, go to your Mail server, then the recipients mail server, then their inbox. This would complete the transmiss…

My mailing address and phone could also be key factors in my life related to identification but there is little regulation there.

"If one day you lose access to the account (in that you insert your password and the provider says no), you will lose access to your entire e-mail history"

This comes down to personal responsibility assuming you lost the password or even if it's the companies fault you should prepare for thus.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#764

Earlier quoted context omitted.

> we need ideas like to 2FA to gain traction as widely as possible No, 2FA needs to die in a fire. Easily circumvented in most social attacks that actually matter, false sense of security, massive timewaster/usability-hell/pain in the butt, acts as a novel social/corporate/accessibility barrier to technology for a large number of previously unaffected groups, and poses a threat to software freedoms. There are many wa…

What are the other ways?

Get rid of software that doesn't have to be an online service, for one. This cuts 90% of incidents.

Then, all the "common sense" stuff: encourage use of password managers to discourage password re-use, having actual humans providing actual customer support when suspicious activity is flagged, companies educating about safe practices like banks do now (e.g. always call back to a trusted number), spam prevention at the ISP level, SSO authentication, VPN ...

At the very least there must be better ways to do two-factor authentication than what is the standard default.

And to top it all off, on many services, if you cant get all that to work, all you need is your "memorable word". *facepalm*

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#765

Earlier quoted context omitted.

> I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? Almost every free email service I've tried now requires a phone number to setup. Even protonmail required it for a brief while, although they now are back to captch…

Fastmail doesn't require a phone number for 2FA.

It doesn't seem like fastmail is free, just a free trial.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#766

Earlier quoted context omitted.

It's certainly not garbage, read it again: people who have "experienced homelessness at some point in their lives".

Yes and that “experienced homelessness” figure includes people who moved in with friends, family, or relatives. The headline number is garbage.

If I was homeless I'd certainly try to move in with friends or relatives.

Not garbage :)

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#767
post #741
post #479

Earlier quoted context omitted.

So you don't want Google to do anything or what is the purpose of all this verbiage? Which moreover, unjustly dismisses whole issue as "marginal benefit to thousands". Being able to keep/recover email address is so much more than a marginal benefit, and there are many more than thousands of homeless in the US alone.

Maybe Google can do something. Just it probably shouldn't be something that alters security measures for billions. I'm not dismissing the whole issue, just that it was presented in a way that's not actually conducive to helping the homeless. If you remove forced 2FA, you would be dismissing the hundreds of thousands (at minimum) of tech illiterate people out of the 1.5 billion users who would get cleaned out in the c…

You really expect people caring for homeless to come with some ready made technically feasible solution? Of course they will do moral appeals and suggest potentially dangerous solutions first. That happens all the time! Getting a response "that aint gonna work get away" isn't appropriate here. Dialogue is, and for that we must listen a bit.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#768

Earlier quoted context omitted.

Google only allows non-U2F 2FA methods (like TOTP) to be enabled AFTER enabling a hardware U2F device. And signing up without a working mobile number is impossible. Anyone who says that's not true hasn't actually tried in the last several years.

I definitely had TOTP before I had U2F. I think you mean after enabling SMS 2FA, not U2F.

Nope, while I also did have TOTP before U2F (because it wasn't even a thing then), the rules changed to where if you don't have a phone number on your account, then you're required to enroll a U2F device before you can turn on TOTP.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#769
post #312

Earlier quoted context omitted.

> Practically, we need ideas like to 2FA to gain tractionas widely as possible, while realising that isn't everywhere. thats just one opinion on security. you see this world where google is an identity provider, and you prove your identity to it via a librarian or bank. i dont. an internet service should absolutely never require any form of government id nor separate network like cell.

You're failing to read my argument: for some people normal 2FA is too hard, and they need help from a local organisation. But not for ALL people. Just for the people who need it. You keep using TOTP and GPG email all you want, just don't get in the way of them getting basic services like social security.

you just backed off and said that the thing i responded to is an auxiliary point then your last sentence just retakes the position you backed off from by reclaiming that the auxillery point is true

shut the fuck up. of course someone named octect is the most braindamaged fuck on earth.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#770
post #224
post #90

Earlier quoted context omitted.

There are over half a million homeless people in the USA right now. And only a quarter are "chronically homeless", meaning for ober a year or more than once. There are many, many people who will be homeless for a few months at some point during their lives.

There are 1.5+ billion gmail users. I don't have stats, but that intuitively means millions of vulnerable people who could be scammed or phished or whatnot because they would never think of using 2FA at all. Among those half a million homeless, how many use gmail and are unable to change for whatever reason? Among those, how many have issues with 2FA? Thus we advocate for increasing the vulnerability of millions to d…

What a viewpoint.

The number of gmail users in the USA is obviously significantly lower, and the number of homeless or people in similar situations globally is obviously significantly higher.

Post reply on HN