Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

51–60 of 484 posts

Re: Librarian's Letter to Google Security

#51
Yeah, Google just doesn't give a shit.

I was a gmail user since gmail was in private beta 18 years ago. I never had a phone number associated with it. And yet two or three years ago when I tried to log in Google decided to just... not let me do that, because fuck you, and started extorting me to give it a phone number. If I don't give it a valid phone number it won't let me access my email. But I can't really do that because, you see, I don't actually own a phone number.

So now I'm essentially locked out of my almost two decades old email account, for no good reason whatsoever except the fact that Google is a bully. Fortunately I've long since migrated to another email address on my own domain as my main address, so it doesn't really matter.

Do not depend on any Google-provided service. They don't care about you, and they will screw you over sooner or later. You're just a number to them. Most importantly, pay for any critical service you need (like email). Do not wait until it's too late. Do it NOW.

Re: Librarian's Letter to Google Security

#52
The best solution I can think of that doesn't compromise security is hardware keys. GMail has very good FIDO support. The keys are easier to use than TOTP and vastly more secure than SMS. They do not depend on any phone or phone service, and there is no transferring necessary at any time.

The librarian would just need to get the person logged in successfully one time, get the key attached to the person's account, and get the key onto the person's physical keychain. The librarian would also print out the backup codes, laminate them, and put them in the person's wallet. Once that's done, this particular library patron should have few authentication issues going forward. Assuming lots of repeat clientele, the auth night mare will largely end once everyone is setup.

Yeah, the key and codes might get lost, broken, or stolen, but that's the best you can do. If the person lost their actual keys and wallet, they've got bigger problems.

The question really is who is going to pay for these keys? They're a lot cheaper than phones at least, but not cheap enough.

Re: Librarian's Letter to Google Security

#53

Someone needs to tell this librarian Google has 2FA backup codes you can just write on a piece of paper.

Does your grandma have printed out backup codes?

My grandma just creates a new google account whenever she gets locked out and it doesn't matter because she doesn't use email for anything important.

I'm starting to wonder if she's the smarter one.

Re: Librarian's Letter to Google Security

#54
This is one of those situations that make it incredibly clear that even Google, with all its resources, never considers the use case or life experience of anyone besides a wealthy Bay Area tech worker when designing their products. I can't help but wonder how this blind spot got so big - and why they still don't address things like this even with all the user testing & A/B trials they do for ruthless optimization. Is it just because usability has no correlation with profit, and so the feedback loop is broken?

Re: Librarian's Letter to Google Security

#55
I've been saying for a while now that the big tech companies have a strong desire to embed themselves into all our lives, and become a central part of our lives: but the all seem to forget that "with great power comes great responsibility" and none of them want to provide the level of support required to prevent people losing everything important in their life due to a stupid technical problem.

It's well overdue time they realised that if you want to be the sole way people communicate with each other, pay their bills, communicate with the government, and hold cherished memories, that they have a strong responsibility to provide a very strong level of support to prevent people from losing their entire online identity - and thus their entire offline identity as well.

Re: Librarian's Letter to Google Security

#56
post #48

I wish that Shelley had co-written this letter with either a tech employee or a more tech-focused librarian. The problem that she mentions is real: I've worked in her position and can confirm. But the way the letter is written makes it clear that she's not very familiar with the tech industry or how things are developed. If I were a Google engineer, this would read like one of dozens of pleas we get constantly to cha…

yikes. old poor people are having their lives upended because technology has infiltrated the processes by which basic business is conducted and the designers of said technology had not bothered to consider them as a real use case, and your response is "she's not asking nicely enough."

yikes*10000. cringe^inf.

Re: Librarian's Letter to Google Security

#57
post #21

Another solution to this problem would be competition. If there were a workable alternative to Gmail that had account recovery mechanisms better suited for this population than the librarian could simply recommend that for their patrons. Can anyone suggest what a good alternative to Gmail would be for this population?

Outlook.com/Hotmail.com?

Hotmail once deleted all my emails because I hadn't logged in through the web interface for 30 days, instead used another client. Then one day I got a weird message and logged into the web interface to find all my emails from more than a decade gone.

Re: Librarian's Letter to Google Security

#58

Why is the US so far behind the rest of the world when it comes to technology? State IDs/Driving Licenses already exist. These should have chips on them that could be used for authentication.

Getting an ID in the US is more difficult than this account recovery procedure that the letter complains about.

Re: Librarian's Letter to Google Security

#60
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

Why would Google want to do this? Current 2FA suits its role perfectly: it prevents a large scale leak, one that would result in bad PR. There is no incentive for Google to care for individual users.
Post reply on HN