Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

11–20 of 484 posts

Re: Librarian's Letter to Google Security

#11

On one hand, you have the perspective of this and other librarians where users are locked out of their accounts by Google in a (debatable) measure to secure them. On the other hand, you have the perspective of computer repair people who routinely field calls and service computers due to the elderly (mostly, but also everyone, including tech literate folks) getting scammed, account takeovers, downloading malware, and…

Better that elderly folks stuck at home should be shut out of major activities of life?

Re: Librarian's Letter to Google Security

#12

On one hand, you have the perspective of this and other librarians where users are locked out of their accounts by Google in a (debatable) measure to secure them. On the other hand, you have the perspective of computer repair people who routinely field calls and service computers due to the elderly (mostly, but also everyone, including tech literate folks) getting scammed, account takeovers, downloading malware, and…

It’s an impossible situation. Account security reset processes are the number one target for most account takeovers.

Re: Librarian's Letter to Google Security

#15
post #7

Someone needs to tell this librarian Google has 2FA backup codes you can just write on a piece of paper.

I used to work as a librarian and ran into the issues the author writes about. Less than she did - but it being a community that skewed older I have plenty of experience shepparding older and/or low income individuals through basic online tasks such as applying for unemployment etc. If you have never done this kind of work then it is very easy to take for granted how low the baseline technology competency of certain…

To give a sense of the level of tech literacy samsa is talking about, I've had to teach multiple people how to use a mouse and keyboard + had to explain to dozens of people that the icon called 'Internet' on the library computer will let them go to Facebook just like the 'Internet Explorer' icon at home or the 'Facebook' app will.

Re: Librarian's Letter to Google Security

#16
post #9

I got locked out of various MFA sites when I got a new device and had to redownload my Authenticator app it wasn’t linking to the accounts anymore and I could not get in. It became a chicken and the egg problem. Eventually going through support channels for each site I was locked out of I was able to get back in but it was a giant headache. I vaguely remember someone posting about a hypothetical scenario where their…

>I vaguely remember someone posting about a hypothetical scenario

This one? "I've locked myself out of my digital life": https://news.ycombinator.com/item?id=31652650

Re: Librarian's Letter to Google Security

#18
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

I agree with your suggestion. I think Post Offices, DMVs, and large reputable retailers (Walmart, Target, Cellular Phone companies, etc.) could verify our identities for a small fee and help us reset our social accounts when needed. I arrived at the same conclusion and wrote a blog post about it a few years ago:

https://www.go350.com/posts/now-they-have-2fa-problems/

Re: Librarian's Letter to Google Security

#19
i suspect that basic digital identity and messaging services will eventually be operated by governments. similar to how many major urban transportation systems were adopted and then glued together to provide subsidized public services.

Re: Librarian's Letter to Google Security

#20
Weird to blame Google for the government's refusal to provide basic services like telephony to its residents. Why doesn't the library provide a SIM with every library card, and store it at the front desk?

Or, you know, an email account with its own security policies? I got my first ever Unix shell account from a library.

Post reply on HN