Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

41–50 of 484 posts

Re: Librarian's Letter to Google Security

#43
Perhaps the solution is for libraries or local authorities to setup their own email providers. An email address “for life” with your library card, with the necessary support and in-person reset verification that their patrons need. I’m not suggesting this would be an easy or inexpensive undertaking, but maybe that’s just the next step in service evolution for a public information service like a library group.

Re: Librarian's Letter to Google Security

#45
I hate, hate, hate how so many web services have started to force 2fa on us. I have many accounts that I don't care that much about and I use bitwarden so it is extremely unlikely that I will get hacked and if I do I don't really care. Still, they force me to open my email account every time I log in because my cookies or ip address do not match my last login so I can input a stupid code. Big offenders in this regard are google, amazon, twitch, outlook, twitter (rarely). I know 2fa exists. If I don't enable it it is because I don't want to.

Re: Librarian's Letter to Google Security

#46
post #33

Can the library set up Google authenticator codes for all of their emails and look after the authenticator codes on behalf of their users? Or is SMS the only possible second factor authentication method?

No. This suggestion is, I'm sorry, utterly ridiculous. Even if it were possible---which it isn't due to the fact that many patrons have their emails long before they come to the library---but it would amount to get another public subsidy of a private mega corporation in the way of free tech support and data storage. Not to mention the security concerns, though to be honest I think that's secondary in the face of losing access to housing and benefits.

Re: Librarian's Letter to Google Security

#48
I wish that Shelley had co-written this letter with either a tech employee or a more tech-focused librarian. The problem that she mentions is real: I've worked in her position and can confirm. But the way the letter is written makes it clear that she's not very familiar with the tech industry or how things are developed.

If I were a Google engineer, this would read like one of dozens of pleas we get constantly to change X, Y, or Z for some small portion of the served population. And software devs in general find those demands annoying, particularly given some of the language that Shelley uses.

I think this would have gotten more reach and been better received if Shelley had a co-writer that acknowledged the reasons for 2FA from a security standpoint and emphasized the trade-offs that are being made + suggest other security measures. Likewise, having someone with a better understanding of tech would mean being able to do things like present some solutions that don't amount to "Oh most magic of Google Oracles, please fix this." Also the suggestion that they could contact her to learn about where patrons get stuck made me cringe slightly.

Basically, there's a misaimed moralizing tone throughout the letter that I think is at odds with its stated purpose, and it could have been written better, but the problem is real.

Re: Librarian's Letter to Google Security

#50
post #37
post #22

Earlier quoted context omitted.

This has been an issue for years. (I've worked in libraries, including public ones, on and off since 2004). It's not just a GOOG problem. In fact, Yahoo makes me want to show up and yell at some business people: They lock people out of their accounts and then CHARGE THEM TO CALL IN and fix it. Another general issue is how much of this population uses/sticks with old products: There is a large number of Yahoo, AOL, an…

Agreed on Yahoo and ISP emails being awful, but Microsoft migrated all the hotmail users over to Outlook years ago. At this point, there is only a cosmetic difference between a hotmail.com email and a outlook.com email. I'm normally not a big Microsoft fan, but that was one change they handled reasonably well.

Oh yeah, it was just an example of how this population stays with familiar products far beyond their usual lifespan. So they often want support for products and services that are old or unsupported. And why changes really screw them over: A lot of these people just have GMail accounts from when they were easier to use.

MS did well on this one, I agree. (And I also hate MS but credit where credit is due.)

Post reply on HN