Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

121–130 of 484 posts

Re: Librarian's Letter to Google Security

#121
post #56
post #48

I wish that Shelley had co-written this letter with either a tech employee or a more tech-focused librarian. The problem that she mentions is real: I've worked in her position and can confirm. But the way the letter is written makes it clear that she's not very familiar with the tech industry or how things are developed. If I were a Google engineer, this would read like one of dozens of pleas we get constantly to cha…

yikes. old poor people are having their lives upended because technology has infiltrated the processes by which basic business is conducted and the designers of said technology had not bothered to consider them as a real use case, and your response is "she's not asking nicely enough." yikes*10000. cringe^inf.

Maybe I should have mentioned I'm a programmer and a librarian, and my suggestion is one of tactics/strategy.

I care more about getting the problem fixed than the writer's feelings not being hurt, and I think that things would be more likely to change if she'd written it differently.

Re: Librarian's Letter to Google Security

#122
post #48

I wish that Shelley had co-written this letter with either a tech employee or a more tech-focused librarian. The problem that she mentions is real: I've worked in her position and can confirm. But the way the letter is written makes it clear that she's not very familiar with the tech industry or how things are developed. If I were a Google engineer, this would read like one of dozens of pleas we get constantly to cha…

My goodness, I think you just might be lacking in empathy. I honestly recommend that you take a step back and reread what you have written here.

> But the way the letter is written makes it clear that she's not very familiar with the tech industry or how things are developed

And she should not have to be familiar with the tech industry. The tech industry's job is to figure out what the users want, by understanding what they do.

> And software devs in general find those demands annoying, particularly given some of the language that Shelley uses.

No no I hope not! I hope that engineers who possess some empathy will see a letter like this and feel their pain and feel compelled to do something for them. If someone feels nothing after reading this letter, they are lacking in empathy.

Re: Librarian's Letter to Google Security

#123
post #48

I wish that Shelley had co-written this letter with either a tech employee or a more tech-focused librarian. The problem that she mentions is real: I've worked in her position and can confirm. But the way the letter is written makes it clear that she's not very familiar with the tech industry or how things are developed. If I were a Google engineer, this would read like one of dozens of pleas we get constantly to cha…

But in this case the affected "portion of the served population" is not even "small" !

It's a small proportion of the served population, not a small population in absolute numbers.

Re: Librarian's Letter to Google Security

#126

Earlier quoted context omitted.

> trusted civic authorities They'll need to be resistant to threats and bribes, so it will be difficult to have these on-site at the library. I think we've overlooked an option. Note that the article's objection to FIDO keys was financial, not UX. This sort of confirms the hunch I got when first playing with them: "hey, the key metaphor is so strong and intuitive that these might be even better than passwords for peo…

It is not uncommon for unhoused people to lose all their possessions, so even if purchasing multiple hardware security keys wasn't a huge financial hurdle, the recovery model I use (Yubikey on my keychain, two in my safe, mail one to my parents) falls apart for those on the margins of society. If email is an essential service in modern society, recovering access to it from some first principle of identity is essentia…

That's true, we still need a good last-ditch fallback. FIDO could still save a lot of people from the hard login screen, the phone number gotcha, and the need to become literate in information-keys. Last-ditch fallback becomes a lot more viable at any given expenditure level if it doesn't have to serve as the primary authentication mechanism for half of the library's elders.

Re: Librarian's Letter to Google Security

#127

Why is the US so far behind the rest of the world when it comes to technology? State IDs/Driving Licenses already exist. These should have chips on them that could be used for authentication.

Getting an ID in the US is more difficult than this account recovery procedure that the letter complains about.

Especially for the the specific demographic that this letter is referring to. It's so easy to get caught in a catch-22.

Re: Librarian's Letter to Google Security

#129
The silent majority of us in the tech world knew (and know) that 2fa is a mess, will always be a mess, but for whatever reason the security-obsessed people have taken over the industry in the last few years and here we are, elderly people actually:

> losing their welfare benefits, their housing, and struggle to find work.

because of technical decisions centered on security.

I'm not sure what would be the best way forward, for the moment I'm in the "less tech is the best" camp, especially when it comes to interactions between citizens and the State, probably that tendency will only grow.

Re: Librarian's Letter to Google Security

#130
post #88
post #18

Earlier quoted context omitted.

I agree with your suggestion. I think Post Offices, DMVs, and large reputable retailers (Walmart, Target, Cellular Phone companies, etc.) could verify our identities for a small fee and help us reset our social accounts when needed. I arrived at the same conclusion and wrote a blog post about it a few years ago: https://www.go350.com/posts/now-they-have-2fa-problems/

I distinctly remember lynching from HN security crowd when SIM cards were being unlocked and moved to new people from "trusted companies" like Verizon and AT&T. HN demanded for such security holes to be disabled and prevented - what changed since then?

What changes is that there are different needs from different segments of the world, and we have reached a problem (authentication in general) that is truly impossible to solve with our current toolset.

For me, the larger threat is that someone impersonates me and takes everything I have. If I lost my email, it would be a nightmare but I could work around significant portions of the system. For my cousin, the larger threat is losing her email, as she has no significant assets to steal but could run into every problem in the email.

There are likely people in the middle as well, and other threat vectors. (For example: caregivers committing fraud, dementia, state actors, and 20 other we could brainstorm pretty quickly.) Perhaps the right answer is that we need 20 different services that can segment. Perhaps the problem is that some sectors aren't profitable: maybe we need a grant for emails for poor people with a circle of trust.

I don't have answers. Maybe we need a collection of people to think deeply about this problem.

Post reply on HN