Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

261–270 of 484 posts

Re: Librarian's Letter to Google Security

#261
post #204

Here's an idea: Why not allow the owner of a Google account to delegate a trusted third party who can handle MFA/otherwise approve logins on their behalf. I kind of do this already by setting the recovery emails for family members (especially aged parents) Google accounts to those that I control, but to my knowledge it is not possible to do the same for the mobile number used to secure the account. This way, at least…

So the biggest problem is that every optional feature you offer up does not help when someone walks into the library already locked out. The vast majority of society will never be aware of available options and features for their Google account, so it's only the default behavior that matters. Most people locked out of their account could've set up some sort of way to get in (like backup codes), if hindsight was 20/20…

> So the biggest problem is that every optional feature you offer up does not help when someone walks into the library already locked out. The vast majority of society will never be aware of available options and features for their Google account, so it's only the default behavior that matters.

Fair enough. I live in the EU, we all have state-issued ID cards and no cultural problem with using them, so presenting those via some channel to Google would work here, but I can't imagine it working in the states.

Re: Librarian's Letter to Google Security

#262

Would it be possible for libraries to provide email addresses through their own mail servers? Certainly Google has an enormous number of issues, but I can't see them weighing in favor of the elderly and less fortunate over the high profile users whose accounts are constantly targeted. I also have doubts that any bypass solution would succeed due to necessarily requiring users to both know their existence and properly…

Yes, and Google will immediately blacklist those mail servers for being small just like they do with everyone else.

Re: Librarian's Letter to Google Security

#264

Why is the US so far behind the rest of the world when it comes to technology? State IDs/Driving Licenses already exist. These should have chips on them that could be used for authentication.

The main reason we don't want a ubiquitous national ID is that once it's there, everything will require it, which means everything you do will be tracked. Which is okay until the government decides to go psycho and attack some section of the population. Right now, literally every red state would love to get their hands on logs filled with IDs of people who have anything to do with abortion (a Texas bill makes it ille…

I'd be more sympathetic to this argument if all that info weren't a couple subpoenas or search-warrants away at most—in fact, the government can often just pay for access to these things, usually with the implicit threat that if access isn't granted at a reasonable rate, the business may find itself in some trouble. Like, if we banned private parties from collecting tons of info about us, then maybe that concern would have some merit, but we don't, so it doesn't.

Point is, they don't need a national ID to pin you to some cell phone records that place you at location X at time Y, to get your CC usage data, to find out pretty much anything they like, to connect that to a license plate, to snag toll and other photo records of the vehicle from various sources, et c., and the only reason there are any restrictions whatsoever on that ability isn't because we don't have a national ID, but because we're not yet living under a tyranny. Difficulty IDing people isn't the limiting factor.

The public-private hybrid ID we have now is terrible and also carries all the same risks under tyranny as a national ID, which is at least not-terrible.

It's not like having a national ID would mean all the spying-data companies collect on us would automatically be shared with the government—more than it already is, anyway. It'd be the same as now, except with fewer ID-related problems for people.

Re: Librarian's Letter to Google Security

#265
post #230

All the anger toward Google misses the larger point – this isn’t only Google's problem. If I get locked out of my Apple account, or my Amazon account, or my account, how do I prove that I am me? A password? I’m glad your memory is much better than mine, because I'm terrible at remembering 1000 passwords that aren’t trivially cracked. Use a password manager? Oh yeah! I do, thanks. On my computer and phone along with..…

The specific anger towards Google comes from the fact that they're an overwhelmingly popular email provider, and email is what a lot of paperless processes (including account resets) assume the existence of. If you get locked out of Amazon, or Facebook, or Instagram, or TikTok, or Reddit, or Twitter, or Netflix, you won't lose the ability to receive welfare benefits, or tax information, or rent / utility bills, or statements from your bank, or whatever. Everyone takes for granted that you have an email address that you can receive statements at, and that you'll use email as the central hub of communication, and sometimes the communication is legally mandated.

Also, it's considered sufficient for all those non-google tech services to just use your email address to get you back into their system. Netflix can send you an email. Facebook can send you an email. Twitter can send you an email. Netflix can send one, too. Gmail can't send you an email to authenticate you. You can never use email to get access to email. Using a Gmail account to try to unlock a Gmail account is an absurdity, like Baron Munchausen pulling himself out of a swamp by his own hair. You can use a cell phone to unlock email, but cell phone service will always cost money, and phones can be lost, broken, stolen, or sold for emergency funds. No library anywhere provides access to phones that make texts, and even if they did it wouldn't work because they'd be shared by people which would make them unsuitable for identification.

That's the reason for the focus. Fixing Gmail sort of "does the heavy lifting" for all the other services that need to get you to prove that you're you.

Re: Librarian's Letter to Google Security

#266

Earlier quoted context omitted.

Or now that I think about it… for 2FA in particular, what about enrolling a software FIDO token with an extension on every library computer that can be triggered by a librarian from their desk? Doesn’t require hardware for each patron, only applies to accounts that have been enrolled at the library. Feels like it could work.

Then it opens up a backdoor for malicious (or socially engineered) library staff to access email accounts.

I think it would be fine for the library to have/be the 2ND FACTOR and the user would still need their password. Being at a physical location seems like a reasonable 2FA (more reasonable than a phone in these cases).

Could the library buy a few FIDO tokens, hot glue them into the backs of the computers, users add them as 2fa to their accounts and now the computer being wiped between users is no longer an obstacle?

Re: Librarian's Letter to Google Security

#267

Earlier quoted context omitted.

It's not just Google, many corporations are starting to make "assumptions" about their customers, and these assumptions totally exclude entire groups of people. A great example I use is there are a ton of restaurants and fast food places around me. I used to walk to get lunch every day but eventually had to stop, these places realized most customers went through the drive through so they closed the lobby. Now even th…

> A great example I use is there are a ton of restaurants and fast food places around me. I used to walk to get lunch every day but eventually had to stop, these places realized most customers went through the drive through so they closed the lobby. Now even though this place is a 5 minute walk from me, it's no longer accessable if I'm not in a car. I think this may have to do COVID and then staffing shortages creati…

A lot of places won't let you do that for safety/liability reasons. And it's not a completely nonsensical concern, there are often multiple blind corners, people driving way too fast for conditions and only looking for other vehicles.

Re: Librarian's Letter to Google Security

#268

Great letter. Wanna bet it was completely ignored? Glad to see it here. Maybe it won't be ignored. Librarians rock. There's even a show about them[0], Starring Number One. I can't access the gMail account I set up, because I made a mistake, when setting the password, and did not save the one I used. It will not allow me to access the account I set up. After a while, I just gave up. I am satisfied that someone can't u…

>I made a mistake, when setting the password That's a feature, not a bug.

Yes, but not being able to recover the account, is a bug.

The issue was that I used a randomly-generated password from 1Password, and accidentally re-generated, before copying, so the original was lost.

That's a fairly common mistake. I'm usually careful to avoid that (now).

Re: Librarian's Letter to Google Security

#269

Earlier quoted context omitted.

You're right, that online-only access is definately a government problem. But this: > Even when we clicked “I don’t have my phone” it asked her to open the Google app from the phone that she does not have. That's a google problem. Google fixing their problem would lessen the impact of the government problem. (And, more generally, make gmail a better service for lots of people.)

Well, you can see the problem, right? Allowing attackers to bypass 2FA just by saying their phone is lost makes 2FA worthless.

Yeah.. but an "I don't have my phone" button that just tells people to use their phone is equally worthless.

I don't know what the right answer is, but that certainly isn't it.

Re: Librarian's Letter to Google Security

#270
post #43

Perhaps the solution is for libraries or local authorities to setup their own email providers. An email address “for life” with your library card, with the necessary support and in-person reset verification that their patrons need. I’m not suggesting this would be an easy or inexpensive undertaking, but maybe that’s just the next step in service evolution for a public information service like a library group.

i absolutely think this is the next step. we're at a point now where it's becoming obvious to even a layperson that we really are lacking a lot of agency over our lives, which has been given over to big tech companies to arbitrate. i also think it could be a way away from the monopoly of facebook over our social lives, to have e.g. library servers which run a local instance of mastodon, for local people, to be connec…

I'll extend off of your great commentary and suggest that the letter/small correspondence delivery portion of the USPS (not the parcel/package delivery segment) should be collaborating with U.S. libraries to establish more digital infrastructure for citizens; especially those who lack what others might consider the digital basics. This could include free/low cost email, local instances of ActivityPub servers, matrix (or other secure, but open source equivalent) chat services, etc. I understand this would open up many issues, and not an easy fix...but if more and more things are truly becoming more digitized, then government (and government-adjacent) services should not just evolve, but also help the citizenry evolve to take advantage of said services. At that point, i can imagine a scenario where if such a free/low cost email service were available, the likes of google and microsoft could not block digital correspondence since there would be at least some regulatory framework/policy in place to avoid such issues. Again, none of this is easy, but i feel the path forward can still leverage gov. entities - like libraris and USPS - that have greatly helped citizens in the past throughout our history.
Post reply on HN