Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

241–250 of 484 posts

Re: Librarian's Letter to Google Security

#241

I fully sympathize with the librarian's concerns, but there's this: "Many government welfare forms, housing applications, and jobs applications these days require the use of the internet exclusively with no option to fill things out in person." Why is this? Really, this does not seem like a problem Google caused, but rather a problem caused by the government when they made it mandatory to have internet access to get…

> The government caused this problem.

It isn't just government forms, it is also private companies, employers, landlords, and even out-of-touch charities that are run by people who are used to having 24/7 access to reliable internet.

Re: Librarian's Letter to Google Security

#242
I am reminded of this every time I support an elderly person. Us techies are just not equipped to deal with the needs of everyday people. I used to get upset with them due to their lack of competence, but now I just feel embarrassed at how Kafkaesque all of this just is.

Re: Librarian's Letter to Google Security

#243
post #108

More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support.

I don't. Customer support is a cost sink that usually isnt empowered to do anything. Its more PR tactic to make people feel they are "heard" without resorting to twitter. In the email/business apps space, google is clearly not a monopoly. Presence/quality of customer support seems a very reasonable grounds to have normal competition over.

Customer support is a cost sink

Too bad. If you have a business (and Google is a business) that goes business with the public (which Google does), you should offer some form of customer services. It's what we human beings call "the right thing to do."

Yes, customer service costs money. It costs money for the dry cleaners, the restaurants, the banks, the car washes, the design firms, and every single other company on the planet. It's a basic part of the financials of running a business, and is called "cost of doing business."

Imagine if Google's vendors stopped offering Google customer service. Janitor didn't show up today? Well, clean your own office toilet today, technie. Surely, there's a YouTube tutorial for that.

Just because Google's a "tech" company, people on HN pretend like it's OK to not provide customer service. Bullshit. It has billions and billions and billions of dollars that it can throw at the customer service problem, but it doesn't for one simple reason: Greed.

How about the restaurant down the street maximizes its shareholder profits by not honoring your reservation? How about the dry cleaner optimizes its workflow by only being open three minutes a day? How about your kid's school right-sizes its workforce responsibilities by kicking your kid out on the street when you got stuck in traffic and couldn't pick him up at the exact moment the school bell rang?

If Google is so wonderful, full of so many smart people, then how come it can't solve its customer service problem? Ignoring the problem isn't a solution. You can do better™.

Re: Librarian's Letter to Google Security

#244
post #238

Earlier quoted context omitted.

> More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support. I would recommend a $5/month email service. It would be nice if free Gmail gave even more free stuff, but only a paid for service can really expect paid support staff. Having said that, this seems like a terrible idea from a security perspective. There may well be no way to desi…

*While the social engineering concern is a valid one, I suspect that Google's original reasons for not providing support were not opsec related. Google's 2FA system combined with their lack of support terrifies me as a security-literate user. Here's one example: I was traveling and signed into Google from a new location. Google prompted me to verify myself via two-factor auth, and the only method they allowed me to v…

The same thing happened to me. Eventually I was randomly allowed in, no idea how.

Re: Librarian's Letter to Google Security

#245
post #189

Earlier quoted context omitted.

> More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support. I would recommend a $5/month email service. It would be nice if free Gmail gave even more free stuff, but only a paid for service can really expect paid support staff. Having said that, this seems like a terrible idea from a security perspective. There may well be no way to desi…

> I would recommend a $5/month email service. Surprise! There is. https://workspace.google.com/intl/en_ie/pricing.html > Google Workspace Standard Support—Standard Support is included with your Google Workspace license. It provides support with a 4-hour service-level objective (SLO) for P1 cases. If you're interested in faster response times and additional Support services, Enhanced or Premium Support might be a bett…

Can you contact support if you can't log in?

Re: Librarian's Letter to Google Security

#246
post #213
post #169

Earlier quoted context omitted.

As with every other "simple solution" to a complex problem there are a few flaws: a) google will have to require a credit card in order to open an email b) person opening an email account must actually have a line of credit, e.g.: many of the people mentioned in the OP will not have it c) opens a new attack vector on google accounts, e.g.: people who secured their emails using 2FA app for example can now be attacked…

a and c can be solved by making it an option for 2fa instead of requiring it.

but you already know what will happen next, don't you? People would stop using 2FA, then some donkey on government contract with access to nuclear weapons gets hacked, and everybody would lose their mind: "how could google be so stupid to allow people not use 2FA?!?!?!"

Re: Librarian's Letter to Google Security

#247
post #187

Earlier quoted context omitted.

You're right, that online-only access is definately a government problem. But this: > Even when we clicked “I don’t have my phone” it asked her to open the Google app from the phone that she does not have. That's a google problem. Google fixing their problem would lessen the impact of the government problem. (And, more generally, make gmail a better service for lots of people.)

but what would Google do, how is it possible to fix? What's the point of having 2FA using the phone if you can bypass it by clicking "i don't have my phone"?

The "I don't have my phone" button only showing options that require a phone is a Catch-22 nightmare. They should remove that workflow, which is effectively just mocking the user, and instead emphasize recovery codes much more. These are free and would solve many of the problems in this letter, if only people knew and were heavily pushed to print them beforehand.

Re: Librarian's Letter to Google Security

#248
post #202
post #140

Earlier quoted context omitted.

> If the person lost their actual keys and wallet, they've got bigger problems Do they? Typically for those sorts of things you have recovery options. Your landlord will be able to get you a new key, your bank can issue you a new card. Looking through my wallet, the only thing that would have a significant hurdle to replacing it is my Egyptian residence permit (I'd have to travel to Egypt to re-issue it). The only si…

> Looking through my wallet, the only thing that would have a significant hurdle to replacing it is my Egyptian residence permit Maybe don't carry that in your wallet if you don't need it where you are and it's so hard to replace. :)

You're absolutely right, I also realised that while going through stuff :) It's going to stay home tomorrow!

It's one of those things you just kinda forget about when you don't need them for a while ...

Re: Librarian's Letter to Google Security

#249
post #108

More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support.

> More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support. I would recommend a $5/month email service. It would be nice if free Gmail gave even more free stuff, but only a paid for service can really expect paid support staff. Having said that, this seems like a terrible idea from a security perspective. There may well be no way to desi…

only a paid for service can really expect paid support staff.

Why?

You make it sound like Google is a pauper, doling out free e-mail accounts and not making any money off of it.

Just because it's not billing your credit card doesn't mean you're not paying for GMail. You just pay for it indirectly through advertising.

If only a paid service can expect paid support, then how does Google make hundreds of billions of dollars every quarter? If GMail wasn't making any money, it would have been shut down years ago.

Re: Librarian's Letter to Google Security

#250
post #229

If the US government created its own SSO system and mandated that all government website used it as primary while allowing third parties to use it too this could become a solved problem. It would be a credential that could be accessed via existing paper based systems. Places like Google allowing it as a sign in method would actually solve this case. Sadly I think the tech world in general is so allergic to losing pri…

login.gov exists. It's not mandated, nor does it currently allow non-government users(last I checked), but otherwise it generally solves the technical problems fine.

It's used to manage your Global Entry membership.
Post reply on HN