Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

191–200 of 484 posts

Re: Librarian's Letter to Google Security

#191
The only solution to this is that state authorities learn how this is a systemic problam and start to reject email addresses from operators like Gmail for all their services (and all email operators that do not have a real support and where one's identity is not actively checked and can not be proven and taked back via a real support line).

Re: Librarian's Letter to Google Security

#192
post #108

More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support.

> More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support. I would recommend a $5/month email service. It would be nice if free Gmail gave even more free stuff, but only a paid for service can really expect paid support staff. Having said that, this seems like a terrible idea from a security perspective. There may well be no way to desi…

Right. Why would these poor and often elderly people pay for a $5/month email service when there are several free options they choose instead?

Re: Librarian's Letter to Google Security

#193
The author is 100% not wrong, but the problem is that, unfortunately, it is entirely possible that Google cannot have an authentication system that is correct for use by the elderly in a shared-machine environment while being correct for everyone else at the same time.

There are options to fix this, but they're social, not technical. To get there, let's start with the technical side of why the author's proposed fix won't work.

Google has no idea who anyone is. The only way they can know is the authentication process. And that process is under perpetual, high-investment attack by basically everyone because Google is a valuable target. Everyone from script kiddies to state actors have tried every method to not only compromise individual accounts but to build frameworks for systemic compromise, because when you focus on a single target you can invest the resources to, for example, set up a server that mimics the Google login page or a phone bot that sounds like it's making calls from Google Security. Our author bemoans the lack of a back-channel to recover one's account, but that back-channel is (a) perpetually overloaded with requests to access accounts (b) one of the major vectors for attempting to steal an account, because the back-channel is just one more interface on the systematically-attacked system.

(Source: I know someone who used to be in the loop on the back-channel. Scammers would call crying about kidnapped children who were going to die in a couple of hours unless they could get into a GMail account to get an address in a ransom note. Google had to train their phone crew to understand that probability was heavily skewed in the direction that if they capitulated, they were, within a statistically-negligible margin of error, never saving a kid and they were always letting an abusive significant other into their former partner's account so they could ransack it for passwords and vulnerable 1FA access codes and fuck up someone's life. Truly sick, heartbreaking stuff).

So that's the system under attack. How to address the problem that the elderly and impoverished can't afford to keep up with Google's security measures?

There are a couple of options here. In the short run, the cheapest is "Don't use Google." Use an email provider under less persistent threat, and one small enough to offer high-touch technical support. This is one of those situations where free may be the enemy of "cheap but affordable," and to bridge the gap someone could even start fundraising to pay for accounts on a service like that. There may even be meat on the bones of someone being a non-profit high-touch email provider of that sort, who can secure a person's account by having them log in from a specific, privileged machine within sight of an operator who knows them personally. Go back to the old days of how the DARPANET was actually secured by "every node is locked behind a door."

Another option is that a service libraries could provide (at possibly great expense to themselves, but options on the table) would be to serve as a credentials broker for their users. Have the library keep track of the 2FA side of things. Risky and adds expense to the library, but for this userbase that local service is the missing piece of the puzzle. Unfortunately, this isn't something Google is set up to provide; they're too centralized, they aren't actually in the communities where the need lies.

Re: Librarian's Letter to Google Security

#194

I fully sympathize with the librarian's concerns, but there's this: "Many government welfare forms, housing applications, and jobs applications these days require the use of the internet exclusively with no option to fill things out in person." Why is this? Really, this does not seem like a problem Google caused, but rather a problem caused by the government when they made it mandatory to have internet access to get…

This is flat out incorrect.

All _government _forms have paper-equivalents for accessibility reasons, and OMB numbers that coincide.

The Paperwork reduction act is a thing, but it also stipulates that within reason, paper forms must be available.

Re: Librarian's Letter to Google Security

#195

Great letter. Wanna bet it was completely ignored? Glad to see it here. Maybe it won't be ignored. Librarians rock. There's even a show about them[0], Starring Number One. I can't access the gMail account I set up, because I made a mistake, when setting the password, and did not save the one I used. It will not allow me to access the account I set up. After a while, I just gave up. I am satisfied that someone can't u…

>I made a mistake, when setting the password

That's a feature, not a bug.

Re: Librarian's Letter to Google Security

#196
Is it even possible to use a google account without a phone number? Google (and about everyone else) demands them for tracking. I've steadfastly avoided giving out my number for most trivial things but it's becoming harder and harder. The recent dark pattern is to setup your account and then claim there was suspicious activity on first login so they need to verify your (brand new) account by having you enter a (completely new) phone number. Microsoft recently extorted it out of me by forcing me to convert my mojang account to a Microsoft account and then pulling the verification stunt. Twitter, facebook, etc all do this.

Another annoyance is if you enter a landline number most of these things just assume it's a cell and then ask you for the verification code that they just sent into the ether.

Re: Librarian's Letter to Google Security

#197

Yeah, Google just doesn't give a shit. I was a gmail user since gmail was in private beta 18 years ago. I never had a phone number associated with it. And yet two or three years ago when I tried to log in Google decided to just... not let me do that, because fuck you, and started extorting me to give it a phone number. If I don't give it a valid phone number it won't let me access my email. But I can't really do that…

This is a great point. My wife and I were attracted to the Google Pixel lineup because they advertised unlimited original quality photo storage through Google Photos. Well they reduced that to just unlimited "high quality" a year or so ago, and I broke my 3A a few months ago. Silly me forgets that newer Google Pixels don't have unlimited photo storage at all, I buy a 5A, and all photos/videos get uploaded to Google Photos and count against my quota. Even though Google technically isn't in the wrong here, I've always felt like I got a rug pull.

Re: Librarian's Letter to Google Security

#198
I quit gmail 10 years ago because of this fucking bullshit (which mainly was brought to status quo by people like HN users and programming blog posters for the last 2 decades).

This is a direct consequence of garbage cultures that have been left uncontended:

- UN*X, for not providing sane protocols that anyone would want to use (email is garbage in the first place. aside from the other 10000 problems with it, you should be able to generate addresses on the fly for each contact you interact with, which also solves spam and removes the need to have a "super smart" central "trusted" server with spam filter created with 10000 man hours of work that you can never create yourself). SQL injection was a UN*X braindamaged phenomena; no sane protocol would require embedding strings in the concrete syntax by hand, except when you have a bunch of idiots following the "everything is text" and "text is the lowest common denominator" mantra

- (continued) The email end game from the beginning (due to the spam problem) is that anyone who tries to make their own email provider will be blocked temporarily or permanently. There are already only a few remaining email services in existence. Due to UN*X braindamage, your email address is tied to a domain name, which will also be blocked as this is the natural meta of such a system: Admins get to look at the pointless string at the end of your address and decide if they don't like a substring of it, or only allow a set of known domains. Of course, if a sane protocol was in use, your address would just be a long string of meaningless bits and there would be no location or English word to discriminate on.

- Webshit, for allowing corpos to create interactive nonsensical applications instead of forcing them to use well established protocols with static pages describing the address of said services. Why in the hell can a website run code? Immediately the first thing I thought of when I heard of that was, "oh but wait what about all the stupid people who will make crap code that will freeze your browser?". This is such a terrible nonsense idea. And all the web standards are crap too. The web is a relic like Flash player.

- Infosec, for floating this idea that the user is an absolute idiot, and cannot be trusted to manage his credentials, not even with an "I'm an infosec expert, opt me out" option (ironically, anyone in infosec probably _can't_ manage their credentials). The only reason they are partially right is because of UN*Xy practices which make the most trivial tasks insecure (for instance, you could just dump the database of 99% of websites between 2000 and 2010 due to SQL injection, so for casual/lazy users who use the same login on multiple pages, you could login to all their services).

- Login voodoo, this started with "frequent flyer number" bullshit, where you could never tell if someone could use your stupid questions to get into your account without your password (they could), and password reset, which means your email address is essentially the public key for your account, and stuff like the Steam vuln where you could literally just press "i forgot my password" and it would let you into whatever account you wanted

- Hyperstatism, the narrative will eventually shift (if it hasn't already) to "you have to have a complex login mechanism because you need to be identified [by cell phone, government ID]"

This thread is a good example of how you are all helping nothing. We need real solutions to technical problems. Not solutions for people who don't know how to do anything properly. We can trivially have a cell phone that stores private keys, and public keys of other people and maps names to them, and is trivial and intuitive to use by lay people, but instead you will pander the dumbest possible thing like "biometrics", or some other forced 2FA crap, because poor people are supposedely too stupid to use anything else, like even a simple password which would still be better that what companies like google do. That's not how it works, you implement a PROPER solution and let the user friendly amendments to it trickle down. We even see now the capability folks reusing UN*X and javascript, the two worst OS and language to try and appeal to get uptake of their projects. Literally no solution the hacker has put forth today solves the problem, they just want to pander to specific nonsense that makes them feel pragmatic about themselves.

Re: Librarian's Letter to Google Security

#199

Why is the US so far behind the rest of the world when it comes to technology? State IDs/Driving Licenses already exist. These should have chips on them that could be used for authentication.

The main reason we don't want a ubiquitous national ID is that once it's there, everything will require it, which means everything you do will be tracked. Which is okay until the government decides to go psycho and attack some section of the population. Right now, literally every red state would love to get their hands on logs filled with IDs of people who have anything to do with abortion (a Texas bill makes it illegal to even drive someone to an abortion) so they can put them all in jail (abortion doctors get 99 years). In the past it was the gay rights movement, civil rights movement, the satanic panic, the communist panic, rounding up all asians into concentration camps during ww2, etc. We can expect more of this, and a ubiquitous ID makes it much easier for the government to execute these plans.

Re: Librarian's Letter to Google Security

#200

Is it even possible to use a google account without a phone number? Google (and about everyone else) demands them for tracking. I've steadfastly avoided giving out my number for most trivial things but it's becoming harder and harder. The recent dark pattern is to setup your account and then claim there was suspicious activity on first login so they need to verify your (brand new) account by having you enter a (compl…

No post body was provided.
Post reply on HN