Librarian's Letter to Google Security
131–140 of 484 posts
Re: Librarian's Letter to Google Security
#132The best solution I can think of that doesn't compromise security is hardware keys. GMail has very good FIDO support. The keys are easier to use than TOTP and vastly more secure than SMS. They do not depend on any phone or phone service, and there is no transferring necessary at any time. The librarian would just need to get the person logged in successfully one time, get the key attached to the person's account, and…
Hardware keys work well in place of a phone, and are in some ways significantly more secure depending on how U2F is implemented. Some of the problem remains: If the user forgets their password the second factor won’t help them, and that includes the backup keys. I’ve read the letter, and I see the massive problem, but I don’t think it’s been fully solved yet. Q: “How do we remotely authenticate a single user, in a wa…
I think biometrics sounds like the best solution. YubiKeys will get lost/damaged/stolen and then you're back to square one. With biometrics you shift the burden of paying for and managing hardware onto the library and individual users don't need to be responsible for anything.
Of course this doesn't solve the issue of the user who is already locked out, but librarians could at least proactively enroll users who have access to their account in order to prevent the issue from happening in the future.
Re: Librarian's Letter to Google Security
#133I wish that Shelley had co-written this letter with either a tech employee or a more tech-focused librarian. The problem that she mentions is real: I've worked in her position and can confirm. But the way the letter is written makes it clear that she's not very familiar with the tech industry or how things are developed. If I were a Google engineer, this would read like one of dozens of pleas we get constantly to cha…
I strong disagree. This isn’t a tech issue, it’s a poorly delivered solution that didn’t consider the needs of the users. The solution is so poorly delivered librarians are an ad hoc support team for thousands of people. Google in particular created a moral problem by choosing to implement a security solution that doesn’t serve people who depend on the services. They have the metrics to know better, but didn’t consid…
> The solution is so poorly delivered librarians are an ad hoc support team for thousands of people.
Well, yes. We're also expected to be teachers, social workers, etc. Everybody has been outsourcing/dumping the unprofitable work on us for decades now, why would Google and other tech companies act any differently? It's a problem that goes deeper than Google and the tech companies; it's a general assumption that infrastructure design can ignore the worst off parts of society and that people like volunteers and librarians will step in without considering whether or not we have the capacity for that as a society.
I just think instead of 'Google, fix it', it would have been wiser to make clear that this is a general problem (not a Google specific one) and to suggest things like partnerships between the GMail team and the PLA, etc.
I'm saying this in the spirit of 'yes, we need to take this territory but maybe a cavalry charge isn't the best way to do that given the other side has machine guns'.
Re: Librarian's Letter to Google Security
#134Re: Librarian's Letter to Google Security
#135Yeah, Google just doesn't give a shit. I was a gmail user since gmail was in private beta 18 years ago. I never had a phone number associated with it. And yet two or three years ago when I tried to log in Google decided to just... not let me do that, because fuck you, and started extorting me to give it a phone number. If I don't give it a valid phone number it won't let me access my email. But I can't really do that…
I also have it since beta -- and no phone associated.
Re: Librarian's Letter to Google Security
#136Re: Librarian's Letter to Google Security
#137I've been saying for a while now that the big tech companies have a strong desire to embed themselves into all our lives, and become a central part of our lives: but the all seem to forget that "with great power comes great responsibility" and none of them want to provide the level of support required to prevent people losing everything important in their life due to a stupid technical problem. It's well overdue time…
I think that Silicon Valley talks big on social issues precisely because they know they walk in the wrong direction.
Re: Librarian's Letter to Google Security
#138The silent majority of us in the tech world knew (and know) that 2fa is a mess, will always be a mess, but for whatever reason the security-obsessed people have taken over the industry in the last few years and here we are, elderly people actually: > losing their welfare benefits, their housing, and struggle to find work. because of technical decisions centered on security. I'm not sure what would be the best way for…
Re: Librarian's Letter to Google Security
#139Perhaps the solution is for libraries or local authorities to setup their own email providers. An email address “for life” with your library card, with the necessary support and in-person reset verification that their patrons need. I’m not suggesting this would be an easy or inexpensive undertaking, but maybe that’s just the next step in service evolution for a public information service like a library group.
Re: Librarian's Letter to Google Security
#140The best solution I can think of that doesn't compromise security is hardware keys. GMail has very good FIDO support. The keys are easier to use than TOTP and vastly more secure than SMS. They do not depend on any phone or phone service, and there is no transferring necessary at any time. The librarian would just need to get the person logged in successfully one time, get the key attached to the person's account, and…
Do they? Typically for those sorts of things you have recovery options. Your landlord will be able to get you a new key, your bank can issue you a new card.
Looking through my wallet, the only thing that would have a significant hurdle to replacing it is my Egyptian residence permit (I'd have to travel to Egypt to re-issue it). The only significant "loss" would be my current monthly public transport ticket, but if I can produce some kind of payment proof and am willing to argue with metro staff I might even be able to get that replaced.
Point being, there is a lot of recourse for offline things, but if you get into this situation with a tech company - there is none. I have a lost 10+ year old Gmail account and I could not regain access to it through any means even while working as an SRE at Google.