Live data from Hacker News

Gmail 2FA causes the homeless to permanently lose access 3 times a year

twitter.com

1–10 of 770 posts

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#2
Google has a lot of issues, but the gist of these twitter posts, is that homeless people lose their phones multiple times a year, and their phone number, and this makes 2fa hard.

But, I mean, why are they not railing on the phone companies, to make it easy for the homeless to keep the same phone number?!

Why is this Google's fault?

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#3
I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail?

I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system has probably prevented identify theft and financial loss for a very large number of people. I'm saying this as someone who thinks Google is a shady and dangerous entity in general.

It's similar to the idea that hard cases make bad law.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#4
post #2

Google has a lot of issues, but the gist of these twitter posts, is that homeless people lose their phones multiple times a year, and their phone number, and this makes 2fa hard. But, I mean, why are they not railing on the phone companies, to make it easy for the homeless to keep the same phone number?! Why is this Google's fault?

This is not just the homeless, there was a post on HN from a librarian talking about the same issues for the elderly and socially disadvantaged. The issue is that Google forces 2FA on them, even if they otherwise don’t have a phone.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#5
post #3

I can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system h…

> because a very, very niche audience is in dire straits

Not very niche.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#6
I agree there should be more explicit support here, but can this not be "solved" with backup codes? One or more could be given to a trusted person – a family member, a friend, or even a trusted librarian – or a backup code could be remembered.

The tough issue here is that these access edge cases look a lot like malicious use. The aren't but authenticating someone who has no device or ID or really much else to authenticate themselves is a Hard Problem. Passwords also aren't the solution here, the industry is moving away from them precisely because they provide poor authentication, particularly for vulnerable people.

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#8
In one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution.

Also, fully acknowledging Google and other bigtechs 2FA is far from ideal:

The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile dissidents, journalists, and senators who will inevitably have accounts; and at the same time to homeless people who can't keep any physical thing. It's kinda difficult to meet those conflicting requirements well at the same time.

Maybe the solution should be to have some basic free state-paid email provider for those people. They are not forced to use Gmail specifically (albeit the number of non-sucking and free email providers is probably close to zero).

Re: Gmail 2FA causes the homeless to permanently lose access 3 times a year

#9
post #4
post #2

Google has a lot of issues, but the gist of these twitter posts, is that homeless people lose their phones multiple times a year, and their phone number, and this makes 2fa hard. But, I mean, why are they not railing on the phone companies, to make it easy for the homeless to keep the same phone number?! Why is this Google's fault?

This is not just the homeless, there was a post on HN from a librarian talking about the same issues for the elderly and socially disadvantaged. The issue is that Google forces 2FA on them, even if they otherwise don’t have a phone.

Yep,that's what I thought of as well. Discussion from two months ago:

https://news.ycombinator.com/item?id=32304320

Post reply on HN