Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

91–100 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#91

I agree there should be more explicit support here, but can this not be "solved" with backup codes? One or more could be given to a trusted person – a family member, a friend, or even a trusted librarian – or a backup code could be remembered. The tough issue here is that these access edge cases look a lot like malicious use. The aren't but authenticating someone who has no device or ID or really much else to authent…

This is potentially a solution for some but it’s not perfect. If they had a trusted friend or family member who could store backup codes and deliver them as needed, they could probably also just stay logged in on that person’s phone or even have emails sent you that person. Keep in mind that they have limited transportation and likely lose their contacts when they lose their phones, and many will have strained relationships with the housed people in their lives.

A library solution may not scale. Sure, a librarian might develop a personal relationship and do this as a favor for someone. But the author mentions talking to about 30 people with this problem in his neighborhood, which suggests that if word got out a librarian was doing this and they tried to institutionalize it, a library might have to store codes for dozens or hundreds of people it has no way to authenticate.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#92

Earlier quoted context omitted.

"Not-my-problem" is a bad response, but the actual response is that without 2FA even more people lose access to their accounts. Anything that makes it harder for adversaries to take over an account almost necessarily adds friction for the users themselves. This isn't a "fuck the people who don't have regular access to a phone, they don't matter" situation. It is a "there is an aggravating balancing act in this situat…

> but the actual response is that without 2FA even more people lose access to their accounts This is not black and white. It is possible to encourage 2FA but allow to opt out. The same for phone numbers. And that's why companies enforce 2FA: they want your juicy phone-number or other data. And yeah, maybe they also want to reduce support costs and avoid bad publicity. Still, it's not in your interest, it's in theirs.…

> And that's why companies enforce 2FA: they want your juicy phone-number or other data.

It is possible. And, as far as understand it, the teams at Google in charge of this have evaluated this option and found that it leads to more lost accounts.

The people responsible for user authentication at Google are in a completely different part of the company as advertising and, in my experience, are especially stubborn about their focus on security. "This is about phone numbers" doesn't make sense to me given my personal experience.

> If they at least would allow for a sufficient number of options. Like paper-tan (even self printed), yubikey or similar, second email address, an authenticator, ... but even big companies often only require a phone number.

We are talking about Google specifically here, which offers all of these options.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#93

This problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint…

Right now, technology has reached a point where it's expected to be ubiquitous, however is not as accessible as other ubiquitous and necessary services. This has been brought up before, buy can someone in their 70s keep up with the changing UIs and websites and security requirements these days? This is all fine for something like Netflix or Spotify. But for government services, access to jobs, and fundamental communications this poses a problem.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#94

Earlier quoted context omitted.

> but the actual response is that without 2FA even more people lose access to their accounts This is not black and white. It is possible to encourage 2FA but allow to opt out. The same for phone numbers. And that's why companies enforce 2FA: they want your juicy phone-number or other data. And yeah, maybe they also want to reduce support costs and avoid bad publicity. Still, it's not in your interest, it's in theirs.…

> Still, it's not in your interest, it's in theirs. Which is okay, because it is a business. If society wants homeless people to have reliable access to email without having SMS 2FA or whatever requirements a business requires, then society should elect a government to provide it as a utility. There is no reason to expect or want businesses to pick up the slack for the government not providing adequate safety nets. L…

I think this is a better answer than it first appears.

Initiatives at for profit corporations will always exist within some business constraints, shareholder obligations, and so forth.

It would be very reasonable for governments to provide tax-supported digital services. I could easily imagine that spending a few dollars per year to provide the homeless with basic digital services would pay off simply in easing administrative overhead.

But we don't do it, because, in America, our sense of what government can or should provide is atrophied, and we, mistakenly, look to private actors to provide basic public services.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#95
post #82

Earlier quoted context omitted.

> but the actual response is that without 2FA even more people lose access to their accounts This is not black and white. It is possible to encourage 2FA but allow to opt out. The same for phone numbers. And that's why companies enforce 2FA: they want your juicy phone-number or other data. And yeah, maybe they also want to reduce support costs and avoid bad publicity. Still, it's not in your interest, it's in theirs.…

> If they at least would allow for a sufficient number of options. Like paper-tan (even self printed), yubikey or similar, second email address, an authenticator, ... but even big companies often only require a phone number. Google seems to support all of those?

Did you recently try to create a gmail account? If not, I suggest you try it right now. Maybe you will be surprised.

Hint: it is still possible to create a gmail account without phone number, but it has become quite tricky to do so.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#96
post #28
post #2

Google has a lot of issues, but the gist of these twitter posts, is that homeless people lose their phones multiple times a year, and their phone number, and this makes 2fa hard. But, I mean, why are they not railing on the phone companies, to make it easy for the homeless to keep the same phone number?! Why is this Google's fault?

It really is every company's fault that jumps on this absurd trend of seeing SMS-2FA as the be-all and end-all of user identification and verification. Google is actually doing much better than the competition here in many aspects (e.g. it is possible to operate a Google account completely without a phone number for 2FA or account recovery), but as far as I understand, one is still required to initially create an acc…

> it is possible to operate a Google account completely without a phone number

This is only true for a limited time. I've tried to use a couple Google accounts this way and inevitably I log in from a new IP and Google's 2FA system kicks in - forcing me to either furnish a phone number or lose access to the account.

It's similar to how Twitter forces phone numbers out of people - just not as immediate.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#97

Earlier quoted context omitted.

My dad helps people navigate the system to find housing. Recent story was a 65yo + veteran living in a shelter. They hadn’t started collecting social security due to some debts and was worried it would ALL be garnished. After explaining that veterans get expedited in line for housing and that they would still get almost all of their SS, they have applied for it and should be housed soon. It doesn’t surprise me at all…

> They hadn’t started collecting social security due to some debts and was worried it would ALL be garnished. Is this common? I knew a guy who had the same mindset. I ended up paying him in cash for some work, he was convinced that if he made any money in a traditional role it would be instantly garnished.

> They hadn’t started collecting social security due to some debts and was worried it would ALL be garnished.

Your contractor’s actions makes a some twisted sense to me as he’s still receiving ‘undisclosed’ cash. The homeless veteran doesn’t make any sense to me as he was not receiving the social security funds at all.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#99

Earlier quoted context omitted.

There are various approaches to 2FA, from backup codes, to SMS, to external physical keys - none of them workable for the specific use-case OP defined: person is homeless and losses their stuff every few weeks. For that situation no 2FA solution is going to work.

Of course there is. For instance a printed paper tan list. Yes, this is not as safe a proper 2FA device. But it's easy to access, cheap (just go to a copyshop and 10 cents to print it, then put in a plastic bag) and it's so small that it's easy to put it somewhere where you don't lose it and is hard to get stolen.

You're not arguing with me, you're arguing with the author of the twitter thread.

"Any solution requiring long-term retention of a physical 2FA key or high-entropy secret will not work."

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#100

Earlier quoted context omitted.

"Not-my-problem" is a bad response, but the actual response is that without 2FA even more people lose access to their accounts. Anything that makes it harder for adversaries to take over an account almost necessarily adds friction for the users themselves. This isn't a "fuck the people who don't have regular access to a phone, they don't matter" situation. It is a "there is an aggravating balancing act in this situat…

I wonder how many people suffer identity theft versus how many have a working recovery email but are denied to use it because some algo finds it suspicious that you moved country or logged in from a linux machine? The key takeaway is not about how we should promote 2FA or how we should promote long ass passwords, the main issue at hand is google's neglectful lack of customer support. I was once caught in this non-sen…

> the main issue at hand is google's neglectful lack of customer support.

Customer support is the main entrypoint into 99% of sim swapping attacks and would be similarly for any targeted account takeovers. What sort of information do you possibly think would be enough to prove someone actually owns a Google account over the phone?

Post reply on HN