Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

181–190 of 484 posts

Re: Librarian's Letter to Google Security

#181

Yeah, Google just doesn't give a shit. I was a gmail user since gmail was in private beta 18 years ago. I never had a phone number associated with it. And yet two or three years ago when I tried to log in Google decided to just... not let me do that, because fuck you, and started extorting me to give it a phone number. If I don't give it a valid phone number it won't let me access my email. But I can't really do that…

It's not just Google, many corporations are starting to make "assumptions" about their customers, and these assumptions totally exclude entire groups of people. A great example I use is there are a ton of restaurants and fast food places around me. I used to walk to get lunch every day but eventually had to stop, these places realized most customers went through the drive through so they closed the lobby. Now even th…

> The TV required an internet connection to "activate"

I’m a huge fan of shoving crap like that back in the box, and returning it DOA. The soulless bastards that built it don’t know if I’m computer literate or not.

Re: Librarian's Letter to Google Security

#182
One thing that the library could do is store the cookies of their patrons, and restore those next time they use a library computer. This would avoid the most common case of the problem. I suspect this is the only feasible solution; Google is certianly never going to bother with these people.

Re: Librarian's Letter to Google Security

#183
post #59

Ehm, don't use Gmail then? I know I know, they're Americans...

It's not like most people will know they might lose everything if they sign up with google. Most rightfully expect that google, like most other companies, has customer service. By the time they realize, they're too late We need to start seriously spreading the word that Google cannot be trusted to hold anything important to you

I'm pretty sure this isn't a Gmail-only issue. This letter could have been written to any other email provider, but it just so happens to be Gmail due to popularity.

Email is an inherently insecure service. Security professionals had been clamoring for default 2fa, E2EE, etc. due to various breaches, leaks, and security issues that have occurred over the years. Remedying the aforementioned security issues necessitates certain practices to be phased out and the people who relied upon them to be caught up to speed or left behind.

Re: Librarian's Letter to Google Security

#185
post #48

I wish that Shelley had co-written this letter with either a tech employee or a more tech-focused librarian. The problem that she mentions is real: I've worked in her position and can confirm. But the way the letter is written makes it clear that she's not very familiar with the tech industry or how things are developed. If I were a Google engineer, this would read like one of dozens of pleas we get constantly to cha…

> misaimed moralizing The moralizing is in fact aimed directly and purposefully at google

And I think she's wrong, as another librarian who's worked in public services.

I think Google's poor implementation of 2FA is a result of misaligned incentives, unknown unknowns in the product development cycle (because she's right that engineers assume a baseline technological literacy and access that isn't there for everyone), and deeper social issues.

Lying it directly at Google's feet and implying that they made that choice maliciously rather than ignorantly (or to maximize their actual goal, which is $$$) + not noting that the bad decisions have also been picked up by their competitors makes it read more as a judgment than an invitation for collaboration/plea for help. I think a different approach would have been more effective.

I have a tactical disagreement with Shelley. No disagreement on the actual issue, which she's right is a huge problem and one I've personally encountered hundreds of times.

Re: Librarian's Letter to Google Security

#186

Well, this is a tricky situation. At what point did Google agree to become the world's free email provider? We have to decide where their social obligation outranks their share holder obligation. And by "we," I include everyone from users, technology providers, and especially governments that require email addresses to get basic services, everyone. A modest proposal. Can one YubiKey serve several email accounts? Ask…

>At what point did Google agree to become the world's free email provider

Maybe they shouldn't have offered email for free to the world if they didn't want to be the world's free email provider.

Re: Librarian's Letter to Google Security

#187

I fully sympathize with the librarian's concerns, but there's this: "Many government welfare forms, housing applications, and jobs applications these days require the use of the internet exclusively with no option to fill things out in person." Why is this? Really, this does not seem like a problem Google caused, but rather a problem caused by the government when they made it mandatory to have internet access to get…

You're right, that online-only access is definately a government problem. But this: > Even when we clicked “I don’t have my phone” it asked her to open the Google app from the phone that she does not have. That's a google problem. Google fixing their problem would lessen the impact of the government problem. (And, more generally, make gmail a better service for lots of people.)

but what would Google do, how is it possible to fix? What's the point of having 2FA using the phone if you can bypass it by clicking "i don't have my phone"?

Re: Librarian's Letter to Google Security

#188

Earlier quoted context omitted.

Or now that I think about it… for 2FA in particular, what about enrolling a software FIDO token with an extension on every library computer that can be triggered by a librarian from their desk? Doesn’t require hardware for each patron, only applies to accounts that have been enrolled at the library. Feels like it could work.

Then it opens up a backdoor for malicious (or socially engineered) library staff to access email accounts.

And given that a lot of the staff working those desks aren't librarians + are working part time, it's also great incentive for bad actors to get jobs in libraries specifically to start stealing that data.

Re: Librarian's Letter to Google Security

#189
post #108

More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support.

> More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support. I would recommend a $5/month email service. It would be nice if free Gmail gave even more free stuff, but only a paid for service can really expect paid support staff. Having said that, this seems like a terrible idea from a security perspective. There may well be no way to desi…

> I would recommend a $5/month email service.

Surprise! There is. https://workspace.google.com/intl/en_ie/pricing.html

> Google Workspace Standard Support—Standard Support is included with your Google Workspace license. It provides support with a 4-hour service-level objective (SLO) for P1 cases. If you're interested in faster response times and additional Support services, Enhanced or Premium Support might be a better fit for your business.

https://support.google.com/a/answer/10105075?hl=en&ref_topic...

A good question is what does P1 case means. Locked out of email or "sorry Google, I just wanted to say your global email network is down, when it's gonna be up?"

Re: Librarian's Letter to Google Security

#190
PSA: If you are low-income, or you know low income people who do not have internet at home, you should check out ACP, the Affordable Connectivity Program[0].

It is a federal program that provides up to $30/month, paid directly to your ISP so that they can take that amount off your bill. I work for an ISP[1] that offers a $30/month, 200Mbps plan which is free when using ACP (we don't even take your credit card). Most ISPs now have an ACP section of their web site if you search for it.

Having worked extensively on implementing this program at my company, I have seen exactly what this librarian is talking about. The people who need programs like ACP are also disproportionately people who have low tech literacy, and often poor literacy/education in general, and the existing systems don't work for them. I wrote about that recently in another thread[2].

When a customer is locked out of their ACP account, luckily the ACP support line is able to reset their password over the phone. But it's not always an easy process. Often, we need to have multiple, in-person meetings with these customers in order to get pictures of their ID, and often ACP will not do anything to an account unless the customer is physically on the phone or in person with us asking them to.

If our customers could always get access to their Gmail, it wouldn't be nearly as big of an issue. They could reset their password the way you'd expect. But as the article is pointing out, if you're locked out of your Gmail there is absolutely no way in.

It's really striking just how much work it is to be poor. Google needs to fix this, and remove one more barrier to people who need to use email with government services.

[0] https://www.fcc.gov/acp

[1] https://www.flumeinternet.com/

[2] https://news.ycombinator.com/item?id=32086589

Post reply on HN