Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

1–10 of 484 posts

Re: Librarian's Letter to Google Security

#5
On one hand, you have the perspective of this and other librarians where users are locked out of their accounts by Google in a (debatable) measure to secure them.

On the other hand, you have the perspective of computer repair people who routinely field calls and service computers due to the elderly (mostly, but also everyone, including tech literate folks) getting scammed, account takeovers, downloading malware, and worse!

So maybe the solution here is not to *force everyone and their literal grandma* to be using these machines for all of their business??

Re: Librarian's Letter to Google Security

#6

Someone needs to tell this librarian Google has 2FA backup codes you can just write on a piece of paper.

You do not need to enable 2FA to be affected by this issue, so IIRC it is possible you never received the 2FA backup codes to begin with. "Suspicious" logins will prompt 2FA from your connected phone.

Re: Librarian's Letter to Google Security

#7

Someone needs to tell this librarian Google has 2FA backup codes you can just write on a piece of paper.

I used to work as a librarian and ran into the issues the author writes about. Less than she did - but it being a community that skewed older I have plenty of experience shepparding older and/or low income individuals through basic online tasks such as applying for unemployment etc. If you have never done this kind of work then it is very easy to take for granted how low the baseline technology competency of certain folks is. Telling someone they will need a working phone number, a password, and recovery codes to access their email when "it used to just work" will simply not fly for them.

This side steps the issue that often these are scenarios where the patron is already locked out of their account and coming into a library as a last resort - so lecturing them on backup codes will be of no avail.

Re: Librarian's Letter to Google Security

#8
About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in DC.

One of the things which I was struck by was how unseriously they appeared to view their role in modern life. People were generally very casual about the need and were especially uninterested in anything which required them to work with outside parties.

My suggestion was that they consider a protocol where trusted civic authorities could be allowed to confirm someone's identity, which sounds like it would be useful for this case: let the person initiate a mediated reset flow where someone like a librarian, police officer, etc. could authenticate in their official capacity and check a box saying that they've confirmed the photo ID for the person standing in front of them. Most of the benefits from MFA are preventing things like phishing attacks which are also stymied by limiting it to people in your geographic area, although you might want to disable this for high-risk people enrolled in Google's Advanced Protection Program.

Re: Librarian's Letter to Google Security

#9
I got locked out of various MFA sites when I got a new device and had to redownload my Authenticator app it wasn’t linking to the accounts anymore and I could not get in. It became a chicken and the egg problem. Eventually going through support channels for each site I was locked out of I was able to get back in but it was a giant headache.

I vaguely remember someone posting about a hypothetical scenario where their house burnt down and they lost all their physical devices and couldn’t get into anything etc.

Re: Librarian's Letter to Google Security

#10
post #7

Someone needs to tell this librarian Google has 2FA backup codes you can just write on a piece of paper.

I used to work as a librarian and ran into the issues the author writes about. Less than she did - but it being a community that skewed older I have plenty of experience shepparding older and/or low income individuals through basic online tasks such as applying for unemployment etc. If you have never done this kind of work then it is very easy to take for granted how low the baseline technology competency of certain…

Obviously, it would be better if Google would do something, but they won’t. A temporary solution could be something like a sign that encourages people to print out backup codes and the librarian could help them with it. Maybe the librarians could even store them in a folder and retrieve with ID. Not saying these are good solutions, but they could maybe help a bit.
Post reply on HN