Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

111–120 of 484 posts

Re: Librarian's Letter to Google Security

#111

Great letter. Wanna bet it was completely ignored? Glad to see it here. Maybe it won't be ignored. Librarians rock. There's even a show about them[0], Starring Number One. I can't access the gMail account I set up, because I made a mistake, when setting the password, and did not save the one I used. It will not allow me to access the account I set up. After a while, I just gave up. I am satisfied that someone can't u…

> Wanna bet it was completely ignored?

I just tweeted it to @Google. Maybe if enough people ping Google about it?

Re: Librarian's Letter to Google Security

#112

So, what should Google do, here?

Google employs the smartest minds on the planet and also have full insight on how Google works and what tools they have, so it shouldn't be hard for them to come up with a viable solution I believe.

The problem is almost impossible to solve. When a person has forgotten their password, lost their device and doesn't have 2fa recovery codes in hand or a recovery account set up, there is no way verify the identity of the user. Real-world identity is not linked with the account, since many goverments don't provide an online identity service (and even if they did, the people in question probably wouldn't have digital IDs either). Moreover, any manual processing is prohibitively expensive and vulnerable to social engineering attacks.

Re: Librarian's Letter to Google Security

#113

Great letter. Wanna bet it was completely ignored? Glad to see it here. Maybe it won't be ignored. Librarians rock. There's even a show about them[0], Starring Number One. I can't access the gMail account I set up, because I made a mistake, when setting the password, and did not save the one I used. It will not allow me to access the account I set up. After a while, I just gave up. I am satisfied that someone can't u…

> Wanna bet it was completely ignored?

Well, looking at the date...

> "Today, July 19th 2021"

Re: Librarian's Letter to Google Security

#114

Why is the US so far behind the rest of the world when it comes to technology? State IDs/Driving Licenses already exist. These should have chips on them that could be used for authentication.

Making these (and especially electronic ones) mandatory is a baaad idea :

I used to feel the same. But in reality, we prove our identity daily - every credit card transaction, banking, electronic tolling, bill payment, health care visit, tax payment, legal proceeding, employment opportunity, voter registration …

What protects us from invasive search is not lack of a uniformly accessible system for identification - its due process. And if the government chooses to compel you against your will and without due process - whether or not you have a laminated ID in your pocket will be irrelevant.

Re: Librarian's Letter to Google Security

#115
post #54

This is one of those situations that make it incredibly clear that even Google, with all its resources, never considers the use case or life experience of anyone besides a wealthy Bay Area tech worker when designing their products. I can't help but wonder how this blind spot got so big - and why they still don't address things like this even with all the user testing & A/B trials they do for ruthless optimization. Is…

[deleted]

Re: Librarian's Letter to Google Security

#116
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

In EU (Italy) there is eIDAS (SPID) that could allow this. It is essentially a national SSO.

Today it requires almost always a Android/iOS phone AFAIK, but it could easily be massaged to solve this problem.

The system is set up so that your account is owned by the state, and you can register with documents to providers; then after certification they run the actual SSO process.

A library provider could set up a computer that automatically passes the SSO login for your national account after certificating your identity.

Honestly this feels a bit too open to social engineering attacks, but probably there is a good middle ground.

Edit: Maybe in the US this is already almost possible by extending something like https://en.m.wikipedia.org/wiki/FIPS_201

Re: Librarian's Letter to Google Security

#117

Earlier quoted context omitted.

Reading this comment, I thought Yubikeys, which aren't /expensive/, but aren't cheap either. I was pleased to see they have a key targeted at this specific use case now - the Security Key Series [0]. At $25, that is not too bad a price, and something I'd buy for the members of my family without much hesitation. The hangup with this, which I think the librarian in question will feel, is what happens when someone loses…

I believe you can set up multiple keys. In this manner, a librarian could keep a "master key." This compromises security somewhat, since the library houses one of the second factors, but IMO it's preferable to total account lockout (and still superior to SMS verification).

if you’re using someone else’s computer, or a computer at a library, you have no security. TLS isn’t enough to be certain they haven’t intercepted the connection, installed their own root certs, or whatever else. I can’t think of any method to securely use someone else’s computer and connection unless you bring a live boot Linux USB or something, which I doubt applies to the intended audience here.

Sure, having a physical key makes it easy for a non-technical librarian to steal someone’s identity, but perhaps having some kind of yubikey safe deposit box would be an appropriate compromise.

Re: Librarian's Letter to Google Security

#118
If a large percentage of computer users who use the library exclusively have ID, the library could purchase a MF device or cheap android phone running an MFA app and use the same device for every user or many users: show your ID, librarian verifies that you're registered, and then come over and log you in with key + username (user still enters password).

Would it be possible for some nefarious person to grab these keys? Yes, but essentially you're reducing the MFA back down to SFA, a cost I think likely worth it for this group.

Re: Librarian's Letter to Google Security

#119
post #84

Earlier quoted context omitted.

Google employs the smartest minds on the planet and also have full insight on how Google works and what tools they have, so it shouldn't be hard for them to come up with a viable solution I believe.

HackerNews is a collection of brightest minds of software engineering who all know better than incompetent Googlers. So asking for how the brightest and bestest of HN engineers handle these security cases is educational for everyone.

It's indeed proving very educational and insightful so far. Several of us are convinced that Yubikeys will solve all their problems, which makes it evident that we have not read the letter. A majority of us are bashing on Google for other reasons.

I'll print out all the comments and forward them on to the Free Library. The next time a patron gets stuck, the librarian can read one of our comments out to them.

Post reply on HN