Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

81–90 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#81
I have lost access to Tinder and Transferwise because I moved between the UK and Australia and thus changed my phone number. Whatsapp also silently fails to send me private messages now, even after I went thru their official inbuilt 'I changed my number' process - only my group chats work now. The messages appear to send to the sender, they don't even know I didn't receive them.

One of the worst examples I've heard is that Overwatch 2 not only requires a phone number, but they actually check with your carrier if it's a prepaid number, and if it is, you're banned. Sorry poor people, Blizzard doesn't want scum like you playing their game.

Assuming someone's phone number never changes, or that they'll have access to their old and new numbers at the same time, is simply wrong and does not work.

I haven't been locked out of Google yet, somehow, but maybe it's just a matter of time.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#82

Earlier quoted context omitted.

"Not-my-problem" is a bad response, but the actual response is that without 2FA even more people lose access to their accounts. Anything that makes it harder for adversaries to take over an account almost necessarily adds friction for the users themselves. This isn't a "fuck the people who don't have regular access to a phone, they don't matter" situation. It is a "there is an aggravating balancing act in this situat…

> but the actual response is that without 2FA even more people lose access to their accounts This is not black and white. It is possible to encourage 2FA but allow to opt out. The same for phone numbers. And that's why companies enforce 2FA: they want your juicy phone-number or other data. And yeah, maybe they also want to reduce support costs and avoid bad publicity. Still, it's not in your interest, it's in theirs.…

> If they at least would allow for a sufficient number of options. Like paper-tan (even self printed), yubikey or similar, second email address, an authenticator, ... but even big companies often only require a phone number.

Google seems to support all of those?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#84
post #8

In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile di…

> ... the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. How about the homeless person remembers a good password, and that's all that's needed for authentication? You know, just like it used to be. What exactly is wrong with that?

A good password is one that is difficult to crack which potentially means it will be difficult to remember. Long phrase passwords are recommended to be the most secure, but ironically the more convoluted the password, the harder it is to remember. In the case that a service requires a new password every x months, remembering a secure password is out the window. This type of practice encourages unsafe and easily guessable passwords such as “password1”, “password2”, etc…

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#85

This is yet another example of the "accessibility, privacy, fraud-protection, choose any two" problem. You can force people to use 2FA, but then you discriminate against people who can't. You can build an account recovery flow that requires government-issued proof of ID, but then you sacrifice privacy. You can do neither, but then you make accounts easier to compromise and harder to recover. There's no good solution…

Maybe each individual should be allowed to "choose the two" that work best for them.

Most of us have at least one email account that's already under our real name, where we have no big interest in hiding our real identity, but we do have a big interest in not being randomly shut down by Google. We hear about such shutdowns every few weeks on HN, if not more.

Google has unfathomable financial and technical resources, much of which goes to projects of speculative value at best. I can't help but feel that they could provide a slightly more customized login experience to help diverse people with diverse needs.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#86

Won't using e.g. Authy with Gmail for 2FA alleviate the need for a phone number after the initial setup (i.e. requiring a number only once, to initially enable 2FA)? https://authy.com/guides/googleandgmail/

There are various approaches to 2FA, from backup codes, to SMS, to external physical keys - none of them workable for the specific use-case OP defined: person is homeless and losses their stuff every few weeks. For that situation no 2FA solution is going to work.

Of course there is. For instance a printed paper tan list. Yes, this is not as safe a proper 2FA device. But it's easy to access, cheap (just go to a copyshop and 10 cents to print it, then put in a plastic bag) and it's so small that it's easy to put it somewhere where you don't lose it and is hard to get stolen.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#87
post #79

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

Quoted post unavailable.

2FA is not only SMS 2FA.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#88

I don't think access to email is the biggest concern the homeless have. It sucks, but there are alternatives besides gmail and if google is going to spend time on this, I'd rather they not and instead spend time on getting homeless into homes.

What about when you want to apply to a job or an apartment which requires email?

I would expect it to require a phone number and physical address before an email.

I also wonder if this person on twitter would be willing to let his friends use his email or phone.

The homeless have challenges, no doubt, but that does not imply google worrying about 2FA for the homeless is the best way to solve those challenges. It wouldn't even BE an issue if they weren't homeless in the first place, for example.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#89
post #51

Earlier quoted context omitted.

No, people like you really highlight the “If they don’t help everyone then they are being immoral” mentality. Which is wrong. Down grading security for the benefit of a tiny minority with an especially ridiculous use case is not the greater good. If the homeless people think they are at risk of losing their phone then they should pick another free email vendor.

This is a simplification of the problem. Both: 1. Vulnerable populations need more assistance accessing essential services required to participate in society 2. Service providers need to maintain a reasonable level of security for their customers Can both be true. Saying that maximum (or minimum) levels of security are required at all time completely misses the point of security--which is to mitigate risk. How much r…

> there is reasonable debate to be had on how to best provide access to essential services to vulnerable populations.

What is the debate? The government can collect taxes and provide services, like they do for multitude of other needs.

> I'm not sure what a correct answer here looks like, but I don't think ignoring the need is an approach that gets us to a better society or enables vulnerable populations to better care for themselves.

The correct answer is not depending on the largesse of businesses. It is using government resources to provide methods for identity verification, communications, and various other bare minimum needs for living.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#90
post #3

I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system h…

There are over half a million homeless people in the USA right now. And only a quarter are "chronically homeless", meaning for ober a year or more than once. There are many, many people who will be homeless for a few months at some point during their lives.
Post reply on HN