Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

221–230 of 484 posts

Re: Librarian's Letter to Google Security

#221
If the US government created its own SSO system and mandated that all government website used it as primary while allowing third parties to use it too this could become a solved problem. It would be a credential that could be accessed via existing paper based systems. Places like Google allowing it as a sign in method would actually solve this case. Sadly I think the tech world in general is so allergic to losing privacy that even something optional like this would get lobbied out of existence just by tech companies alone.

Re: Librarian's Letter to Google Security

#222

The silent majority of us in the tech world knew (and know) that 2fa is a mess, will always be a mess, but for whatever reason the security-obsessed people have taken over the industry in the last few years and here we are, elderly people actually: > losing their welfare benefits, their housing, and struggle to find work. because of technical decisions centered on security. I'm not sure what would be the best way for…

> security-obsessed people

More like “incompetent, self-proclaimed security experts.” The three pillars of security are availability, integrity and confidentiality. Google’s auth flow aggressively face plants on the first requirement.

Re: Librarian's Letter to Google Security

#223
post #23

Earlier quoted context omitted.

That sounds like a good idea! Perhaps expand what notaries do?

It sounds nice. if everyone plays nice. Slip some underpaid gov worker a 50 and suddenly you are someone else. There would need to be abuse provisions put in place. Then a whole org around that too. Not saying it can not be done, but it looks like to me is Google has a poor customer service issue, even if not true. Roping our govs into doing googles customer service seems odd.

It's a real concern, but how is this different from the current ink & paper scenario? I know people who use county notaries to keep important documents and we, as a society, have apparently deemed that an acceptable risk. Is the distinction the potential scope and scale of digital theft?

Re: Librarian's Letter to Google Security

#224
post #47

Shelly Rosen is a hero, and should be recognized as one. It is not very often I get to read business requirements that are so clearly defined. Kudos. This letter should be obligatory reading in schools.

It's a good letter.

I'd like to see another letter drafted to other librarians recommending specific competing email providers that people who are MFA-challenged should use for anything important.

Re: Librarian's Letter to Google Security

#225
post #182

One thing that the library could do is store the cookies of their patrons, and restore those next time they use a library computer. This would avoid the most common case of the problem. I suspect this is the only feasible solution; Google is certianly never going to bother with these people.

This would be a massive security risk, holding that information on the machines, or even in a central location (as roaming profiles which not even MS recommend anymore).

Re: Librarian's Letter to Google Security

#226

Earlier quoted context omitted.

Indeed, but this will then going to face the issue of Gmail (et al.) refusing to accept e-mail sent from small providers.

I am sure a another huge vendor like Amazon, facebook, or Microsoft will step in to provide the email services :)

This is where regulations can step in, to require email providers to accept mail from essential service providers.

Re: Librarian's Letter to Google Security

#227

Classism via Internet. When Uber and Lyft became popular and you still needed a smartphone and mobile connection to use it, it basically became a way to keep poor people segregated in transportation. If you couldn't afford a smartphone, or a data plan, or only sporadically, you were relegated to the public transportation options which are slowly defunded as Lyft and Uber lobby governments to become the "more affordab…

My town now as "app-only" parking spots. (Maybe there's some fine print on the sign about another way to pay, but it's not clear from 10 feet away if so).

Re: Librarian's Letter to Google Security

#228
post #192

Earlier quoted context omitted.

> More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support. I would recommend a $5/month email service. It would be nice if free Gmail gave even more free stuff, but only a paid for service can really expect paid support staff. Having said that, this seems like a terrible idea from a security perspective. There may well be no way to desi…

Right. Why would these poor and often elderly people pay for a $5/month email service when there are several free options they choose instead?

Do any of them offer phone support?

Re: Librarian's Letter to Google Security

#229

If the US government created its own SSO system and mandated that all government website used it as primary while allowing third parties to use it too this could become a solved problem. It would be a credential that could be accessed via existing paper based systems. Places like Google allowing it as a sign in method would actually solve this case. Sadly I think the tech world in general is so allergic to losing pri…

login.gov exists. It's not mandated, nor does it currently allow non-government users(last I checked), but otherwise it generally solves the technical problems fine.

Re: Librarian's Letter to Google Security

#230
All the anger toward Google misses the larger point – this isn’t only Google's problem. If I get locked out of my Apple account, or my Amazon account, or my account, how do I prove that I am me? A password? I’m glad your memory is much better than mine, because I'm terrible at remembering 1000 passwords that aren’t trivially cracked. Use a password manager? Oh yeah! I do, thanks. On my computer and phone along with... my 2FAs.

What I need is a way to get into my personal accounts when I find myself naked and alone on the street (don’t judge, you don’t know how I got there). And the only way to do that is to be able to physically present myself at some place and have them verify my identity, allowing me access to my digital life again – and hopefully let me to call my wife to being me some clothes.

Basic identity verification is the type of function that everyone will need at some point as a common public service. The kind I would expect a government to provide.

Post reply on HN