Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

161–170 of 484 posts

Re: Librarian's Letter to Google Security

#161

So, what should Google do, here?

Allow users to link accounts to widely accepted forms of government ID. Maybe a state ID, whatever the common ID is amongst that community.

If a user has chosen to link their account to a real ID in this way, they must be able to regain access to their account regardless of password/2FA blah blah by presenting a valid ID.

Banks and lots of institutions have processes to do this. The librarian is right, "how" is not an issue because verifying identity is _not_ an unsolved problem lol.

Re: Librarian's Letter to Google Security

#162

I fully sympathize with the librarian's concerns, but there's this: "Many government welfare forms, housing applications, and jobs applications these days require the use of the internet exclusively with no option to fill things out in person." Why is this? Really, this does not seem like a problem Google caused, but rather a problem caused by the government when they made it mandatory to have internet access to get…

You're right, that online-only access is definately a government problem. But this: > Even when we clicked “I don’t have my phone” it asked her to open the Google app from the phone that she does not have. That's a google problem. Google fixing their problem would lessen the impact of the government problem. (And, more generally, make gmail a better service for lots of people.)

Well, you can see the problem, right? Allowing attackers to bypass 2FA just by saying their phone is lost makes 2FA worthless.

Re: Librarian's Letter to Google Security

#164

Earlier quoted context omitted.

To the target audience of the library? Outlook.com as it's the simplest to use. Their immediate concern is their livelihood so they need a free email account and not have to think about anything else including its lifetime. To a techie audience? ProtonMail, FastMail, Tutanota, GMail, Postfix...

Gmail sounds like an odd recommendation as a replacement for Gmail.

Gmail but the Workspace version so that you have a better customer support*.

* Relatively better, but still lower than what I expect.

Re: Librarian's Letter to Google Security

#165
post #108

More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support.

Customer support that has access to google accounts, that can give everyone telling a sob story to some customer service rep access to your account?

This comment does raise a serious concern. The primary reason why cell phone numbers are bad for 2FA is sim swapping, which can only occur because there is a customer support rep who can fall for it. Email is largely immune to that right now because customer support generally cannot let you into an account you locked yourself out of.

This isn't to say that this is an unsolvable problem, it's not, but it's definitely worth talking about.

Re: Librarian's Letter to Google Security

#167
post #108

More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support.

> More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support.

I would recommend a $5/month email service. It would be nice if free Gmail gave even more free stuff, but only a paid for service can really expect paid support staff.

Having said that, this seems like a terrible idea from a security perspective. There may well be no way to design a service that is resistant to social engineering and lets you unlock your account via a phone call.

Re: Librarian's Letter to Google Security

#168

Earlier quoted context omitted.

Customer support that has access to google accounts, that can give everyone telling a sob story to some customer service rep access to your account?

Your concern while valid seems solvable. They could preauthorize a random token amount on credit card with matching details, have you call the number on the back of your card to figure out that amount and then you have to input that number to authorize the access in an oath like flow. Please tell me if you see something wrong with my procedure? edit: I saw something wrong, I have forgotten about the vast unbanked pop…

The disadvantaged people who the librarian talks about (selling their phone to make ends meet) may not have a credit card to charge.

Re: Librarian's Letter to Google Security

#169

Earlier quoted context omitted.

Customer support that has access to google accounts, that can give everyone telling a sob story to some customer service rep access to your account?

Your concern while valid seems solvable. They could preauthorize a random token amount on credit card with matching details, have you call the number on the back of your card to figure out that amount and then you have to input that number to authorize the access in an oath like flow. Please tell me if you see something wrong with my procedure? edit: I saw something wrong, I have forgotten about the vast unbanked pop…

As with every other "simple solution" to a complex problem there are a few flaws:

a) google will have to require a credit card in order to open an email

b) person opening an email account must actually have a line of credit, e.g.: many of the people mentioned in the OP will not have it

c) opens a new attack vector on google accounts, e.g.: people who secured their emails using 2FA app for example can now be attacked via a credit card process

Re: Librarian's Letter to Google Security

#170
post #31

Earlier quoted context omitted.

I think something like this could work iff the accounts were required to be set up by said civic authorities with confirmable paperwork. Otherwise, librarians are stuck awkwardly trying to decide if 'John Doe' really owns the email account 'ILoveButts64@gmail.com'. I also doubt this will ever happen since it would require more $$$ for things that are not profit generating and supports a population that is useless fro…

Or now that I think about it… for 2FA in particular, what about enrolling a software FIDO token with an extension on every library computer that can be triggered by a librarian from their desk? Doesn’t require hardware for each patron, only applies to accounts that have been enrolled at the library. Feels like it could work.

Then it opens up a backdoor for malicious (or socially engineered) library staff to access email accounts.
Post reply on HN