Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

231–240 of 484 posts

Re: Librarian's Letter to Google Security

#231
post #108

More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support.

I don't.

Customer support is a cost sink that usually isnt empowered to do anything. Its more PR tactic to make people feel they are "heard" without resorting to twitter.

In the email/business apps space, google is clearly not a monopoly. Presence/quality of customer support seems a very reasonable grounds to have normal competition over.

Re: Librarian's Letter to Google Security

#232

Yeah, Google just doesn't give a shit. I was a gmail user since gmail was in private beta 18 years ago. I never had a phone number associated with it. And yet two or three years ago when I tried to log in Google decided to just... not let me do that, because fuck you, and started extorting me to give it a phone number. If I don't give it a valid phone number it won't let me access my email. But I can't really do that…

It's not just Google, many corporations are starting to make "assumptions" about their customers, and these assumptions totally exclude entire groups of people. A great example I use is there are a ton of restaurants and fast food places around me. I used to walk to get lunch every day but eventually had to stop, these places realized most customers went through the drive through so they closed the lobby. Now even th…

> Same thing with my TV and Router, both of which required an app to just setup

Off the top of my head, both Xfinity and Google Home have this problem and it aggravates me to no end. I can reset my gateway from my PC but for some reason, *need* to use my phone to manage Xfinity or any of my Nest routers

Re: Librarian's Letter to Google Security

#233
post #108

More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support.

I don't. Customer support is a cost sink that usually isnt empowered to do anything. Its more PR tactic to make people feel they are "heard" without resorting to twitter. In the email/business apps space, google is clearly not a monopoly. Presence/quality of customer support seems a very reasonable grounds to have normal competition over.

Hm? I'd say about 80% of calls I make to customer service accomplish the goal I have (canceling something I can't cancel online, doing some kind of "identity verification," etc.).

Re: Librarian's Letter to Google Security

#234

I fully sympathize with the librarian's concerns, but there's this: "Many government welfare forms, housing applications, and jobs applications these days require the use of the internet exclusively with no option to fill things out in person." Why is this? Really, this does not seem like a problem Google caused, but rather a problem caused by the government when they made it mandatory to have internet access to get…

Google is still a huge part of the problem for requiring all kinds of acrobatics to log into their service which you are forced to use due to the fact that it's one of the only free email providers, the fact that email is pointlessly required to use most websites, and the fact that a huge amount of websites only allow gmail and a few other hosts (yes, there are also other stupid websites that go the other way around…

> a huge amount of websites only allow gmail and a few other hosts

Is that actually true? I’ve never seen a single site that didn’t allow me to log in with a ‘regular’ email address, even if they pushed Log in with Google first

Re: Librarian's Letter to Google Security

#235
post #91
post #54

This is one of those situations that make it incredibly clear that even Google, with all its resources, never considers the use case or life experience of anyone besides a wealthy Bay Area tech worker when designing their products. I can't help but wonder how this blind spot got so big - and why they still don't address things like this even with all the user testing & A/B trials they do for ruthless optimization. Is…

So how does your company handle these cases while defending against social engineering attacks to steal all private data? The security wisdom I've always seen was to use 2FA and prevent other attempts at authentication, but if Google is evil for doing this security... what's the answer?

I get the impression Apple stores handle this reasonably well (though you lose data after a last-ditch password reset if and only if that data is unavailable to law enforcement warrants).

Anyway, I think the the common case is that most data is recoverable with an ID or whatever they require. FWIW, searching HN for: “locked out of icloud” doesn’t produce much.

Re: Librarian's Letter to Google Security

#236

Earlier quoted context omitted.

I am sure a another huge vendor like Amazon, facebook, or Microsoft will step in to provide the email services :)

This is where regulations can step in, to require email providers to accept mail from essential service providers.

I will pass on that, no one should be required to accept messages from anyone

Re: Librarian's Letter to Google Security

#237
This is not really Google's "fault". (trust me I'm not a fan of their cavalier attitudes to beta services and lack of customer support)

They are working "in the future" where every human has access to the virtual world by "right". You cannot cut off someone's gas or phone without huge regulatory hurdles. And we will see something similar for access to internet

We just aren't there. And that's the problem.

And this conversation should not be about "google should reduce its security" it should be about how do we regulate ISPs and google and facebook and Email providers so that they are on par with the gas company?

Is access to http a basic utility? Access to an email inbox?

In short Internet access is a necessity for access to civil society, and now we work out who pays for it. it's going to be a fun decade

Re: Librarian's Letter to Google Security

#238
post #108

More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support.

> More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support. I would recommend a $5/month email service. It would be nice if free Gmail gave even more free stuff, but only a paid for service can really expect paid support staff. Having said that, this seems like a terrible idea from a security perspective. There may well be no way to desi…

*While the social engineering concern is a valid one, I suspect that Google's original reasons for not providing support were not opsec related.

Google's 2FA system combined with their lack of support terrifies me as a security-literate user. Here's one example: I was traveling and signed into Google from a new location. Google prompted me to verify myself via two-factor auth, and the only method they allowed me to verify by was by opening up the Google app on my iPhone and by confirming the provided number. I tapped "try another way", and gone was the option to verify via authenticator app.

I'm lucky that I had my phone on hand but I was dumbstruck. What if I lost my phone? I'd be screwed, locked out of my account with no way to fix it, even after following the best security practice of enabling 2FA via authenticator app, because Google took it upon themselves to say "screw your choice of security, open our app on the phone" (also, thereby coercing me to link my two devices to my ip address/location for analytics/targeting reasons, I'm guessing).

I could have done everything right and still gotten locked out of my account.

Re: Librarian's Letter to Google Security

#239
Would it be possible for libraries to provide email addresses through their own mail servers? Certainly Google has an enormous number of issues, but I can't see them weighing in favor of the elderly and less fortunate over the high profile users whose accounts are constantly targeted. I also have doubts that any bypass solution would succeed due to necessarily requiring users to both know their existence and properly set them up; not everyone has technical competence nor the experience to know for which resources to seek.

Re: Librarian's Letter to Google Security

#240
post #188

Earlier quoted context omitted.

Then it opens up a backdoor for malicious (or socially engineered) library staff to access email accounts.

And given that a lot of the staff working those desks aren't librarians + are working part time, it's also great incentive for bad actors to get jobs in libraries specifically to start stealing that data.

Not sure data theft from homeless or poor people is a major threat. What could an attacker gain from that?
Post reply on HN