Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

21–30 of 484 posts

Re: Librarian's Letter to Google Security

#21
Another solution to this problem would be competition. If there were a workable alternative to Gmail that had account recovery mechanisms better suited for this population than the librarian could simply recommend that for their patrons.

Can anyone suggest what a good alternative to Gmail would be for this population?

Re: Librarian's Letter to Google Security

#22
post #13

It looks like the librarian's letter is from July 2021. So, the frustrated librarian raised this issue more than a year ago. Has GOOG done anything about it in the past year? There needs to be a better way.

This has been an issue for years. (I've worked in libraries, including public ones, on and off since 2004).

It's not just a GOOG problem. In fact, Yahoo makes me want to show up and yell at some business people: They lock people out of their accounts and then CHARGE THEM TO CALL IN and fix it. Another general issue is how much of this population uses/sticks with old products: There is a large number of Yahoo, AOL, and Hotmail addresses still being used, as well as old ISP mailboxes.

Re: Librarian's Letter to Google Security

#23
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

That sounds like a good idea! Perhaps expand what notaries do?

Re: Librarian's Letter to Google Security

#24

Someone needs to tell this librarian Google has 2FA backup codes you can just write on a piece of paper.

Google has basically made 2FA mandatory if you have set-up an Android phone, which doesn't even prompt to back up recovery codes.

And this is more likely to happen to the poor since they're going to have Lifeline Assistance phones, which are all shitty Android phones. (I had a couple and keep them as burners but they're crap.)

Re: Librarian's Letter to Google Security

#25
Great letter. Wanna bet it was completely ignored? Glad to see it here. Maybe it won't be ignored.

Librarians rock. There's even a show about them[0], Starring Number One.

I can't access the gMail account I set up, because I made a mistake, when setting the password, and did not save the one I used.

It will not allow me to access the account I set up.

After a while, I just gave up. I am satisfied that someone can't use my gMail address to impersonate me (because even I can't get it). I have plenty of other eMail accounts.

[0] https://www.imdb.com/title/tt3663490/

Re: Librarian's Letter to Google Security

#27
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

Library op-sec is pretty weak IME. Mine accepted seeing an email of a utility bill on my phone. Which is probably fine for just checking out books.

I still love libraries and the services they provide. But wouldn't want them to be an arbiter of identity any more than a faceless, human hostile corporation.

Re: Librarian's Letter to Google Security

#28
post #21

Another solution to this problem would be competition. If there were a workable alternative to Gmail that had account recovery mechanisms better suited for this population than the librarian could simply recommend that for their patrons. Can anyone suggest what a good alternative to Gmail would be for this population?

Outlook.com/Hotmail.com?

Re: Librarian's Letter to Google Security

#29
post #21

Another solution to this problem would be competition. If there were a workable alternative to Gmail that had account recovery mechanisms better suited for this population than the librarian could simply recommend that for their patrons. Can anyone suggest what a good alternative to Gmail would be for this population?

[deleted]
Post reply on HN