Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

71–80 of 484 posts

Re: Librarian's Letter to Google Security

#71
I suspect that this is yet another situation where public libraries are going to have to step up to the plate and provide services to fill in the gap. In this case, it would be email services to patrons.

The Googles of the world exist because they provide inexpensive services through automation and at scale. They are poorly positioned to provide services that cannot be automated at scale. Chances are that any attempt to do so would likely bankrupt them even though we are talking about extremely wealthy corporations. (Keep in mind that we only hear of a fraction of the complaints about Google. Few people have the reach or ability to have their voices heard.)

On the other hand, libraries are already embedded in the community. They already have personnel who can better understand and respond to situations that Google would regard as edge cases. They are also much smaller organizations that have less bureaucracy to deal with and a mission that aligns with the needs of the community.

I am not saying that they have to provide the actual email servers. They could contract that out, perhaps even to Google (though I suspect they would try to find another organization). They would be managing the email accounts themselves, including authentication and recovery.

Re: Librarian's Letter to Google Security

#72
post #43

Perhaps the solution is for libraries or local authorities to setup their own email providers. An email address “for life” with your library card, with the necessary support and in-person reset verification that their patrons need. I’m not suggesting this would be an easy or inexpensive undertaking, but maybe that’s just the next step in service evolution for a public information service like a library group.

Indeed, but this will then going to face the issue of Gmail (et al.) refusing to accept e-mail sent from small providers.

Re: Librarian's Letter to Google Security

#73
post #52

The best solution I can think of that doesn't compromise security is hardware keys. GMail has very good FIDO support. The keys are easier to use than TOTP and vastly more secure than SMS. They do not depend on any phone or phone service, and there is no transferring necessary at any time. The librarian would just need to get the person logged in successfully one time, get the key attached to the person's account, and…

>>The keys are easier to use than TOTP

This has not been my experience, even for more knowledgeable people let alone normal users.

>> this particular library patron should have few authentication issues going forward

Until they lose or break the physical key, which will happen more often than losing or breaking their phone with the TOTP

Re: Librarian's Letter to Google Security

#74
post #48

I wish that Shelley had co-written this letter with either a tech employee or a more tech-focused librarian. The problem that she mentions is real: I've worked in her position and can confirm. But the way the letter is written makes it clear that she's not very familiar with the tech industry or how things are developed. If I were a Google engineer, this would read like one of dozens of pleas we get constantly to cha…

I strong disagree. This isn’t a tech issue, it’s a poorly delivered solution that didn’t consider the needs of the users. The solution is so poorly delivered librarians are an ad hoc support team for thousands of people.

Google in particular created a moral problem by choosing to implement a security solution that doesn’t serve people who depend on the services. They have the metrics to know better, but didn’t consider the use case.

I provide services to users in these use cases. It’s very possible to serve them in a way that is both secure and respectful to humans.

Re: Librarian's Letter to Google Security

#75
post #31
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

I think something like this could work iff the accounts were required to be set up by said civic authorities with confirmable paperwork. Otherwise, librarians are stuck awkwardly trying to decide if 'John Doe' really owns the email account 'ILoveButts64@gmail.com'. I also doubt this will ever happen since it would require more $$$ for things that are not profit generating and supports a population that is useless fro…

Or now that I think about it… for 2FA in particular, what about enrolling a software FIDO token with an extension on every library computer that can be triggered by a librarian from their desk? Doesn’t require hardware for each patron, only applies to accounts that have been enrolled at the library. Feels like it could work.

Re: Librarian's Letter to Google Security

#76
post #43

Perhaps the solution is for libraries or local authorities to setup their own email providers. An email address “for life” with your library card, with the necessary support and in-person reset verification that their patrons need. I’m not suggesting this would be an easy or inexpensive undertaking, but maybe that’s just the next step in service evolution for a public information service like a library group.

Indeed, but this will then going to face the issue of Gmail (et al.) refusing to accept e-mail sent from small providers.

I am sure a another huge vendor like Amazon, facebook, or Microsoft will step in to provide the email services :)

Re: Librarian's Letter to Google Security

#77
This is well meaning and shows an unfortunate side of 2f-auth, but she seems to think that google is in the business of helping people. They are in the business of selling ads. True their search engine has greatly helped a lot of people, as has gmail.

But they are in the business of selling ads, and they are not selling enough ads to people who both a) cannot continuously afford a phone number b) are unable to afford an internet connection at home to be worth dealing with the complaints, manual verification and prevent fraud.

Google is in the business of making money. You make very little money from poor people, and you lose money if they cost even more to service.

This does not mean that it doesn't suck for the homeless lady, but this is reality.

Re: Librarian's Letter to Google Security

#78
post #37
post #22

Earlier quoted context omitted.

This has been an issue for years. (I've worked in libraries, including public ones, on and off since 2004). It's not just a GOOG problem. In fact, Yahoo makes me want to show up and yell at some business people: They lock people out of their accounts and then CHARGE THEM TO CALL IN and fix it. Another general issue is how much of this population uses/sticks with old products: There is a large number of Yahoo, AOL, an…

Agreed on Yahoo and ISP emails being awful, but Microsoft migrated all the hotmail users over to Outlook years ago. At this point, there is only a cosmetic difference between a hotmail.com email and a outlook.com email. I'm normally not a big Microsoft fan, but that was one change they handled reasonably well.

Considering my experience with the migration and merging of various Microsoft accounts, I find this statement very surprising...

Re: Librarian's Letter to Google Security

#79
post #52

The best solution I can think of that doesn't compromise security is hardware keys. GMail has very good FIDO support. The keys are easier to use than TOTP and vastly more secure than SMS. They do not depend on any phone or phone service, and there is no transferring necessary at any time. The librarian would just need to get the person logged in successfully one time, get the key attached to the person's account, and…

Hardware keys work well in place of a phone, and are in some ways significantly more secure depending on how U2F is implemented.

Some of the problem remains: If the user forgets their password the second factor won’t help them, and that includes the backup keys.

I’ve read the letter, and I see the massive problem, but I don’t think it’s been fully solved yet.

Q: “How do we remotely authenticate a single user, in a way that cannot be forged, without relying on their memory?”

There are solutions to every part of that sentence, but I do not know of one that solves it entirely.

They could write their password down, but then they’re exposing themselves to the obvious risk of it being stolen. You could trust the librarian in a 2-of-3 system, but this seems very easy to abuse by the library staff.

Genuinely not sure of how this is solved.

A cryptographically-strong biometric key store at the library (e.g. finger-print or face scanner) that will only authenticate a physically present user and release a FIDO signature that could then be used in a multisig authentication?

Re: Librarian's Letter to Google Security

#80
post #66

So, what should Google do, here?

Have a Support line where people can call and verify their identity?

How would they verify their identity?

Those sorts of password reset systems are regularly bypassed by convincing scammers who have stolen some personal information.

Post reply on HN