41 ms·
Gmail 2FA causes the homeless to permanently lose access 3 times a year
- shadowgovt 4y agoYep. Recent changes to Gmail security make Gmail a bad fit for the homeless. What are the best available alternatives?
- punkhodler 4y agowhy don't they use applications that do not require a phone number and have free backup options? I.e. 2fas.com and many many others?
- b112 4y agoGoogle has a lot of issues, but the gist of these twitter posts, is that homeless people lose their phones multiple times a year, and their phone number, and this makes 2fa hard. But, I mean, why are they not railing on the phone companies, to make it easy for the homeless to keep the same phone number?! Why is this Google's fault?
- Semaphor 4y agoThis is not just the homeless, there was a post on HN from a librarian talking about the same issues for the elderly and socially disadvantaged. The issue is that Google forces 2FA on them, even if they otherwise don’t have a phone.
- bertman 4y agoYep,that's what I thought of as well. Discussion from two months ago: https://news.ycombinator.com/item?id=32304320 https://news.ycombinator.com/item?id=32304320
- Semaphor 4y agoWow, my sense of time is horrible. I thought it was about 1-2 years ago :D
- UncleMeat 4y agoThis post was also very misleading. The concerns the librarian raised were actually addressed. The doc was old and made public by somebody other than the librarian, who edited it after it blew up to make it clear that the content was out of date. ====== Addition, 08/02/2022, 3:03pm: I don’t know how this got shared to HackerNews. I appreciate all of the positive responses we have gotten. However, this was not an open letter. It was meant to be shared internally to Google. It went directly to the security team and we had a conversation about it about a year ago. Things have improved significantly since then and this is no longer a daily problem. Please stop calling the branch or emailing me about it. It’s interfering with my work. Press inquiries can be made through https://libwww.freelibrary.org/contact/ https://libwww.freelibrary.org/contact/ and the public relations department will be in touch with you. If you want to learn more about patron privacy and support librarians advocating for patron privacy and against big tech please check out https://libraryfreedom.org/ https://libraryfreedom.org/ which is a wonderful organization I am a part of that does work like this. I still firmly believe in and stand by everything that I wrote. But this particular action was not meant to be a public letter. Also! If you’re in Philadelphia you should check out this big program we’re doing on August 12th called Empathy Versus Misinformation where a panel of experts will address questions and misconceptions about transgender youth!! Boy am I relieved that this was a Google Doc and I can just put whatever I want onto the front page of HackerNews now :)
- Semaphor 4y agoThere was a followup comment on HN: > Doesn't sound like it was completely resolved. In fact, it sounds like Google may have treated it as a "squeaky wheel," and only that library is getting better help. -- https://news.ycombinator.com/item?id=32309190 https://news.ycombinator.com/item?id=32309190
- UncleMeat 4y agoSo on one hand we've got the actual author of the original document saying one thing and on the other hand we've got an uninvolved internet poster saying something else.
- dgan 4y agobut nobody ever advertised phone numbers to be assigned "for life". People lose their phones all the times, I personally lost countless phones, and I am very far from being homeless. The problem is forcing 2FA on everyone
- ZiiS 4y agoIf you have a permanent address the are lots of ways to ensure you keep your phone number when you loose your phone. This is a very different problem.
- deleted 4y ago[deleted]
- lxgr 4y agoIt really is every company's fault that jumps on this absurd trend of seeing SMS-2FA as the be-all and end-all of user identification and verification. Google is actually doing much better than the competition here in many aspects (e.g. it is possible to operate a Google account completely without a phone number for 2FA or account recovery), but as far as I understand, one is still required to initially create an account.
- pilgrimfff 4y ago> it is possible to operate a Google account completely without a phone number This is only true for a limited time. I've tried to use a couple Google accounts this way and inevitably I log in from a new IP and Google's 2FA system kicks in - forcing me to either furnish a phone number or lose access to the account. It's similar to how Twitter forces phone numbers out of people - just not as immediate.
- lxgr 4y agoDo they really ask for a phone number, or would a Yubikey work as well?
- b112 4y agoA yubikey would be as useless in this article's specific case, as the problem is losing valuable things (eg, phones). A yubikey is no different. It too would be lost.
- lxgr 4y agoThat's definitely a problem, and a tricky one to solve in the context of 2FA: One of these factors is usually knowledge (your password); the other then has to be possession or inherence, and the latter has problems as well. Essentially, if you rule out possession, your choice is between server-side validated biometrics (if offered at all), or "double knowledge" (e.g. a password and email 2FA, with the email account also only protected by a password), which is pretty phishable.
- Bakary 4y agoI can definitely understand not realizing that you could lose access to your account if you lose your phone number. But once it happens the first time, could you not pick any free email that does not require 2FA, and warn fellow homeless to avoid gmail? I disagree with the idea that because a very, very niche audience is in dire straits that the design decisions should be based on their needs. The forced 2FA system has probably prevented identify theft and financial loss for a very large number of people. I'm saying this as someone who thinks Google is a shady and dangerous entity in general. It's similar to the idea that hard cases make bad law.
- tomxor 4y ago> because a very, very niche audience is in dire straits Not very niche.
- IIAOPSW 4y agoThe phone number decision is stupid. I up and jump countries every few years. Each time, I'm switching to a new number. I'm the opposite of homeless, I'm that jet set elite. The idea that you want, need, should or will tie your identity to a phone number where people can always reach you is long outdated.
- uup 4y agoSo use one of the other 2FA options.
- wavelen 4y agoafair you need to set up a phone number before you can choose to add another 2FA option (which is stupid imho)
- UncleMeat 4y agoEven if this is the case, this isn't a problem for the poster. They have a phone number, it just changes frequently. They can sign up, enroll in a TOTP or U2F system, and then they are set.
- danpalmer 4y agoI agree there should be more explicit support here, but can this not be "solved" with backup codes? One or more could be given to a trusted person – a family member, a friend, or even a trusted librarian – or a backup code could be remembered. The tough issue here is that these access edge cases look a lot like malicious use. The aren't but authenticating someone who has no device or ID or really much else to authenticate themselves is a Hard Problem. Passwords also aren't the solution here, the industry is moving away from them precisely because they provide poor authentication, particularly for vulnerable people.
- smelendez 4y agoThis is potentially a solution for some but it’s not perfect. If they had a trusted friend or family member who could store backup codes and deliver them as needed, they could probably also just stay logged in on that person’s phone or even have emails sent you that person. Keep in mind that they have limited transportation and likely lose their contacts when they lose their phones, and many will have strained relationships with the housed people in their lives. A library solution may not scale. Sure, a librarian might develop a personal relationship and do this as a favor for someone. But the author mentions talking to about 30 people with this problem in his neighborhood, which suggests that if word got out a librarian was doing this and they tried to institutionalize it, a library might have to store codes for dozens or hundreds of people it has no way to authenticate.
- jamesrr39 4y agoI think there are possible solutions here for a library, off the top of my head, taking a picture of your face when dropping off the codes, so that when you come back and ask for your codes, the librarian can ID you against the picture they have. Basically what is done when verifying your ID card/passport when you travel/go to the bank etc... It wouldn't be a librarian doing someone a favour, but rather a service that libraries provide. This could be a great evolution for libraries. They are already a distributed, public system, that people in general trust, but their role in society has changed with the rise of the internet and online services, and this could be a really useful role they could fill.
- WithinReason 4y agoJust turn off 2FA
- Maursault 4y agoFinally. Everyone seems to assume that 2FA is a great idea, but it is, in fact, a problem in itself, and a much larger problem than unauthorized access ever was. Unauthorized access was never an ubiquitous problem like 2FA definitely is. Unauthorized access was an exception. The only UA I had heard of prior to 2FA being rolled out was with users of Yahoo Mail. I can understand that some institutions may have experienced it more because they had so many users, but 2FA punishes everyone. Just consider the sheer amount of time it has wasted since being rolled out everywhere, 30 seconds at a time. It's centuries of wasted time by now to solve an issue affecting as little as 1% of users. And 2FA can be defeated through social engineering, and it is defeated constantly in this way. I would far preferred password requirements with 80-bits of entropy than everywhere I log into requiring I collect a 6 digit number from an email, app, SMS message, etc. But nearly everyone here seems to think this extra little bit of work at every login is a good thing, assuming they would ever have an account compromised. Seriously, how many here ever was compromised prior to 2FA? I've been online since 1983, and I had never come across it personally until after 2FA was rolled out. Ignoring the personal inconvenience, 2FA's inconvenience increases exponentially for every 10 users being supported. Supporting 2FA among 10K users globally, just 2FA in itself, becomes a full time job for more than one administrator, when previously, those 10K users were commonly supported by a single tech. Frankly, I'd far far rather take the risk of unauthorized access than being strong-armed into using 2FA. The amount of time 2FA wastes is far more than the time wasted by unauthorized access. The solution is far worse than the problem ever was.
- jakub_g 4y agoIn one of the later posts, the OP writes that the homeless will lose any physical thing after N weeks. So what kind of 2FA would be homeless-proof? I don't see a solution. Also, fully acknowledging Google and other bigtechs 2FA is far from ideal: The other thing is, we want at the same time Gmail to be unhackable against best hackers and state sponsored adversaries for the billions of users, including high profile dissidents, journalists, and senators who will inevitably have accounts; and at the same time to homeless people who can't keep any physical thing. It's kinda difficult to meet those conflicting requirements well at the same time. Maybe the solution should be to have some basic free state-paid email provider for those people. They are not forced to use Gmail specifically (albeit the number of non-sucking and free email providers is probably close to zero).
- Cerium 4y agoMaybe we don't need to meet all those requirements simultaneously. The on boarding process could try to determining if 2fa would actually benefit you or not.
- macspoofing 4y ago>The on boarding process could try to determining if 2fa would actually benefit you or not. How?
- adgjlsfhk1 4y agoBy asking you?
- macspoofing 4y agoWell .. yeah. And I think that's what OP (of the twitter thread) is advocating (without explicitly stating it). Namely, that 2FA doesn't work for homeless.
- MonkeyMalarky 4y agoAsk. Default to yes but allow to opt out.
- virtualritz 4y agoWon't using e.g. Authy with Gmail for 2FA alleviate the need for a phone number after the initial setup (i.e. requiring a number only once, to initially enable 2FA)? https://authy.com/guides/googleandgmail/ https://authy.com/guides/googleandgmail/
- Taek 4y agoYes, but that's a highly technical solution. I've been trying to get my girlfriend to use Authy for 6 months now, and the solution we landed on is that my Authy app has all of her 2FA codes, and she just calls me if she needs one. To you and me 2FA doesn't seem that complicated. But to less technical people it's just overwhelming and they don't want to bother with the learning curve.
- kioleanu 4y agoWhat learning curve? Setting up the account in the first place? Sure, that’s a tad complicated, but I really don’t understand why your girlfriend finds it easier to call you when she just has to open the app and the code is simply there.
- abraham 4y agoHow do you use Authy if you lose all of your possessions every few months?
- deleted 4y ago[deleted]
- saghm 4y agoFrom what I remember when I used Authy briefly (Google Authenticator finally added the ability to mass import/export codes shortly after I ended up trying Authy), you create a login and set a master password, and then you have access to your codes on any device when you log into the app. Of course, this means that you have to trust Authy with your codes being stored externally, but this might be one of the sets of circumstances where that's preferable.
- P5fRxh5kUvp2th 4y agoI don't think access to email is the biggest concern the homeless have. It sucks, but there are alternatives besides gmail and if google is going to spend time on this, I'd rather they not and instead spend time on getting homeless into homes.
- lxgr 4y agoWho do you think would be spending time on this at Google? I highly doubt that their software engineers and product managers in charge of 2FA would, when idle between pull requests, go out and help the homeless. Why not lobby those engineers and product managers to improve something that they are actually have agency and arguably a mandate to improve, helping users homeless and otherwise?
- P5fRxh5kUvp2th 4y agoI don't understand the question, google cannot attempt to solve this without assigning someone to spend their time on it. If they do so, I would rather they put that money into actually helping the homeless.
- lxgr 4y agoI think you vastly overestimate the fungibility of engineering resources in large corporations. Also, which one do you think the involved stakeholders at Google would have an easier time getting signed-off: Decreasing reliance on stable phone numbers as an authentication factor, or firing a couple of people and donating their salaries to an organization helping the homeless? Sometimes, depending on the probability of success, the pragmatic choice is also the ethical one.
- P5fRxh5kUvp2th 4y agooh stop it, tech people always think the world works in binary. Apparently this multi-billion dollar company can't see fit to help humanity because it's literally hard (or impossible?). That somehow I, as an individual, have more of an effect because charities only ever accept money from individuals and not billion dollar corporations? seriously, just stop.
- lxgr 4y agoSMS 2FA needs to disappear (or be relegated to a strictly optional, discouraged method) yesterday, and so does using a phone number as the primary user identifier.
- nordsieck 4y ago> SMS 2FA needs to disappear (or be relegated to a strictly optional, discouraged method) yesterday, and so does using a phone number as the primary user identifier. A lot of the downsides are mitigated by using Google Voice as the SMS number, since attackers can't migrate your number away from Google. But in general, I totally agree with you from a security perspective. I just think that it's a difficult thing to get people to use authenticator apps. Apple has resorted to baking the functionality into their OS.
- lxgr 4y agoThat's what I'm doing, and it works fairly well – until I get to one of the many corporations regarding VoIP numbers as inherently insecure, and they don't let you use it for 2FA purposes... (Nevermind Google supporting robust 2FA for logins, and my phone operator not even offering 2FA for eSIM swaps.) And that's disregarding the elephant in the room, i.e. Google inevitably pulling the plug on Voice at some point.
- angry_octet 4y agoThis problem, and the not-my-problem responses, really highlight the self centered mindset we have encouraged. What if that homeless person was your substance-abusing sibling? A friend from school with mental health issues? We need to collectively take more responsibility for those in the worst situations. If you've every tried to teach an old person how to use 2FA you know it's an uphill battle. Using a fingerprint reader isn't even doable for some. And we're all going to be old one day. Practically, we need ideas like to 2FA to gain tractionas widely as possible, while realising that isn't everywhere. And some people will never use 2FA, need higher thresholds for triggering lockouts, and need alternative methods for re-establishing identity to their ID provider (google in this case). For some people that might be their local librarians or community shelter, legal aid groups, and banks.
- remote_phone 4y agoNo, people like you really highlight the “If they don’t help everyone then they are being immoral” mentality. Which is wrong. Down grading security for the benefit of a tiny minority with an especially ridiculous use case is not the greater good. If the homeless people think they are at risk of losing their phone then they should pick another free email vendor.
- d4mi3n 4y agoThis is a simplification of the problem. Both: 1. Vulnerable populations need more assistance accessing essential services required to participate in society 2. Service providers need to maintain a reasonable level of security for their customers Can both be true. Saying that maximum (or minimum) levels of security are required at all time completely misses the point of security--which is to mitigate risk. How much risk is appropriate varies a lot by context. Beyond the context of risk, there is reasonable debate to be had on how to best provide access to essential services to vulnerable populations. It's pretty important to have an email nowadays and if you're not tech savvy or an individual/community has little to no money to spend it's not unreasonable to have the reality of the matter be that there may simply not be many good alternatives (or awareness of alternatives) to GMail. I'm not sure what a correct answer here looks like, but I don't think ignoring the need is an approach that gets us to a better society or enables vulnerable populations to better care for themselves.
- codegeek 4y agoMaybe we can build some sort of a "reverse proxy" solution where you can get a number from Twilio etc and just forward to an actual phone number from your carrier. Bonsu, you can add some "firewall" rules and boom. If you lose your phone from your carrier, your twilio number is the same. Just change the rule in Twilio ? Isn't there a service like this already ? If not, there is your billion dollar startup idea.
- remote_phone 4y agoThe biggest fallacy we have right now use that all use cases need to be treated equally and if they don’t then somehow they are being immoral. Google is not being immoral. The homeless people can use a different service. Dealing with the use case of someone losing their phone every few weeks when you have billions of others to worry about is unreasonable. I think handling that situation should be considered out of scope.
- bombcar 4y agoPerhaps not immoral but kafkaesque or something - if a government support service requires an email address to be used, and the government doesn't provide the email address, there is a dependency on the market to provide such. And if they don't give a list of "workable free email providers" then the government has failed. Imagine the howling if you had to have an email address to vote.
- krzyk 4y agoI'm a bit surprised, homeless people have phones and email addresses? Sorry for question, but it is a bit mind blowing for me, in my country homeless people are rare and the ones I see don't worry about anything besides something to eat and alcohol. So having a mobile for them would be like having cash to buy the mentioned things.
- adgjlsfhk1 4y agoMost homeless people aren't permanently homeless. Of the homeless population at any given time (very) roughly 50% will only be homeless for a few days, 20% will be homeless for a few weeks, and 30% will be homeless for months or longer.
- Comevius 4y agoThey are homeless not Amish. People can have jobs too while being homeless, since you often can't afford rent in many parts of the world with just a single income. You have to choose between a roof over your head, or eating and having a car to be able to go to work. Or you can get a second income, either another job or a relationship, but that's not always an option, hence why so many people live in their cars. Around 200,000 people live in their cars in the United States alone, but that number is climbing rapidly and will reach a million in a few years, because housing is a luxury now. And just to compare, the cheapest completely useful (4G, 3GB RAM, 3000mAh battery, Android 11) smartphone is $30, the average monthly rent of a two-bedroom apartment in the United States is $1300.
- guywithahat 4y agoI was walking to a convenience store two nights ago and I saw a girl venmo'ing a homeless man money. Realistically it's hard to exist without a phone and bank account, and there are a lot of financial aid/benefit programs for homeless people to pay for these sorts of things
- exabrial 4y ago2FA that delegates to SMS needs to be illegal and addressed by congress at this point. Whats "actual" happening is you're delegating authentication to another company that performed either a hard credit check the person (the vast majority of us) or has a prepaid (likely the situation above). In both cases, it's delegating of IDV and needs to be outlawed.
- jqpabc123 4y agoAn authenticator app is a much better 2FA solution that I opt for at every opportunity. Google's authenticator app is brain dead because they want to encourage 2FA over SMS. Why? Because it has the wonderful side effect of destroying your privacy. With your phone number, Google can easily identify you personally. Ain't that special --- privacy invasion wrapped up in security clothing! Much too tempting for Google to resist. Google didn't invent OTP so there are other apps that are perfectly compatible. Word to the wise, it should be obvious by now that all things "Google" are synonymous with "privacy invasion".
- sp332 4y agoHow are you going to sign in to your OTP app on a new device?
- jqpabc123 4y agoReinstall the app and restore private keys from off device backup. The lack of key backup and restore is one big reason not to use Google's authenticator app. Other compatible apps are not so brain dead. I backup every time I add a new sign in. If you don't have the ability to sign in from multiple devices and the ability to install access onto any new device, then you're doing it wrong. Phones are highly portable devices subject to being stolen, damaged or just dying for no obvious reason --- so always be prepared. This is simply not possible with 2FA over SMS.
- joshuamorton 4y ago
- kuwoze 4y agosorry but why are they losing their phones ? stolen ? sell it for drugs?
- Workaccount2 4y agoWhen you are on the street your stuff gets stolen a lot.
- kotaKat 4y agoShit gets stolen nonstop, and not just by fellow unhoused. When the police come and tear down camps, there's no expectation of recovering anything left behind. 9 times out of 10 they're followed by a public works crew throwing everything into dumpsters. Good luck getting your phone (or any of your other possessions) back.
- kuwoze 4y agoi thought in california there's a recent law stopping police from tearing down camps because exactly homeless people's property is now considered same "class" as normal people's hence you can't just throw it out.
- ifqwz 4y agoI hate services that forcibly enable 2fa on you. Even if you have it disabled, if they detect that you have changed browsers, IP addresses, etc. they make you go through 2fa whether you want it or not. Or just lock you out, or even suspend your account. Fuck that.
- ifqwz 4y ago>Unhoused people tend to get their phones through the "Obamaphone" program, which means that replacing a lost or stolen phone results in a completely new phone number. Maybe that's part of the issue. Why recycle numbers so aggressively? Give the user a few months to recover their old number if they can prove they are the same person.
- miki123211 4y agoThis is yet another example of the "accessibility, privacy, fraud-protection, choose any two" problem. You can force people to use 2FA, but then you discriminate against people who can't. You can build an account recovery flow that requires government-issued proof of ID, but then you sacrifice privacy. You can do neither, but then you make accounts easier to compromise and harder to recover. There's no good solution here, it's all tradeoffs. Captchas are another situation where this problem arises. You can implement easy audio and text captchas, available in all the languages your signup form supports, but then you get a lot more fraudulent signups. You can eliminate captchas altogether, relying on invasive user fingerprinting instead, but then you sacrifice privacy. You can do neither, but then you discriminate against visually impaired users. Once again, no good solution, just tradeoffs.
- civilized 4y agoMaybe each individual should be allowed to "choose the two" that work best for them. Most of us have at least one email account that's already under our real name, where we have no big interest in hiding our real identity, but we do have a big interest in not being randomly shut down by Google. We hear about such shutdowns every few weeks on HN, if not more. Google has unfathomable financial and technical resources, much of which goes to projects of speculative value at best. I can't help but feel that they could provide a slightly more customized login experience to help diverse people with diverse needs.
- Balgair 4y agoThere are a lot of email providers out right now that fit one of the three possibilities OP set out. But most people aren't aware of any of this, choose the one they know of or see first, and get angry when 'it doesn't work right'. Like OP said, all cover is temporary.
- ridgered4 4y agoThe only email provider I'm aware of that still doesn't require a phone number during sign up is protonmail. Maybe tutanota but IIRC they wouldn't let you sign up over a VPN.
- borissk 4y agoWhat makes you think Google cares about homeless?
- notThrowingAway 4y agoWhat makes you think Google cares about anyone?
- borissk 4y agoStupid question.
- ClassyJacket 4y agoI have lost access to Tinder and Transferwise because I moved between the UK and Australia and thus changed my phone number. Whatsapp also silently fails to send me private messages now, even after I went thru their official inbuilt 'I changed my number' process - only my group chats work now. The messages appear to send to the sender, they don't even know I didn't receive them. One of the worst examples I've heard is that Overwatch 2 not only requires a phone number, but they actually check with your carrier if it's a prepaid number, and if it is, you're banned. Sorry poor people, Blizzard doesn't want scum like you playing their game. Assuming someone's phone number never changes, or that they'll have access to their old and new numbers at the same time, is simply wrong and does not work. I haven't been locked out of Google yet, somehow, but maybe it's just a matter of time.
- 0xbadcafebee 4y agoGoogle doesn't even care about their paying customers. You think they care about the homeless? Just stop using Gmail. Here is a very small number of other providers: https://www.ionos.co.uk/digitalguide/e-mail/technical-matters/free-e-mail-providers/ https://www.ionos.co.uk/digitalguide/e-mail/technical-matter...
- ChoGGi 4y agoLast time I checked Google will issue backup codes, the individuals and this person can both hang on to them when the phones go missing.
- tzury 4y agoThe title "Gmail 2FA causes" is misleading. Every phone-based MFA will lock out users once phone is lost, and no proper back up was taking place.
- pmarreck 4y agoDoesn’t Authy persist Google Authenticator codes through devices?
- hatware 4y ago"Unhoused people" The newspeak is strong with this one. There was never anything wrong with the word homeless. Have progressives gone too far?
- theandrewbailey 4y agoMaybe. Look up George Carlin's soft language skit. It's happening to "homeless" now.
- BulaVinaka 4y agoIt's meant to imply that private persons shouldn't be allowed to own property, and that a central authority should be responsible for "housing" people.
- ajhurliman 4y agoBack in Seattle the lingo was "persons experiencing homelessness". I feel like the more syllables you can get in there, the more PC it gets.
- est 4y agoReminds me of an anti-CAPTCHA argument, there are many people in this world who have never seen a fire-hydrant in their life.
- xxs 4y agoor American buses, or anything culture centric. The US version of hydrant is just not present around here.
- concordDance 4y agoI don't understand why governments don't provide everyone with an email address. E.g. John.doe1234@people.gov
- tiku 4y agoEstonia does this for their eResidents.
- dexterdog 4y agoBecause google funds campaigns
- RichardCNormos 4y agoThe government doesn't need copies of my communications living on their servers.
- peanut_worm 4y agoDon’t they have backup codes?
- ruph123 4y agoGmail != Email. There are many other usable (and free) email providers out there. It doesn't have to be Google.
- dtx1 4y agoIf you rely on a free google service for anything in any situation, you are one random AI decision away from being completely fucked anyway. If losing 2FA access often is a problem for you, chose a different provider or if you have to use google for some reason, use their google authentication app and save the authentication credentials somewhere save. If you cannot keep a strip of paper with a few recovery codes safe, don't use the internet, it's not for you.
- calibas 4y agoPotential solution, the Obamaphone program keeps using the same phone number for an individual instead of totally new ones every time they lose a phone.
- MAGZine 4y agothis feels like a workaround. We should not be treating phonenumbers as SSN round two, where everyone relies on it for your identity, and it should never be changed because of how much shit was needlessly tied to it. I rue the day I need to change my phone number and my digital identity becomes a huge headache, especially for far flung services that decided they wanted my phone number, but I wouldn't have considered going explicitly to them to update it.
- calibas 4y agoIt's not ideal, but phone numbers already are how we verify identity online and sometimes offline. There's been other methods proposed, but they've generally been rejected because of concerns over privacy. I'm not proposing a solution for the real issue, simply a way of making things easier for people who have a hard enough time already.
- syrrim 4y agoIt already is that, which is precisely why google is using it here. Google is an american private company. Phone numbers have government mandated systems around the world that allow a individual to keep using them even when they lose their phone. Google uses it because it lets governments solve the identity problem in the fashion and to the degree they deem acceptable, and leaves google in the tech business. Some countries have issued ID cards which support encrypting and signing documents. If that becomes more widely practiced, then google could switch to that instead, but until then I imagine they'll keep using phone numbers.
- yamtaddle 4y agoThe correct solution to this and a shitload of other problems is a real, national ID program. But there's enough resistance to it in both US political parties that it can't happen. The lack of it causes a ton of stress, over the population, and is a drag on the economy, but we're just never gonna fix it. Instead we'll de-facto have one (or more) anyway, including 99% of the risks that a real one would carry with it that everyone's so hand-wringy about, but without the benefits of the real thing.
- arbuge 4y agoYou lose your entire Google account if you lose your 2FA device or number (assuming it's a phone number), for any reason. Even if your Google account is set up with a non-Google email address which you still have access to, and you still know the correct password. And there's nobody you can reach at Google about it, no appeals process, nothing. https://news.ycombinator.com/item?id=33098261 https://news.ycombinator.com/item?id=33098261
- anotherman554 4y agoThat link involves someone with no backup email address connected to their google account for recovery purposes, for what it's worth.
- arbuge 4y agoYou can set a backup email address for Google accounts if they're using Google email addresses, but you can't do this if they're using non-Google email addresses as the primary address, such as the one in that link. I'm logged in to such an account right now and there's no way to do this. The account primary email is also set as the recovery email address and there's no way to add another. It's actually deceptive to the user to even call it a recovery email address in this case, since Google will never offer to alternatively send a verification code there if the 2FA device is unavailable.
- ChrisGranger 4y agoI lost access to a Gmail account for which I had the correct password and a recovery email with a different email service. I was still unable to convince the Google machine that the account was mine. My suspicion is that because I'd changed operating systems on my desktop, I appeared to be 'someone else' as far as Gmail was concerned.
- mihaaly 4y agoI took three steps against this happening: 1) Not providing phone number for 2FA. Never. 2) Using multiple (3 pcs.) physical keys for 2FA (like Yubikey and similar). Authentication app is an alternative for one choice of 2FA (but not the sole one!) 3) Only using a limited set of Google functionality. Use for secondary purposes mostly. Well, the last one is mainly to mitigate the consequences if happens anyway, for other reasons too (like with that poor guy who made picture of his own naked baby for a remote diagnostics with his doctor and the Google locked him out for months - and still counting at the time of the article - for child pornography)
- l72 4y agoEvery single American should be able to get a free, permanent email account through our Postal Service! We shouldn't have to rely on Gmail for what may be the only way to get information/apply for on basic government services!
- alpentmil 4y agoThis. The provider/USPS will then realise how challenging it is to do verify identity.
- mcshicks 4y agoThere was a bill to improve digital identity in the us Congress but I don't think it went anywhere. I do think govt issued digital id, while in some ways problematic would be a step in the right direction https://www.congress.gov/bill/117th-congress/house-bill/4258 https://www.congress.gov/bill/117th-congress/house-bill/4258
- 99112000 4y ago
- Cyph0n 4y agoDid you even click on the link?
- benhurmarcel 4y agoI understand they get stolen
- topherPedersen 4y agoYeah I don't like that feature either. You can't get into your gmail unless your phone is working. If you don't have access to your phone # you are kind of screwed. EDIT: It looks like you can turn off 2FA, I think I'm going to do that now so I don't get locked out of my Gmail.
- topherPedersen 4y agoToday I learned you can turn this feature off. Just disabled 2FA for my Gmail so I don't get locked out if something happens to my phone/phone-number.
- beauHD 4y agoSMS as a second factor should be deprecated. I got locked out once because my phone was stolen that had the SIM inside, and I couldn't get back into my Google account. Now I just use a Yubikey and am never asked for OTP codes that are sent to my phone.
- courgette 4y agoIt's a valid point that I don't expect Alphabet to address. Honest question : what about those security code? I'm not homeless but I expect my phone to die anytime. It's from 2015. I want to bring it to 2025 but it might not make it. As a result I planned for that phone stopping to work and my understanding is that I will be able to emergency 2FA with those code once it broke. Am I wrong?
- nyuszika7h 4y agoHow do you expect homeless people who can't hold on to their phones to hold on to the backup codes?
- spoonjim 4y agoProbably a genuinely useful application of biometric authentication.
- bArray 4y agoAgain, this idea of "secure by default" should at least have an option to opt-out. A few misunderstandings about phones: 1. Somebody has a phone 2. Somebody has a smart phone 3. They are in contact with the phone 24/7 4. They are the unique user of that phone 5. The SIM card and/or number cannot be taken from the phone (virtually or physically) I currently have to use this for work, with the only positive being that if I get locked out, I can go tell the admin team to let me back in. With someone like Google, it's not even possible to get them on the phone to explain, let alone have them believe it is really you.
- deleted 4y ago[deleted]
- mihaaly 4y agoNot only Google. A much less critical or important thing but underlines the bad attitudes: I just tried to renew my cancelled Netflix membership yesterday. I am not allowed to do that without providing a phone number (I used Netflix for ca. 8 years without it). I do not provide that because I do not want to. I do not tie every aspect of my life to my phone number. In fact I do not want to tie any aspect of it to my phone exclusively. Phone number based authentication is not safe and reliable anyway (can loose, stolen, damaged, then I'll have a cascading effect of problems instantly). I talked long to the helpdesk lady and the conclusion is that I am not allowed to renew my Netflix account without providing a phone number. End of story. I permanently remain a non-Netflix user this way. Their loss actually. (A secondary trouble with them is that they are trying to misinform me, giving false reasons! The support lady reasoned that they need the phone number for validating bank transaction. Since they - Netflix - want to use this to send a code in text that I am required to type into their - Netflix - system it has nothing to do with my bank and with authenticating the transaction! (my bank would never use phone for authienticating a transaction btw, I am not even sure if I updated my phone number with them, they reach me other electronic ways). She was just bullsh%ting! Also the renewal pages stated differently, saying that authenticating my account is where the phone number is required. Not to mention that a friend of mine registered recently and for him the reason to register a phone number was to retrieve password recovery messages. Three sources, three different reasons, one of them is complete bullsh%t. Very repelling kind of practice, I am actually glad staying away.) (A third smaller aspect was that the helpdesk lady tried to interview me about my phone usage strategy and my reasons instead of answering my question about alternatives. It is not her business how I use phone and trying to pressure me into some rigid lifestyle strategy they determine. There are many alternative ways to carry out the same task, they should provide more and better choices.)
- judge2020 4y ago> (my bank would never use phone for authienticating a transaction btw, I am not even sure if I updated my phone number with them, they reach me other electronic ways). Phone numbers are often included in billing address inputs, so I imagine it's at least logged in the bank's system and perhaps used as a heuristic signal for fraud.
- 4y ago
- s0rce 4y agoVery confusing title, I thought there was some weird schedule that needed address verification. It's when a phone is lost which is on average every 12 weeks according to the twitter post.
- xen0 4y agoThere is a huge disconnect between two types of companies. The majority of companies seem to view email addresses and phone numbers as largely permanent identifiers. Then there are the companies that actually provide you those things. To them, what they provide you is definitely not permanent.
- deleted 4y ago[deleted]
- craniumslows 4y agoWhy not educate the people in need about the tons of other free email services that exist? Outlook, tutanota, protonmail, yahoo, gmx, fastmail, zoho theres plenty more but you get the idea. The only way to win is to not play the game.
- jupp0r 4y agoGMail requiring a password makes my grandparents loose their access what feels like every time I visit them. I can imagine that homeless people are facing that problem on top of the ones described in the thread as well. GMail offers backup codes to somewhat solve the phone number problem by the way.
- sicp-enjoyer 4y agoI wonder how much time is used for 2fa in the entire economy each day.
- ynbl_ 4y ago
- deleted 4y ago[deleted]
- ENOTTY 4y agoThis might not be a problem that matters to the Google bean counters, but it would be a problem that a responsible, moral, and just company would solve.
- labanimalster 4y agoYou mean 4 times a year…every 12 wks
- hitpointdrew 4y agoI think you really mean once. How do you "permanently lose" anything more than once? If it is permanent then you can only lose it once.
- sb057 4y agoFWIW I have pretty much given up on trying to use any sort of online banking or other financial website because I do not have cell service at my home, and practically every financial institute requires SMS 2FA these days.
- jochakovsky 4y agoSome carriers have apps to allow you to receive an SMS over data (eg. Message+ on Verizon)
- sholladay 4y agoI wonder how WebAuthn Passkeys will fare here, as they can replace both passwords and existing 2FA systems. With Passkeys, your credentials will automatically sync between devices. So as long as you have some way to log in to your main account (Apple/Google/Microsoft, etc.), then you should be able to maintain access to all other accounts, even if you’re always moving between devices. And there is a solution to the single point of failure problem as well, because there is a built-in flow where you can copy the credentials to other platforms, in case you lose access to your main account.
- etchalon 4y agoThis could be remedied with "Custodian" 2FA, couldn't it? Allowing for a case-worker, for instance, to act as a secondary 2FA method, and making it easy for the custodian to update the users information. Wouldn't be all that different than corporate ownership policies or family accounts.
- hammock 4y agoIs homeless a temporary or permanent state? How many homeless have been so for longer than four months?
- charcircuit 4y agoIt is temporary because they can just buy / rent a home
- tiku 4y agoJust stop being poor or mentally ill, easy.
- aaron695 4y ago
- from 4y agoI want out the ability to opt out of this 2FA nonsense. I’m not a journalist in a war zone, I’m just a guy who wants to read his email (with a 64 character password containing random ASCII characters). 2FA is just an excuse to make the abuse departments life easier by raising the cost of botting accounts.
- permo-w 4y agoI know this will sound “let them eat cake”-ey but just don’t use gmail then?
- AngeloAnolin 4y agoEvery solution/alternative would always impose challenges that can be considered an edge case initially until it becomes permanent. For example, if Google wants people (who have a tendency to lose their 2FA devices more often) to always use this feature, and in case they lose access to their device, they could use a trusted designate who can verify on their behalf that they are the ones signing into the service. But then again, this alternative will impose some new challenges such as: - What if the designate is not available? - Designate is available but also lost their access to verify the other person? As with this case being raised here, it will always be a process wherein Google (or any other organization) will have to explore and find meaningful solutions that is both inclusive and considerate on specific conditions. The variability alone of such premise is huge that I am quite sure when the next edge case comes up, there are other edge cases boiling down that will become the next set of issues.
- deleted 4y ago[deleted]
- A4ET8a8uTh0 4y agoI will offer an unpopular take. Maybe we should not be focusing on ensuring homeless have access to email. Maybe we should be focusing on ensuring basic services do not require email and/or cell phone.
- tiku 4y agoYou could tattoo your recovery code somewhere on your body perhaps? And the re enter it in your 2fa app. Not ideal but unloseable.
- dexterdog 4y agoTattoos are not cheap and recovery codes are 1-time use.
- spoonjim 4y agoI don't think changing Gmail to meet the needs of the homeless, at the risk of everyone else's security, makes any sense. Instead there should be a different email service that the homeless use, perhaps government provided if there's no business model in it.
- chimprich 4y agoGoogle's 2FA is dreadful. 2FA is a good idea when it's added with consent, but Google adds it behind your back in ways that are both infuriating and brain-dead. I've been caught out recently twice: once I was away on work and had to access my email. Google demanded that I verify it using my phone that I'd previously accessed my work email with. However, this phone was just a phone I use for development, had never had a sim card inserted, and was on my desk at home. I hadn't agreed that it should be used for 2FA. It was tremendously inconvenient because I needed to find where my hotel was. Another time recently I managed to destroy my phone in an accident and got the phone replaced. Despite taking the sim card from the old phone and putting it in the new one, doing a factory reset on the old one, and it not being active for a week, Google still demanded I 2FA authenticate on the old one. I feel these problems could have easily been avoided, but it's typical latter-day Google experience: a tin ear for the customer experience and a general attitude of automation knows better than users.
- gigglesupstairs 4y agoApple does it too. I have three iPhones, one much older than the other two. Recently, in one of my new iPhones, Apple decided to ask me about my passcode I used in my “giggleupstairs’s iPhone” for some special verification scenario. Now, what? I have THREE iPhones, how will I remember which iPhone is this generic looking iPhone name referring to? I kept entering what I thought was the correct passcode for at least three times before realising what was happening. I shudder to think I could have ended up locking up my account like this.
- Sirened 4y agofwiw, the passcode challenge is for decrypting your keychain. If you fail that, you lose your passwords and other E2E data, but for better or for worse, not that much stored stuff is E2E encrypted and so you don't lose too much. I don't know if it's still true, but a few years back if you lost everything (i.e. didn't know your passcodes, didn't have a device to approve the sign in from) you could still get back into your account by waiting two weeks and recreating your keychain. This also means that if you are ever away from the internet for two weeks and someone knows your password that they can jack your shit but that's quite the edge case imo.
- bongoman37 4y ago
- aaaaaaaaaaab 4y agoWtf is "unhoused".
- golemotron 4y agoIt is the next step on the euphemism treadmill. Apparently, "homeless" is tainted or declasse now.
- himinlomax 4y agoI wonder what the next step will be. Probably an acronym, PWFA (Person Without Fixed Abode).
- deleted 4y ago[deleted]
- RichardCNormos 4y agoMy city government here in California calls them "people who live outside".
- deleted 4y ago[deleted]
- ZeroGravitas 4y agoIt feels like having a way for them to transfer the Obamaphone numbers would solve this, and probably some related issues. Since I've been able to keep the same number through various phones and Sims, this seems technically possible.
- sneak 4y agoYour phone number is also your permanent cross-app tracking advertising identifier. This is why every app and vendor asks you for it. I change mine every 90 days.
- ajhurliman 4y agoDo you just go into the carrier's store and ask them to change it, or do you have some streamlined way of changing it? Every time I go into one of those stores it seems to take hours to get even the simplest thing done.
- sneak 4y agoI just buy new $90 mint prepaid sims for cash. They work for three months. I have never talked to a CSR.
- ajhurliman 4y agoThat sounds like the dream. What do you do for 2FA stuff that requires a consistent number?
- sneak 4y agoMost of those I simply make new accounts after 90 days, or I don’t use those services. For some things I have a Google Voice number, the Google account for which uses Advanced Protection (hardware 2fa only).
- kazinator 4y agoSeparately from the Gmail 2FA cluster fuck, maybe that Obamaphone program should fix its number nonportability problem?
- susanasj 4y agoI think the answer here is not that Google makes bad product design decisions it's that we shouldn't live in a society of incredible wealth but some people still don't have homes and have to sleep in places where they are constantly the victims of property crime.
- benpxu 4y agoSidenote from something I noticed from the rest of these comments: SMS is not the only form of 2FA. It is the most common type, but also one of the most insecure versions of it. You should not be using SMS for 2FA.
- yellowapple 4y agoAn elegant solution here might be to allow users to designate a list of other users who can "vouch" for them; if multiple people who you previously designated as trustworthy say "hey, this is my friend's new phone number, use it instead of the old one for account recovery", then that should satisfy the "who you are" authentication factor (and set the new "what you have" factor). Similar idea behind web-of-trust or multisig cryptocurrency wallets, except without the cryptographic mumbo-jumbo.
- deleted 4y ago[deleted]
- kylehotchkiss 4y agoThey should try other free email services. It’d be nice if Google voice was still free and somebody could help set that up as their persistent number. That said, Google 2FA is mission critical for many people’s online identity and is protecting them from a world of online evils, this is not a reason to step back from a security posture that Google has rightly decided protects its users.
- errorik 4y agoHow about building a solution (or a possible solution)? I think it is fair to guess that many people reading this have achieved some level of success building solutions to technology problems. Much like solving for malicious use for the average user with 2FA - or privacy with things like protonmail - why shouldn't some of us attempt to solve this rather than expect/complain that Google hasn't? Mail hosting isn't particularly expensive - companies like mxroute are sub $1 per GB per year with deliverability, etc taken care of - or at least well enough to make it better than constantly changing addresses. I know that I personally would be willing to invest time and non-trivial amounts of money to offer a solution and gauge adoption and feedback. Some opinions (open to feedback!) on where to start: 1. Use existing mail provider from the start - mxroute looks like a possibility 2. Overprovision storage by some reasonable factor - say 1GB accounts with 10x overprovisioning - interested to hear from those who know more than me about this but I wonder if more unhoused/homeless people generally use email for mostly transactional purposes not 20mb JPEGs, etc. 3. Ensure the webmail interface (possibly build it) is Ultra simple and Super accessible - screen readers, text to speech, and of course mobile first. Again I (perhaps naively) imagine that features like tagging, rich content composing, and filtering are super low priority here. 4. Have a sign up flow that is mildly fraud resistant - mobile number verification (VoIP not accepted) with a cool off before it can be used for another account (how often do Obamaphone numbers rotate/deactivate once stolen?) and an (accessible) captcha type system to avoid mass sign ups. This could then in V2 be expanded to include more corner cases - possibly invites in lieu of phone numbers, etc. If fraud/spam became an issue it should be easy to detect given these will generally be low volume users. 5. Require only a modestly secure password for login. Use malicious use detection to trigger recovery/verification mode (see next). 6. Have a recovery/verification mode that fits the user group - need ideas here - but 5 questions that you have to answer 4 of and have some verification that the answers are not just simple words at setup? Combine that with verify with a real (but possibly different) mobile (non-VOIP) number that hasn't been used in X days to verify another account? Trusted friend recovery address? Seems like lots of possible solutions to explore here, and no doubt lots of people smarter then me who could provided ideas. Is there interest in doing this? Am I the only one that feels frustrated when we (including myself) debate what google should do, or why people are unhoused (or what to call people how are) when many of us are capable and financially able to at least try to offer a solution? With 500k-1M homeless/unhoused in the US (no reason it couldn't be international, just starting somewhere) - let's say it was crazy successful and had a 10% adoption rate of actual active usage. Maybe that's 7.5 TB of storage. I'm sure a reputable provider would be willing to partner to provide that at $1/gb/year or less (plus hosting webmail, etc) - I'd be willing to pay that bill personally for that kind of adoption/benefit. Would others? Would others dedicate their time? Homelessness is multifaceted - that seems to be the one thing everyone agrees on - so offering possible solutions to any given facet - from fragmented communications to safe shelter - is at least a start and possibly a small part of making a difficult life situation a little easier to overcome/deal with.
- olalonde 4y agoYou can disable 2FA[0]. [0] https://support.google.com/accounts/answer/1064203 https://support.google.com/accounts/answer/1064203
- bgro 4y agoDoes anyone else notice old accounts that were working fine in the past randomly get demanded to enter your phone number for verification. "We detected unusual activity" is such an obvious lie. When setting up thunderbird, I've had multiple Google accounts lie about suspicious activity and demand I go through about 10 captcha checks and enter my old password and answer my security questions and verify my phone number. After passing all of that without error, they STILL won't let me log in with a blanket statement about security. Why oh why would they ask users to jump through extreme hoops just looking for any possible questionable failure to point to as an excuse, but still reject you after passing everything? If you're not going to let people use their account, farming free AI detection and personal information out of them doesn't seem like a legitimate tactic one should be doing. They discriminate against some phone numbers too. They have to be in whatever they think the correct country is, they often can't be VOIP or VOIP related, and there's unknown blacklists of some famous numbers sometimes. What happens when we run out of phone numbers? I won't be surprised when accounts start getting banned for "sharing" or "ban evading" phone numbers (aka getting a new phone number for any reason) because it screws up their ad tracking of you... Or they'll force you to first log into an account in order to delete it even though it belongs to somebody else. Or your new phone number you bought specifically for authenticating a separate account is banned (just like voip number) because a previous user was banned using it.
- webdoodle 4y agoI went cellphone-less 2 years ago, and have experienced this first hand. I've been locked out of my Gmail, Ebay, LinkedIn, and other services multiple times. I was unable to apply for government services either, until I finally found a decent soul that used there own phone to register me. But they shouldn't have needed to do that, and we shouldn't be required to have a spy phone just to be part of society. These spy phones and the apps they peddle have become a plaque upon humanity. They use addiction and coercion (denied services) to keep you under there spell. The worst part is that they are being forced upon our children, way worse than the tobacco industry ever tried.
- modeless 4y agoWhy is this guy mad at Google for implementing security (which I guarantee has saved a lot of homeless from account takeovers), when he could be mad at the government program for failing to provide people with a stable phone number? Constantly changing your phone number has a lot of other bad consequences which have nothing to do with Google. And maybe the government should consider providing an email account too. The cost would be negligible compared to buying people new phones every 12 weeks...
- gerash 4y agobecause that's what you get with a 140 character attention economy
- RenThraysk 4y agoMore evidence how different groups in society have no idea how the other groups live.
- deleted 4y ago[deleted]
- rkagerer 4y agoI feel for these folks. I'm housed and never wanted my email (and a host of other services) to become dependant on my phone number. I've gone so far as telling service providers "I don't have a phone, deal with it" (which is getting harder and harder).
- pyuser583 4y agoHomeless, people facing criminal charges, incarcerated, etc. None of these folks are desirable advertising targets.
- deeblering4 4y agoI had never considered this thanks for sharing it. Yes the typical “something you know and something you have” 2FA authentication approach doesn’t work when unable to reliably “have” something. Even backup otp keys would be a challenge in this scenario. What solutions would help with this? I would think even having two passwords on the account (as in you need both to log in) would be an improvement over plain password auth.
- IncRnd 4y agoThis is a non-issue. When signing up for 2FA google provides a set of backup codes and instructions on how to use them when access to your phone number is lost. I don't work for google, and recognize they have many other issues, but this person on twitter is incorrect. There are other methods in addition to backup codes. There are voice authentication and id upload. I've even had Google call me back, and I spoke to a person who manually authenticated me. This particular system isn't broken. Of course, there are many other email providers. Why would someone keep choosing the same provider, when it doesn't act in the way they expect?
- googlryas 4y agoThe article mentions that "maintaining possession of anything physical is difficult" for the homeless. Let's say they print out the backup codes...but then their backpack gets stolen. Or it just rains and ruins the paper.
- deleted 4y ago[deleted]
- Pxtl 4y agoFundamentally this is a hard problem - how do you have "something you have plus something you know" which is security best-practice, for somebody who will regularly lose all their possessions? I mean I've always fantasized about getting NFC into everything so that NFC-based tags could provide convenient "something you have" taps. Like, give me a simple ring on my finger to tap-in to a scanner on my keyboard rather than having to meander through an app on my phone. The other problem is that with every org running their own auth systems, if you're trying to help a person with this problem you have to set them up on a dozen services. I really wish something like Mozilla Persona had took off.
- googlryas 4y agoHere's the solution: Since OP is regularly in contact with 30+ homeless people, he can offer to be their backup email account. He can then confirm the identity of people if they lose access to their account and help them get it back. Or, he can safely store their 2FA backup codes in his house. The homeless make up like 0.1% of society. And not every homeless person has this issue. It would be insane to make any feature for like 0.02% of the population. Especially a feature which diminished security. Because yes, those 0.02% of people might have an easier time accessing their accounts, but probably 100x that amount of people are going to end up getting tricked into de-securing their account, or do it by accident, and end up getting compromised.
- IncRnd 4y ago> Here's the solution: Since OP is regularly in contact with 30+ homeless people, he can offer to be their backup email account. He can then confirm the identity of people if they lose access to their account and help them get it back. > Or, he can safely store their 2FA backup codes in his house. Why even have security? Your solution practically screams for those 30+ people to be taken advantage of. Just use a different email provider whose procedures align with how you regularly change your phone number.
- googlryas 4y agoWhy would Chad Loder take advantage of them? Yes, it gives him the ability to, but that doesn't mean he will. Why have security? So some random, untrusted person can't compromise the account. If Chad holds the codes, then only he can compromise the account, and maybe their relationships are good enough that they would trust him. Using a different email provider also works, but I assumed there would be some reason that doesn't work - android effectively has a built in gmail client, non-tech people might just autocomplete "@gmail.com" and mess up someone's address if it is a non-expected domain, etc.
- IncRnd 4y ago> Why have security? So some random, untrusted person can't compromise the account. I know why there should be security. I was pointing out that what you suggested would degrade security. It's not whether one specific person would do anything with 30 phones' backup codes but that such a list would exist. There are many other valid security practices that can be used.
- throwaway290 4y agoJust the other day had an experience where someone in need, freshly moved to a new country, asked to use my phone to email a relative asking for money to buy a phone. When I realized they would need to log in to their gmail, I felt sorry knowing it almost certainly won't work. It didn't. Thankfully Facebook worked.
- rch 4y agoIt seems to me that the government service responsible for providing the phone should be expanded to provide a permanent digital identity, including email, and a lasting phone number. A permanent address (open and scan, with selective forwarding) for physical mail would also be worth investigating.
- admax88qqq 4y agoAmazing that we let Telecoms become the arbiters of identity online.
- themagician 4y agoSolution: Don't use Gmail. There are many other (free) email providers. Not all require 2FA via SMS.
- karaterobot 4y agoI'll accept the downvotes, but I don't feel like optimizing for the subset of homeless people who regularly lose their phones and their recovery codes is a good use of resources. I'd change my mind if someone could cite reliable sources that say this is actually a large community that Google as a corporation should really be paying more attention to, but just this one guy on Twitter is not enough for me.
- 867-5309 4y agomaybe just.. don't use gmail? if it happens twice then that should tell them something
- tobyhinloopen 4y ago“Unhoused people”?
- kweingar 4y agoThe USPS should operate a free public email service and provide support at every post office. The government has the resources to navigate complex situations that digital safeguards can’t. If someone has no paperwork, lost the device they made their account with, and cannot remember a password they made—no tech company has the resources or expertise to handle this at scale as well as local institutions can. If someone needs to take over an account of a loved one that they have legal guardianship of, you don’t want a support agent at a call center to make these decisions.
- matthewcford 4y agoN26 I see (as my phone died and needed to setup a new one) uses facial recognition to determine identity, you take a selfie video when signing up. IMO this approach would be a good way to confirm identity over a sms.
- crooked-v 4y agoPersonally, I find it particularly infuriating that more and more companies are demanding to use phone-based 2FA even when I already have 2FA authentication set up. This applies to Google, too, which has forced me to add a phone number and get a SMS 2FA code for accounts that already had non-SMS 2FA configured. The whole reason I use an authenticator app is so that my accounts aren't dependent on having the same phone number forever!
- Liquix 4y agoBeing strongarmed into giving up your phone number is as much "for your security" as manifest v3 is "for your privacy". They could care less that you have 2FA enabled, they want that phone number. Many people never change their numbers and enter them into hundreds of sites, creating a wealth of data which can then be profitably correlated with your email content, google account activity, searches, location, etc.
- gerash 4y agoI'm sure you won't blame it on the "big bad tech" once you drop your phone in the pool and lose access to your accounts because they never asked you to create an SMS backup
- crooked-v 4y agoI already have my own backups. Chaining me to a specific phone number on top of that isn't a backup, it's a liability.
- krick 4y agoI don't even know what this has to do with the homeless. I don't want ANY of my internet accounts to depend on my phone (which I can lose, and I just don't want it to be a big deal) or, worst of all on "my" phone number, which IS NOT, never was and never will be controlled by me — but by my cellphone operator. Who isn't my friend. Both problems seem to be so obvious, that I don't see how pointing out (also rather obvious thing) — that life out there on the streets is a bit different than in your [home-sized] cubicles — can help. And since it's always more productive to assume malice, not stupidity — obviously, this is the point. Somebody wants you to depend on your phone number, something you don't really control and cannot easily change. This isn't about comfort and security, it never was. What else is new. But, I mean, if I have to pretend that it's not about me, but about homeless people for something to be changed — I guess I'm homeless' rights supporter #1 from now on.
- ineedasername 4y agoJust one more way in which being on a lower rung of the socioeconomic ladder is a self-reinforcing situation. In this case it’s not even a criticism of Google. I don’t see an easy solution here that couldn’t introduce a more gameable system for hackers.
- Slow_Hand 4y agoPerhaps an opt-out version for homeless users?
- bsimpson 4y agoTicketmaster started requiring 2FA, but they only allow phone numbers connected to a SIM card. For over a decade, I've been using my Google Voice number as my identity, with whatever number is on whatever SIM I happen to have at the time being an implementation detail. Ticketmaster doesn't accept that, so now I have to schlep myself over to the venue (which often includes a bridge toll) to buy tickets at the box office. It's infuriating. I believe Credit Karma Tax also had this problem, which is moot now that Square owns it (since Square doesn't have this problem).
- lucasyvas 4y agoAs someone who uses 2FA extensively and even has 1Password autofill the OTP codes - 2FA is objectively fucking brutal. Half of you in here have never met a non-technical user. These folks should not have 2FA on ever, because they can't even use the damn thing with it on. Yes, those users run a higher risk and should be notified of that extremely clearly. But 2FA is a garbage solution to the problem and it should always be possible to disable it. I'm going to continue using 2FA happily like most of those in here - but man the lack of empathy is outstanding in here. I feel bad for your users. And fuck Discord for not allowing me to reset my account with my own damn email address when my phone broke that one time. Total morons, through and through. I'd never want to work with anyone so objectively ignorant and unwilling to admit their ass backwards position.
- intrasight 4y ago>because they can't even use the damn thing with it on Trump for example. Which is why his account was regularly hacked.
- parkingrift 4y agoOh please. Every business I’ve ever worked for has enforced MFA for corporate access. You’re acting as if “non technical users” are illiterate subhuman morons. Even my 90 year old grandparents trivially figured it out on their own.
- lucasyvas 4y agoI'm claiming the reverse - the human ones are the normal people who just want to use email without it berating them every time they log in. Then your grandparents are technical users. Curiously, so are mine. Sorry to tell you that you're wrong though and you have not met the non-technical users. I've had to try to help my aunt and uncle recover old Apple and Google accounts with complete failure because they've changed cell phone providers and didn't care that their phone numbers changed. At no point are they adequately warned this is the case, and recovery codes are a confusing additional layer that they don't understand. So they basically lose everything and nobody is willing to help them. You are making a grand assumption about accessibility - not everyone has the capability to grok such a convoluted login process. The non-technical users often aren't morons - they are just differently abled. Maybe they are immigrants who didn't grow up with computers much because they were poor, or have a mental condition. 2FA fails spectacularly on accessibility. Your reply is an example of the problem - completely oblivious to the users that are horribly underserved by 2FA as it exists.
- gerash 4y agoside question from the tweet: is "unhoused" the politically correct version of "homeless"? How is it any better?
- fareesh 4y agoYes and the other new terminology is "persons experiencing homelessness" It's all so tiresome honestly. One of the absolute worst things about western culture is the apparent creeping obsession with political correctness that has been escalating for the past few decades. If only more westerners were like the great George Carlin. Grateful for once to live in the third world.
- stavros 4y agoWhy can't they use Fastmail? It's as if Gmail is the only email provider any more.
- e9 4y agoBy definition homeless person doesn’t have much money and most likely no credit card or bank account. Who and how they are going to pay for fastmail?
- deleted 4y ago[deleted]
- intrasight 4y ago2FA needs to be implemented in a more human-friendly manner. Apple does better with their "friend or family member" account recovery. 2FA needs to be something you know not something you have. Or at least needs to support that. Yes, this would be a problem for someone who doesn't know someone to be their backup. But that's a real edge case.
- obamaphoneuser 4y agoThere is a very simple flaw in the "Obamaphone" system that is the root cause of this catch-22 dilemma. I was homeless and had to use an Obamaphone, so I saw first hand how this flaw works. My solution to this problem was simple: don't use Google. Use Yandex instead because they never require a phone for 2FA and they allow you to set your own custom security questions for account recovery as well as link a backup email account to reset your password. It would be trivial for Google to have these features too, but they won't because this is about spying and tracking and controlling users by forcing everyone to use a SIM card. The Federal Govt doesn't "give" you a free phone. Cellular carriers give you the phone and the service when you sign up at one of their kiosks usually setup outside local Govt offices that provide services to the homeless. Like the food stamps office. So you sign up witg T-Mobile or Verizon or smaller carriers nobody has heard of and you get your cheapo off-brand phone with low specs like 1GB of RAM and 3GB of cellular data per month. Great, that is an amazing way to help the homeless since doing everything requires a cell phone now. But when you sign up, the carriers require you to provide a cirrebtly valid food stamps EBT card and a govt ID like a drivers license with your mailing address on it. They mail a form to that address within 60 days that you must sign and mail back to them to prove you are who you claim to be. I guess this is for fraud detection. But if you are homeless, then obviously you will never be able to receive that form in the mail to prove you are who you claim to be. Then after 90 days if you have not returned your form in the mail, your free phone service is terminated. You can immediately go and get a new Obamaphone, but you will have a new number and a new account. There is no way to port your old number because each carrier has totally separate systems to store your account. This whole Obamaphone program is extremely wasteful because it is intended to help the homeless, but it is implemented to force the homeless to constantly churn through getting new phones every 90 days. I went through several different Obamaphones because of this. Typical Big Govt inefficiency I guess. It is too bad that Google is so obsessed with spying on people and blibdly trusting SIM cards because you can still use Wifi on an Obamaphone that has been deactivated for cellular service. I don't know why Google refuses to base 2FA on something other than a SIM card. They already control the hardware through Android, so the phone hardware IMEI ID itself should be able to be used as a unique identifier. Unmoored, trillion dollar megacorporations on autopilot like Google who are managed by multimillionaires Executives living in Silicon Valley and who are staffed by millionaire developers designing these systems of global information control do not think of the use case needs of the poorest, disadvantaged users who fall through the cracks.
- Beltalowda 4y agoI very explicitly do not have 2FA enabled on my email account, and it's also the only account that's not a random password from my password manager but rather a (very) strong password I memorized. Maybe my house will get burgled, maybe I will lose all my stuff in travel, or a fire, or ... I don't know. Email is kind of the key to everything, which makes 2FA important, but can also a huge pain in all sorts of exceptional situations, and losing access to your email often means losing access to lots of other stuff, too. I feel account access is still an unsolved problem; 2FA is a meh stop-gap solution at best with lots of trade-offs. Ideally your account should be tied to your identity (e.g. passport or the like) in a privacy-secure manner.
- aasasd 4y ago> unhoused people face extreme challenges when it comes to retaining physical items. Reminds me of a case in Moscow (iirc): a homeless guy bought a gym pass that came with a locker, and was storing his things in said locker. The gym administration decided to deny him this arrangement, but he sued them and the court said “since the locker is in the contract, it's his privilege now”.
- ezoe 4y agoIt's 2022, why are we still using phone number?
- wheresvic5 4y agoWhy not make 2FA opt-out? This would work for most cases or am I missing something?
- afiori 4y agoNo you are not missing anything in my opinion. The reason this is not offered (IMHO) is that a lot the use (on the users side) of 2FA is from people that want better security, while a lot of the push (on the developer side) for 2FA is from people that would like to see the use of passwords almost disappear.