Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

251–260 of 484 posts

Re: Librarian's Letter to Google Security

#251

Earlier quoted context omitted.

> Wanna bet it was completely ignored? I just tweeted it to @Google. Maybe if enough people ping Google about it?

It's important to understand that Google is, as an organizational body, psychopathic in nature. (Many corporations are, but Google especially, through well-indoctrinated concepts like being solely data-driven and putting scale first, combined with a belief that Google hires the best people and hence is already doing the best possible thing.) Google does not care. You cannot make Google care. Employees who care get fi…

This is an extremely bleak perspective. Individuals care, but most are powerless to make a difference if they don't work in the area of concern. It's often a knowledge sharing game of making sure the right people hear about it which can be hard. They are intentionally shielded from direct feedback to keep them focused, but that is a double edged sword. I honestly believe the reason viral stories get resolved is because the information gets to the right people, not because of a desire to avoid bad PR. Google is a collection of largely independent tiny organizations.

Re: Librarian's Letter to Google Security

#252

I feel like fingerprint/iris/retinal scanners would be a reasonable stop-gap here if only there was some way to deploy them cheaply. Does anyone know if such add-ons exist that might be made compatible with a 2FA system?

Serious Question: Do iris/retinal scanners work on people with severe cataracts[1] ? --- [1] People with these are part of the demographic being discussed.

Huh! https://biomedical-engineering-online.biomedcentral.com/arti...

Re: Librarian's Letter to Google Security

#253
post #192

Earlier quoted context omitted.

Right. Why would these poor and often elderly people pay for a $5/month email service when there are several free options they choose instead?

Do any of them offer phone support?

You're missing the point. When a poor tech illiterate person signs up for an email account, they probably don't consider if they will someday need phone support to recover an account. They will choose a free account over an account that costs $5/month that they don't have. And that assumes that they even know about the paid email services. For a lot of tech illiterate people email and gmail are synonymous.

Re: Librarian's Letter to Google Security

#254
post #188

Earlier quoted context omitted.

And given that a lot of the staff working those desks aren't librarians + are working part time, it's also great incentive for bad actors to get jobs in libraries specifically to start stealing that data.

Not sure data theft from homeless or poor people is a major threat. What could an attacker gain from that?

I can see some value in it for scammers, hackers, and businesses that pray on the poor. (For example the 'buy now, pay later' Aaron's Rent-A-Center type businesses).

Or for identity theft.

Re: Librarian's Letter to Google Security

#255
I don't particularly love gmail and I'm personally trying to switch to fastmail over time, however I am on google's side this time around. There are reasonable approaches that can address this librarian's concern. Backup codes, backing up the MFA seed. She talks about patrons having cell service shutoff, but that doesn't affect google authenticator. There are good reasons why google went to an MFA only model and yes there are some downsides, but they're not unmanageable.

Re: Librarian's Letter to Google Security

#257
post #189

Earlier quoted context omitted.

> I would recommend a $5/month email service. Surprise! There is. https://workspace.google.com/intl/en_ie/pricing.html > Google Workspace Standard Support—Standard Support is included with your Google Workspace license. It provides support with a 4-hour service-level objective (SLO) for P1 cases. If you're interested in faster response times and additional Support services, Enhanced or Premium Support might be a bett…

Can you contact support if you can't log in?

Yes.

EDIT: it's not $5 in the US (between $6 and $7). I've called support a bunch of times.

Re: Librarian's Letter to Google Security

#258
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

a protocol where trusted civic authorities could be allowed to confirm someone's identity

This is already a solved problem, and without getting the government involved.

There are plenty of identification confirmation companies out there. If you've ever requested your credit report, or applied for a new apartment online, you've probably interacted with one.

Oh, but that's an expense. It might costs pennies per user! Google doesn't do expenses. It would rather spend money on rooms full of toys and gourmet catering than on helping people use its own products.

Re: Librarian's Letter to Google Security

#259
post #201

It looks like it is possible to use totp for your backup second factor, which would let the libraries store the secrets on paper and require ID for a password reset: https://webapps.stackexchange.com/questions/127464/enabling-... It looks like it is a pain in the neck, but also possible to use it as the main second factor, for people without phones. This reminds me, I need to move 100% off google’s ecosystem.

Google only recently made MFA mandatory, so most of these impacted users didn't really opt into MFA, they just didn't opt-out by closing their Google account. Likely the first time they realized they might need a backup option would be when they were locked out at the library and it was too late.

It is so incredibly heartless on Google's part to spring this on unsuspecting users, without any sort of customer service support. Most people having their accounts suddenly bricked aren't the type that can raise a twitter mob loud enough to actually get on the company's radar.

Re: Librarian's Letter to Google Security

#260
Rich and poor, young and old, have this in common. I know many college educated and affluent people that can't manage passwords or multi-factor authentication. Oh and don't ask them to save recovery codes because they will put them in highly insecure places... and then forget where they put them.
Post reply on HN