Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

91–100 of 484 posts

Re: Librarian's Letter to Google Security

#91
post #54

This is one of those situations that make it incredibly clear that even Google, with all its resources, never considers the use case or life experience of anyone besides a wealthy Bay Area tech worker when designing their products. I can't help but wonder how this blind spot got so big - and why they still don't address things like this even with all the user testing & A/B trials they do for ruthless optimization. Is…

So how does your company handle these cases while defending against social engineering attacks to steal all private data?

The security wisdom I've always seen was to use 2FA and prevent other attempts at authentication, but if Google is evil for doing this security... what's the answer?

Re: Librarian's Letter to Google Security

#92

Yeah, Google just doesn't give a shit. I was a gmail user since gmail was in private beta 18 years ago. I never had a phone number associated with it. And yet two or three years ago when I tried to log in Google decided to just... not let me do that, because fuck you, and started extorting me to give it a phone number. If I don't give it a valid phone number it won't let me access my email. But I can't really do that…

I also have it since beta -- and no phone associated.

Re: Librarian's Letter to Google Security

#94
>> There simply must be a way to change how Google handles two-factor authentication which does not constantly lock out poor people who use the public library to access their email. It must be possible to make it so we do not constantly reach these dead-ends where Google tells patrons to endlessly loop through “I don’t have my phone” and “Try another way” until their account becomes locked permanently due to too many failed attempts.

Why is Google making it hard for the poor to access their email in these times?

it’s not like google just launched today. They have the data of these users, who use internet from public libraries.

Re: Librarian's Letter to Google Security

#95
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

It’s an absolutely catastrophic experience, that they clearly don’t take seriously.

Regulation solves this. I hate to say that, as so much of tech regulation is a ham-fisted disaster that misunderstands the problem and creates even bigger ones, but this is really a very serious problem that can ruin lives, and regulators really should step in here.

I’ve known a couple of people who have been through this experience, and one in particular who not only couldn’t get back in to their account - but had no way of knowing if someone else was able to get in to the account later. They’ll never know. It will never be possible to know. The kicker is that they could never have their data deleted due to the same problem. And no amount of help or time spent with chat support ever changed anything.

Re: Librarian's Letter to Google Security

#96
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

> trusted civic authorities They'll need to be resistant to threats and bribes, so it will be difficult to have these on-site at the library. I think we've overlooked an option. Note that the article's objection to FIDO keys was financial, not UX. This sort of confirms the hunch I got when first playing with them: "hey, the key metaphor is so strong and intuitive that these might be even better than passwords for peo…

It is not uncommon for unhoused people to lose all their possessions, so even if purchasing multiple hardware security keys wasn't a huge financial hurdle, the recovery model I use (Yubikey on my keychain, two in my safe, mail one to my parents) falls apart for those on the margins of society. If email is an essential service in modern society, recovering access to it from some first principle of identity is essential. I don't have an easy answer for how to do that, but I also don't have a trillion dollar market cap.

Re: Librarian's Letter to Google Security

#97
post #88
post #18

Earlier quoted context omitted.

I agree with your suggestion. I think Post Offices, DMVs, and large reputable retailers (Walmart, Target, Cellular Phone companies, etc.) could verify our identities for a small fee and help us reset our social accounts when needed. I arrived at the same conclusion and wrote a blog post about it a few years ago: https://www.go350.com/posts/now-they-have-2fa-problems/

I distinctly remember lynching from HN security crowd when SIM cards were being unlocked and moved to new people from "trusted companies" like Verizon and AT&T. HN demanded for such security holes to be disabled and prevented - what changed since then?

What changed is that we're starting to learn about the breadth of needs by people with different lives and opportunity sets, and feel at least a desire to talk through potential solutions for a subset of people who opt into it.

If the worst thing that people could commit in this discussion is hypocrisy, I'm sure they're willing to step over that line.

Re: Librarian's Letter to Google Security

#100
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

Library op-sec is pretty weak IME. Mine accepted seeing an email of a utility bill on my phone. Which is probably fine for just checking out books. I still love libraries and the services they provide. But wouldn't want them to be an arbiter of identity any more than a faceless, human hostile corporation.

It's supposed to be easy to get a library card! The threat of an out-of-towner getting a local library card is nothing like a stranger getting access to your inbox.
Post reply on HN