Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

171–180 of 484 posts

Re: Librarian's Letter to Google Security

#171
post #21

Another solution to this problem would be competition. If there were a workable alternative to Gmail that had account recovery mechanisms better suited for this population than the librarian could simply recommend that for their patrons. Can anyone suggest what a good alternative to Gmail would be for this population?

Maybe a Government-supplied email address that is only accessible from libraries?

I would hope that libraries would have fixed IP addresses, so surely that could be factored into the authentication process? Some FIDO keys used to be able to be bought for as little as $5 (https://wiert.me/category/power-user/security/u2f-fido-secur...) so it shouldn't be beyond the budget of any self-respecting town/county/state?

Re: Librarian's Letter to Google Security

#172

Great letter. Wanna bet it was completely ignored? Glad to see it here. Maybe it won't be ignored. Librarians rock. There's even a show about them[0], Starring Number One. I can't access the gMail account I set up, because I made a mistake, when setting the password, and did not save the one I used. It will not allow me to access the account I set up. After a while, I just gave up. I am satisfied that someone can't u…

> Wanna bet it was completely ignored? Well, looking at the date... > "Today, July 19th 2021 "

Edited Sept 10,2021 per Activity and Details. The year is not a misprint.

Re: Librarian's Letter to Google Security

#173
Classism via Internet.

When Uber and Lyft became popular and you still needed a smartphone and mobile connection to use it, it basically became a way to keep poor people segregated in transportation. If you couldn't afford a smartphone, or a data plan, or only sporadically, you were relegated to the public transportation options which are slowly defunded as Lyft and Uber lobby governments to become the "more affordable" alternative to public transit. As a result, 'hacks' (illegal taxis) are widely used in many cities because you don't need a smartphone or data plan and they are cheaper, yet are more dangerous.

Mega-corporations that design for "the 80% of users" implicitly make life harder for vulnerable and poor people. It's time for us to not only hold Government accountable to treat people well, we have to hold Corporations accountable to the same standards (at minimum).

(as an aside: I love the Free Library of Philadelphia. they get out in the city and meet all kinds of people, help them get access, always generous with their time and friendly. they are a vital service to the community and I hope Google listens to them)

Re: Librarian's Letter to Google Security

#174
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

It’s an absolutely catastrophic experience, that they clearly don’t take seriously. Regulation solves this. I hate to say that, as so much of tech regulation is a ham-fisted disaster that misunderstands the problem and creates even bigger ones, but this is really a very serious problem that can ruin lives, and regulators really should step in here. I’ve known a couple of people who have been through this experience,…

Can you describe how regulation solves this problem, how exactly are you proposing for this regulation to work?

Re: Librarian's Letter to Google Security

#175

I've been saying for a while now that the big tech companies have a strong desire to embed themselves into all our lives, and become a central part of our lives: but the all seem to forget that "with great power comes great responsibility" and none of them want to provide the level of support required to prevent people losing everything important in their life due to a stupid technical problem. It's well overdue time…

They don’t care because you’re an underclass to be milked for profit. I think that Silicon Valley talks big on social issues precisely because they know they walk in the wrong direction.

Its interesting how wrong they are when dealing with the daily lives of the lower class or people who don't have a big voice. There's no ROI in helping an elderly person maintain their dignity nor cancelling a couple of Native American accounts because their names don't seem correct to them.

What really bugs me is that the employees of the Google seem to have their own political agenda, but none of that includes the people the company is actually ill serving. I guess that's just not cool or edgy. Its the company they work for that has become a tyrant.

Re: Librarian's Letter to Google Security

#176
post #48

I wish that Shelley had co-written this letter with either a tech employee or a more tech-focused librarian. The problem that she mentions is real: I've worked in her position and can confirm. But the way the letter is written makes it clear that she's not very familiar with the tech industry or how things are developed. If I were a Google engineer, this would read like one of dozens of pleas we get constantly to cha…

> misaimed moralizing

The moralizing is in fact aimed directly and purposefully at google

Re: Librarian's Letter to Google Security

#177

Yeah, Google just doesn't give a shit. I was a gmail user since gmail was in private beta 18 years ago. I never had a phone number associated with it. And yet two or three years ago when I tried to log in Google decided to just... not let me do that, because fuck you, and started extorting me to give it a phone number. If I don't give it a valid phone number it won't let me access my email. But I can't really do that…

It's not just Google, many corporations are starting to make "assumptions" about their customers, and these assumptions totally exclude entire groups of people.

A great example I use is there are a ton of restaurants and fast food places around me. I used to walk to get lunch every day but eventually had to stop, these places realized most customers went through the drive through so they closed the lobby. Now even though this place is a 5 minute walk from me, it's no longer accessable if I'm not in a car.

Same thing with my TV and Router, both of which required an app to just setup. The TV required an internet connection to "activate" and I realized that if some family saved up and bought this TV but didn't have an smartphone or internet connection, well they just bought a $500 brick.

And that's why authentication standards like FIDO scare me. To me it almost seems that the standard was written by a bunch of out of touch tech bros thinking to themselves: "Well of course EVERYONE has a phone these days"

Re: Librarian's Letter to Google Security

#178

I fully sympathize with the librarian's concerns, but there's this: "Many government welfare forms, housing applications, and jobs applications these days require the use of the internet exclusively with no option to fill things out in person." Why is this? Really, this does not seem like a problem Google caused, but rather a problem caused by the government when they made it mandatory to have internet access to get…

What does this have to do with not having an account recovery flow?

Many government offices have temporarily(?) gone online-only for covid.

Re: Librarian's Letter to Google Security

#179
Well, this is a tricky situation. At what point did Google agree to become the world's free email provider? We have to decide where their social obligation outranks their share holder obligation.

And by "we," I include everyone from users, technology providers, and especially governments that require email addresses to get basic services, everyone.

A modest proposal. Can one YubiKey serve several email accounts? Ask patrons to sign up for a library card. Register each library card with one key, such that one key can serve many patrons. Help them enroll with multi-factor authentication. Whenever they need it, simply request the token from the librarian desk.

(Put the token on a giant brick or yardstick, so that it never leaves the library. Sort of like how they do at gas station bathrooms.)

Re: Librarian's Letter to Google Security

#180
post #158
post #147

Earlier quoted context omitted.

sure, maybe you do get more bees with honey. or more often than not you never get seen. we live in a sad era where the only way to get real attention from large companies is to embarrass them in public. this is by their design. > I care more about getting the problem fixed than the writer's feelings not being hurt i don't really follow how the writer's feelings could be hurt in any case. you seem to have an odd persp…

So we disagree on the best tactics to take here. In particular, I think the embarrassing tech companies in public works when it's done by either other tech people OR it gets into the media where the bottom line could be impacted. This That doesn't make me 'cringe^inf' or boil down my tactical critiques to '"she's not asking nicely enough'. I presumed you were attempting to call me out for tone policing, and usually t…

the call out was more in line with a general disagreement with what i saw as a tech industry apologist take. i don't think people who work in the tech industry are bad people, but if people are losing housing because of their products, inventions, or service policies, then it appears that they have certainly (possibly inadvertently!) done some very bad things and that needs to be acknowledged plainly and clearly.

no masters need to be pleased, no egos massaged (it's time for that obnoxious culture to die). they done bad and it's time to make it right.

embarrassing companies in public is an old tactic that predates consumer technology companies by a large margin. in the old days letters would appear in trade rags or newspapers to the same effect.

also, thank you for your time in public service.

Post reply on HN