Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

81–90 of 484 posts

Re: Librarian's Letter to Google Security

#81
post #52

The best solution I can think of that doesn't compromise security is hardware keys. GMail has very good FIDO support. The keys are easier to use than TOTP and vastly more secure than SMS. They do not depend on any phone or phone service, and there is no transferring necessary at any time. The librarian would just need to get the person logged in successfully one time, get the key attached to the person's account, and…

Reading this comment, I thought Yubikeys, which aren't /expensive/, but aren't cheap either. I was pleased to see they have a key targeted at this specific use case now - the Security Key Series [0]. At $25, that is not too bad a price, and something I'd buy for the members of my family without much hesitation. The hangup with this, which I think the librarian in question will feel, is what happens when someone loses…

I believe you can set up multiple keys. In this manner, a librarian could keep a "master key."

This compromises security somewhat, since the library houses one of the second factors, but IMO it's preferable to total account lockout (and still superior to SMS verification).

Re: Librarian's Letter to Google Security

#82
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

Lots of services are available to opt-in to validate identity. In fact, Google sells solutions on the cloud side.

Re: Librarian's Letter to Google Security

#83
post #59

Ehm, don't use Gmail then? I know I know, they're Americans...

It's not like most people will know they might lose everything if they sign up with google. Most rightfully expect that google, like most other companies, has customer service. By the time they realize, they're too late

We need to start seriously spreading the word that Google cannot be trusted to hold anything important to you

Re: Librarian's Letter to Google Security

#84

So, what should Google do, here?

Google employs the smartest minds on the planet and also have full insight on how Google works and what tools they have, so it shouldn't be hard for them to come up with a viable solution I believe.

HackerNews is a collection of brightest minds of software engineering who all know better than incompetent Googlers. So asking for how the brightest and bestest of HN engineers handle these security cases is educational for everyone.

Re: Librarian's Letter to Google Security

#85

Why is the US so far behind the rest of the world when it comes to technology? State IDs/Driving Licenses already exist. These should have chips on them that could be used for authentication.

Making these (and especially electronic ones) mandatory is a baaad idea :

Re: Librarian's Letter to Google Security

#86
post #60
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

Why would Google want to do this? Current 2FA suits its role perfectly: it prevents a large scale leak, one that would result in bad PR. There is no incentive for Google to care for individual users.

The government is slowly figuring out digital ID and will show up to regulate it.

Identity is too critical a business for services companies like Google to walk away from. It’s stupid, because once the camel gets it’s nose in the tent, it will cost them more.

Re: Librarian's Letter to Google Security

#87
post #52

The best solution I can think of that doesn't compromise security is hardware keys. GMail has very good FIDO support. The keys are easier to use than TOTP and vastly more secure than SMS. They do not depend on any phone or phone service, and there is no transferring necessary at any time. The librarian would just need to get the person logged in successfully one time, get the key attached to the person's account, and…

TFA mentions YubiKeys, and acknowledges that they would work, but that the barrier is paying for 450k of them.

Re: Librarian's Letter to Google Security

#88
post #18
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

I agree with your suggestion. I think Post Offices, DMVs, and large reputable retailers (Walmart, Target, Cellular Phone companies, etc.) could verify our identities for a small fee and help us reset our social accounts when needed. I arrived at the same conclusion and wrote a blog post about it a few years ago: https://www.go350.com/posts/now-they-have-2fa-problems/

I distinctly remember lynching from HN security crowd when SIM cards were being unlocked and moved to new people from "trusted companies" like Verizon and AT&T.

HN demanded for such security holes to be disabled and prevented - what changed since then?

Re: Librarian's Letter to Google Security

#89
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

Library op-sec is pretty weak IME. Mine accepted seeing an email of a utility bill on my phone. Which is probably fine for just checking out books. I still love libraries and the services they provide. But wouldn't want them to be an arbiter of identity any more than a faceless, human hostile corporation.

I wonder if that's deliberate. My bank also accepted an email utility bill but they said they only ask for the utility bill to prove that you didn't make a careless mistake when entering your address.

Re: Librarian's Letter to Google Security

#90
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

Library op-sec is pretty weak IME. Mine accepted seeing an email of a utility bill on my phone. Which is probably fine for just checking out books. I still love libraries and the services they provide. But wouldn't want them to be an arbiter of identity any more than a faceless, human hostile corporation.

> Mine accepted seeing an email of a utility bill on my phone.

To be fair, tons of places use those as proof of residence. It’s not as if it makes a real difference if you print them first.

Post reply on HN