Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

201–210 of 484 posts

Re: Librarian's Letter to Google Security

#201
It looks like it is possible to use totp for your backup second factor, which would let the libraries store the secrets on paper and require ID for a password reset:

https://webapps.stackexchange.com/questions/127464/enabling-...

It looks like it is a pain in the neck, but also possible to use it as the main second factor, for people without phones.

This reminds me, I need to move 100% off google’s ecosystem.

Re: Librarian's Letter to Google Security

#202
post #140
post #52

The best solution I can think of that doesn't compromise security is hardware keys. GMail has very good FIDO support. The keys are easier to use than TOTP and vastly more secure than SMS. They do not depend on any phone or phone service, and there is no transferring necessary at any time. The librarian would just need to get the person logged in successfully one time, get the key attached to the person's account, and…

> If the person lost their actual keys and wallet, they've got bigger problems Do they? Typically for those sorts of things you have recovery options. Your landlord will be able to get you a new key, your bank can issue you a new card. Looking through my wallet, the only thing that would have a significant hurdle to replacing it is my Egyptian residence permit (I'd have to travel to Egypt to re-issue it). The only si…

> Looking through my wallet, the only thing that would have a significant hurdle to replacing it is my Egyptian residence permit

Maybe don't carry that in your wallet if you don't need it where you are and it's so hard to replace. :)

Re: Librarian's Letter to Google Security

#203
post #54

This is one of those situations that make it incredibly clear that even Google, with all its resources, never considers the use case or life experience of anyone besides a wealthy Bay Area tech worker when designing their products. I can't help but wonder how this blind spot got so big - and why they still don't address things like this even with all the user testing & A/B trials they do for ruthless optimization. Is…

This blind spot got so big because the vast majority of wealthy Bay Area tech workers have never been poor or homeless. It is difficult for those that have never lived in poverty to understand the struggles that it brings. Just look at his thread, see how many people fail to comprehend that if someone is using the library computers they aren't going to be able to afford a $25 key-chain verifier.

Yes. The overwhelming majority of people that I worked with in SV had never been poor, never been homeless, never worked a fast food or customer facing retail job, and never lacked support from family or some kind of extended network.

They were accustomed to lightning fast internet on Macbooks and constant technological churn. Unfortunately for these exceptional people, poverty is logic resistant and nearly impossible to understand second-hand.

Re: Librarian's Letter to Google Security

#204
Here's an idea:

Why not allow the owner of a Google account to delegate a trusted third party who can handle MFA/otherwise approve logins on their behalf. I kind of do this already by setting the recovery emails for family members (especially aged parents) Google accounts to those that I control, but to my knowledge it is not possible to do the same for the mobile number used to secure the account.

This way, at least as I imagine the authors scenario, the library's regulars could delegate them as the trusted third party, problem solved.

Oh yes, and also what they write -- add an on/off setting for "Be less anal about logins from unrecognized devices".

Re: Librarian's Letter to Google Security

#205

Yeah, Google just doesn't give a shit. I was a gmail user since gmail was in private beta 18 years ago. I never had a phone number associated with it. And yet two or three years ago when I tried to log in Google decided to just... not let me do that, because fuck you, and started extorting me to give it a phone number. If I don't give it a valid phone number it won't let me access my email. But I can't really do that…

It's not just Google, many corporations are starting to make "assumptions" about their customers, and these assumptions totally exclude entire groups of people. A great example I use is there are a ton of restaurants and fast food places around me. I used to walk to get lunch every day but eventually had to stop, these places realized most customers went through the drive through so they closed the lobby. Now even th…

> A great example I use is there are a ton of restaurants and fast food places around me. I used to walk to get lunch every day but eventually had to stop, these places realized most customers went through the drive through so they closed the lobby. Now even though this place is a 5 minute walk from me, it's no longer accessable if I'm not in a car.

I think this may have to do COVID and then staffing shortages creating a necessity rather than a active business decision. It would be ridiculous but couldn't you walk through the drive through? (I probably wouldn't do it either but I can't really think of a reason you couldn't)

Re: Librarian's Letter to Google Security

#206
post #114

Earlier quoted context omitted.

Making these (and especially electronic ones) mandatory is a baaad idea :

I used to feel the same. But in reality, we prove our identity daily - every credit card transaction, banking, electronic tolling, bill payment, health care visit, tax payment, legal proceeding, employment opportunity, voter registration … What protects us from invasive search is not lack of a uniformly accessible system for identification - its due process. And if the government chooses to compel you against your wi…

Most of those are optional. You can use cash, you don't need a bank account, nor electronic tolling, or bill payment, emergency room visits are free and there's free clinics. Other various things like legal proceedings, voter reg, and taxes are not things that are "tracked", that's just basic citizenship requirements.

A national ID would make the few cases where you need to hide your identity (like you're a 10 year old girl who was raped and needs an abortion, or the doctor that needs to perform it - https://www.seattletimes.com/nation-world/10-year-old-rape-v...) much harder. Until our government decides not to be so fucking crazy, we need to push back on its ability to unjustly track and then punish its citizens.

Re: Librarian's Letter to Google Security

#209

Earlier quoted context omitted.

Customer support that has access to google accounts, that can give everyone telling a sob story to some customer service rep access to your account?

This comment does raise a serious concern. The primary reason why cell phone numbers are bad for 2FA is sim swapping, which can only occur because there is a customer support rep who can fall for it. Email is largely immune to that right now because customer support generally cannot let you into an account you locked yourself out of. This isn't to say that this is an unsolvable problem, it's not, but it's definitely…

I'd like to see the Post Office (in the US) get involved.

Post offices are geographically ubiquitous, already deal with identity verification, and already have to maintain the trustworthiness of their workforce.

I'd like to see a system where (a) an account [whether GMail, Facebook, Schwab or Bob's Online Pet Food Mart] can be tied to a real-world identity and (b) when you lose access, you can go to the local post office to verify your identity and get a one-time recovery token for a given account.

Re: Librarian's Letter to Google Security

#210
post #180
post #158

Earlier quoted context omitted.

So we disagree on the best tactics to take here. In particular, I think the embarrassing tech companies in public works when it's done by either other tech people OR it gets into the media where the bottom line could be impacted. This That doesn't make me 'cringe^inf' or boil down my tactical critiques to '"she's not asking nicely enough'. I presumed you were attempting to call me out for tone policing, and usually t…

the call out was more in line with a general disagreement with what i saw as a tech industry apologist take. i don't think people who work in the tech industry are bad people, but if people are losing housing because of their products, inventions, or service policies, then it appears that they have certainly (possibly inadvertently!) done some very bad things and that needs to be acknowledged plainly and clearly. no…

That's fair, that would be a decent read on the comment assuming average HN demographics. I am a librarian who was raised by hackers, so I was programming and playing around online for years before starting library work and eventually getting my MLIS. So I was critiquing her from a colleague's POV of 'this clearly isn't your area of expertise, why didn't you ask a colleague who does know this area so the letter was stronger?' I wouldn't write a letter about, say, the impact of social media on kids' media without talking to some of the children's librarians I know, since I don't know much about children's services.

Also libraries have a major cultural issue of their own, which is that they love credentialism and gatekeeping, and part of that manifests through assumptions that they and only they know the right thing to do (you'll note she suggests that Google contact her for more information rather than perform their own research or, God forbid, asking the userbase directly). Related to this, librarians, because of their vocational awe, are very, very susceptible to forms of communication that affirm their righteousness, and I see signs of that in this letter. From a communications standpoint, it's just not ideal to ask people do something by shaming them and assuming a stance of superiority while ignoring some context. That's just asking to be dismissed.

So that's where I'm coming from.

I actually greatly agree that tech culture needs to change.

> embarrassing companies in public is an old tactic that predates consumer technology companies by a large margin. in the old days letters would appear in trade rags or newspapers to the same effect.

Same problem, though. Embarrassing a company in a trade rag means that your employees are going to be judged by their peers and you're going to have a hard time hiring new employees. Using a newspaper meant that it went through some sort of editorial gatekeeping and the newspaper determined it was an issue that was likely to blow up. There were also plenty of cranky letters to the editor/opinion pieces in newspapers (especially smaller ones) that were dismissed as 'lol old people be cranky'. You have to have a strategy there.

I actually miss public service a lot.

Post reply on HN