Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

211–220 of 484 posts

Re: Librarian's Letter to Google Security

#211

The author is 100% not wrong, but the problem is that, unfortunately, it is entirely possible that Google cannot have an authentication system that is correct for use by the elderly in a shared-machine environment while being correct for everyone else at the same time. There are options to fix this, but they're social, not technical. To get there, let's start with the technical side of why the author's proposed fix w…

> Another option is that a service libraries could provide (at possibly great expense to themselves, but options on the table) would be to serve as a credentials broker for their users. Have the library keep track of the 2FA side of things. Risky and adds expense to the library, but for this userbase that local service is the missing piece of the puzzle. Unfortunately, this isn't something Google is set up to provide; they're too centralized, they aren't actually in the communities where the need lies.

This. I wrote as much in an earlier comment. Why not allow the option to delegate a trusted third party to manage $ACCOUNT MFA flow? I'd use it (and kind of already do, via the recovery email addresses) for managing my aged parents accounts.

This seems like not that hard in terms of implementation and UX. What is the risk/expense from the libraries PoV you are alluding to?

Re: Librarian's Letter to Google Security

#212

Great letter. Wanna bet it was completely ignored? Glad to see it here. Maybe it won't be ignored. Librarians rock. There's even a show about them[0], Starring Number One. I can't access the gMail account I set up, because I made a mistake, when setting the password, and did not save the one I used. It will not allow me to access the account I set up. After a while, I just gave up. I am satisfied that someone can't u…

> Starring Number One.

OG Mystique as well. Rebecca Romijn has done some great roles.

Re: Librarian's Letter to Google Security

#213
post #169

Earlier quoted context omitted.

Your concern while valid seems solvable. They could preauthorize a random token amount on credit card with matching details, have you call the number on the back of your card to figure out that amount and then you have to input that number to authorize the access in an oath like flow. Please tell me if you see something wrong with my procedure? edit: I saw something wrong, I have forgotten about the vast unbanked pop…

As with every other "simple solution" to a complex problem there are a few flaws: a) google will have to require a credit card in order to open an email b) person opening an email account must actually have a line of credit, e.g.: many of the people mentioned in the OP will not have it c) opens a new attack vector on google accounts, e.g.: people who secured their emails using 2FA app for example can now be attacked…

a and c can be solved by making it an option for 2fa instead of requiring it.

Re: Librarian's Letter to Google Security

#214

Great letter. Wanna bet it was completely ignored? Glad to see it here. Maybe it won't be ignored. Librarians rock. There's even a show about them[0], Starring Number One. I can't access the gMail account I set up, because I made a mistake, when setting the password, and did not save the one I used. It will not allow me to access the account I set up. After a while, I just gave up. I am satisfied that someone can't u…

> Wanna bet it was completely ignored? I just tweeted it to @Google. Maybe if enough people ping Google about it?

It's important to understand that Google is, as an organizational body, psychopathic in nature. (Many corporations are, but Google especially, through well-indoctrinated concepts like being solely data-driven and putting scale first, combined with a belief that Google hires the best people and hence is already doing the best possible thing.)

Google does not care. You cannot make Google care. Employees who care get fired, or burn out trying to make the company care, and inevitably quit. Google is Google, and the only thing that's going to make it change is regulation.

Re: Librarian's Letter to Google Security

#215

I fully sympathize with the librarian's concerns, but there's this: "Many government welfare forms, housing applications, and jobs applications these days require the use of the internet exclusively with no option to fill things out in person." Why is this? Really, this does not seem like a problem Google caused, but rather a problem caused by the government when they made it mandatory to have internet access to get…

> Really, this does not seem like a problem Google caused,

The problem is 2FA. 2FA causes people to get locked out of their accounts. Google mail requires 2FA, the government does not. If Google turns off 2FA requirement, the problem in the letter goes away. But they won't.

Google is the cause of the problem, and can easily solve it.

Re: Librarian's Letter to Google Security

#216
post #201

It looks like it is possible to use totp for your backup second factor, which would let the libraries store the secrets on paper and require ID for a password reset: https://webapps.stackexchange.com/questions/127464/enabling-... It looks like it is a pain in the neck, but also possible to use it as the main second factor, for people without phones. This reminds me, I need to move 100% off google’s ecosystem.

Google only recently made MFA mandatory, so most of these impacted users didn't really opt into MFA, they just didn't opt-out by closing their Google account. Likely the first time they realized they might need a backup option would be when they were locked out at the library and it was too late.

Re: Librarian's Letter to Google Security

#217

Great letter. Wanna bet it was completely ignored? Glad to see it here. Maybe it won't be ignored. Librarians rock. There's even a show about them[0], Starring Number One. I can't access the gMail account I set up, because I made a mistake, when setting the password, and did not save the one I used. It will not allow me to access the account I set up. After a while, I just gave up. I am satisfied that someone can't u…

[deleted]

Re: Librarian's Letter to Google Security

#218

I fully sympathize with the librarian's concerns, but there's this: "Many government welfare forms, housing applications, and jobs applications these days require the use of the internet exclusively with no option to fill things out in person." Why is this? Really, this does not seem like a problem Google caused, but rather a problem caused by the government when they made it mandatory to have internet access to get…

Google is still a huge part of the problem for requiring all kinds of acrobatics to log into their service which you are forced to use due to the fact that it's one of the only free email providers, the fact that email is pointlessly required to use most websites, and the fact that a huge amount of websites only allow gmail and a few other hosts (yes, there are also other stupid websites that go the other way around and block gmail, yahoo, etc). Government is at fault for not using their billions of dollars to create a simple _modern_ protocol to transfer information. Using web for banking or tax purposes should be illegal just as it would be to use a kids toy radio in the military.

Re: Librarian's Letter to Google Security

#219
post #204

Here's an idea: Why not allow the owner of a Google account to delegate a trusted third party who can handle MFA/otherwise approve logins on their behalf. I kind of do this already by setting the recovery emails for family members (especially aged parents) Google accounts to those that I control, but to my knowledge it is not possible to do the same for the mobile number used to secure the account. This way, at least…

So the biggest problem is that every optional feature you offer up does not help when someone walks into the library already locked out. The vast majority of society will never be aware of available options and features for their Google account, so it's only the default behavior that matters. Most people locked out of their account could've set up some sort of way to get in (like backup codes), if hindsight was 20/20 and they knew a lot about Google accounts.

You could add a feature like this, and maybe it helps one out of every hundred people who try to log in at this library, and that's optimistic at best.

Re: Librarian's Letter to Google Security

#220

I feel like fingerprint/iris/retinal scanners would be a reasonable stop-gap here if only there was some way to deploy them cheaply. Does anyone know if such add-ons exist that might be made compatible with a 2FA system?

Serious Question: Do iris/retinal scanners work on people with severe cataracts[1] ?

---

[1] People with these are part of the demographic being discussed.

Post reply on HN