Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

31–40 of 484 posts

Re: Librarian's Letter to Google Security

#31
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

I think something like this could work iff the accounts were required to be set up by said civic authorities with confirmable paperwork. Otherwise, librarians are stuck awkwardly trying to decide if 'John Doe' really owns the email account 'ILoveButts64@gmail.com'.

I also doubt this will ever happen since it would require more $$$ for things that are not profit generating and supports a population that is useless from the tech companies' POV.

Re: Librarian's Letter to Google Security

#34

Someone needs to tell this librarian Google has 2FA backup codes you can just write on a piece of paper.

Something that I don’t think has been mentioned yet is that Google requires a phone number attached to every account (not just a 2FA method). This is to prevent scammers from making an infinite number of Gmail accounts. (With a max of 5 accounts per phone number if I remember correctly.) This means that people without phones are unable to even set up an email account—backup code or not.

Re: Librarian's Letter to Google Security

#35

Someone needs to tell this librarian Google has 2FA backup codes you can just write on a piece of paper.

Does your grandma have printed out backup codes?

My father was a statistician and programmer for most of his career. He's switched to a new gmail account three times, at least, when he couldn't remember a password.

So, no, nobody has printouts of backup codes except the people who are already aware of Google's reliability problem.

Re: Librarian's Letter to Google Security

#37
post #22
post #13

It looks like the librarian's letter is from July 2021. So, the frustrated librarian raised this issue more than a year ago. Has GOOG done anything about it in the past year? There needs to be a better way.

This has been an issue for years. (I've worked in libraries, including public ones, on and off since 2004). It's not just a GOOG problem. In fact, Yahoo makes me want to show up and yell at some business people: They lock people out of their accounts and then CHARGE THEM TO CALL IN and fix it. Another general issue is how much of this population uses/sticks with old products: There is a large number of Yahoo, AOL, an…

Agreed on Yahoo and ISP emails being awful, but Microsoft migrated all the hotmail users over to Outlook years ago. At this point, there is only a cosmetic difference between a hotmail.com email and a outlook.com email. I'm normally not a big Microsoft fan, but that was one change they handled reasonably well.

Re: Librarian's Letter to Google Security

#38
post #23
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

That sounds like a good idea! Perhaps expand what notaries do?

It sounds nice. if everyone plays nice. Slip some underpaid gov worker a 50 and suddenly you are someone else. There would need to be abuse provisions put in place. Then a whole org around that too. Not saying it can not be done, but it looks like to me is Google has a poor customer service issue, even if not true. Roping our govs into doing googles customer service seems odd.
Post reply on HN