Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

281–290 of 484 posts

Re: Librarian's Letter to Google Security

#281

Earlier quoted context omitted.

This comment does raise a serious concern. The primary reason why cell phone numbers are bad for 2FA is sim swapping, which can only occur because there is a customer support rep who can fall for it. Email is largely immune to that right now because customer support generally cannot let you into an account you locked yourself out of. This isn't to say that this is an unsolvable problem, it's not, but it's definitely…

I'd like to see the Post Office (in the US) get involved. Post offices are geographically ubiquitous, already deal with identity verification, and already have to maintain the trustworthiness of their workforce. I'd like to see a system where (a) an account [whether GMail, Facebook, Schwab or Bob's Online Pet Food Mart] can be tied to a real-world identity and (b) when you lose access, you can go to the local post of…

Google already has the ability to generate one time use recovery codes, at least for gmail accounts -- not sure if it is generally integrated into their Authenticator app. You could generate some recovery codes and put them in a safe deposit box or something I guess.

This sort of solution (and your post office idea) can be, but they don't satisfy the last resort customer service role, for people who haven't set these kinds of recovery options up.

Re: Librarian's Letter to Google Security

#282
post #259

Earlier quoted context omitted.

Google only recently made MFA mandatory, so most of these impacted users didn't really opt into MFA, they just didn't opt-out by closing their Google account. Likely the first time they realized they might need a backup option would be when they were locked out at the library and it was too late.

It is so incredibly heartless on Google's part to spring this on unsuspecting users, without any sort of customer service support. Most people having their accounts suddenly bricked aren't the type that can raise a twitter mob loud enough to actually get on the company's radar.

Google did provide some advance warning that was coming.

Also, accounts without MFA were also also causing harm. Some vulnerable populations also didn't realize how easily a non-MFA'ed account could be taken over remotely due to a weak password. And then due to "password reset" functionality, a Gmail account takeover can pivot to cause greater harm.

This is a classically difficult problem: improving security often reduces convenience. The trade-off Google chose to mandate for all users was not the best for users without stable phone access.

Re: Librarian's Letter to Google Security

#283

Earlier quoted context omitted.

So the biggest problem is that every optional feature you offer up does not help when someone walks into the library already locked out. The vast majority of society will never be aware of available options and features for their Google account, so it's only the default behavior that matters. Most people locked out of their account could've set up some sort of way to get in (like backup codes), if hindsight was 20/20…

At what point is it reasonable to start assuming basic security/computer literacy on the part of the public (to the point where, if you screw up, it is your fault for screwing up and not the computer/companies fault for not telling you something)? This is an open question. We are not there yet, but at the same time I don't think it's tenable in the long term to be in the state of assuming the user can't be trusted to…

So, my grandmother knows drastically less about computers than she used to. She actually previously used email with regularity, and has since forgotten about even the existence of the email account she had for fifteen years. Unless we have a cure for memory loss in seniors, new less computer literate people will be occurring every day.

So the answer is, unfortunately, never. There will always be people who are not computer literate, and if we want basic services to be available via the Internet, as many government services now are, we have to include systems that include these people.

You can't just discard the poor because they aren't computer literate.

Re: Librarian's Letter to Google Security

#284
post #187

Earlier quoted context omitted.

You're right, that online-only access is definately a government problem. But this: > Even when we clicked “I don’t have my phone” it asked her to open the Google app from the phone that she does not have. That's a google problem. Google fixing their problem would lessen the impact of the government problem. (And, more generally, make gmail a better service for lots of people.)

but what would Google do, how is it possible to fix? What's the point of having 2FA using the phone if you can bypass it by clicking "i don't have my phone"?

well what every other service relying on OTP or YubiKey for 2FA (not that SMS bullcrap) has ever did: recovery codes you write down somewhere. it can even be as simple as writing them down on the library card carried in the wallet.

Re: Librarian's Letter to Google Security

#285

Earlier quoted context omitted.

This comment does raise a serious concern. The primary reason why cell phone numbers are bad for 2FA is sim swapping, which can only occur because there is a customer support rep who can fall for it. Email is largely immune to that right now because customer support generally cannot let you into an account you locked yourself out of. This isn't to say that this is an unsolvable problem, it's not, but it's definitely…

I'd like to see the Post Office (in the US) get involved. Post offices are geographically ubiquitous, already deal with identity verification, and already have to maintain the trustworthiness of their workforce. I'd like to see a system where (a) an account [whether GMail, Facebook, Schwab or Bob's Online Pet Food Mart] can be tied to a real-world identity and (b) when you lose access, you can go to the local post of…

I understand, and agree with you, but at the same time, a HUGE number of people don't have that identification. Many homeless people that could qualify for services struggle to prove who they are, and that they are able to receive it (especially vets) because they have lost their ID, have no idea where their birth certificate is (or marriage license), and have no home to show multiple bills to that address in their name.

Re: Librarian's Letter to Google Security

#286
post #108

More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support.

Americans with disabilities act?

Haha, google doesn't provide good customer service for able bodied, so they provide the equal service for disabled.

Big tech needs a reckoning from consumer protection. Oh wait, those laws and the government agency were gutted. Nevermind.

Being a relatively new parent, the lack of consumer protection regulation in things like kids apps, youtube ads, and similar is APPALLING. I recall from my youth TV programming was highly regulated, arguably a bit too much, but at least the advertising industry had to stay within bounds.

App and youtube ads are the wild west, especially freemium games using any and all addictive mechanisms to extract money from kids and their parents.

Aside from that, big tech can't have it both ways. They can't be major providers of "cyberspace" services and provide no means for customer service or protection from their security automated services locking out someone. Why this isn't subject to large civil penalties, massive class action lawsuits, and even criminal violation of federal law is beyond me.

Terms of Service can't cover all of those, but then again, I haven't read them so...

Online services are steadily gaining importance equal to things like banking. Can you imagine a bank locking you out of your accounts and providing no means to get YOUR MONEY? Well, replace money with information. Why can't you get access to YOUR INFORMATION?

I understand the ToS providing the rights to analyze and use YOUR INFORMATION as part of the service, but we need federal legislation equal to the EU laws that I think do a better (but from what I can tell incomplete) job of delimiting the rights you have to YOUR INFORMATION.

Re: Librarian's Letter to Google Security

#287

Earlier quoted context omitted.

I will pass on that, no one should be required to accept messages from anyone

How about "required to not mark as spam"?

I am not a fan of regulation in general

But SPAM should be resolved with strict adherence to standards like SPF, DKIM, etc. and where those fail it should be improved

Today many companies, large and small, as well as government agencies, large and small do SPF and DKIM very very very wrong.

Unless we can get this right I fail to see how regulations would do anything other than make things worse

Some of the biggest SPAM abusers are not the small providers but the Large companies like Gmail and Microsoft who do not vet their customers very well

Re: Librarian's Letter to Google Security

#288
post #204

Here's an idea: Why not allow the owner of a Google account to delegate a trusted third party who can handle MFA/otherwise approve logins on their behalf. I kind of do this already by setting the recovery emails for family members (especially aged parents) Google accounts to those that I control, but to my knowledge it is not possible to do the same for the mobile number used to secure the account. This way, at least…

So the biggest problem is that every optional feature you offer up does not help when someone walks into the library already locked out. The vast majority of society will never be aware of available options and features for their Google account, so it's only the default behavior that matters. Most people locked out of their account could've set up some sort of way to get in (like backup codes), if hindsight was 20/20…

Or how about if google sees you log into a computer associated with a library IP address more than once it offers to help you set this up. With some sort of special dialog that specifically targets people in this situation. And it periodically reminds you to confirm you still have these recovery codes saved somewhere and if you don’t helps you create new ones. I know this isn’t google scale but it’s a nice feel good story that google could trot out at I/O

Re: Librarian's Letter to Google Security

#289
post #211

The author is 100% not wrong, but the problem is that, unfortunately, it is entirely possible that Google cannot have an authentication system that is correct for use by the elderly in a shared-machine environment while being correct for everyone else at the same time. There are options to fix this, but they're social, not technical. To get there, let's start with the technical side of why the author's proposed fix w…

> Another option is that a service libraries could provide (at possibly great expense to themselves, but options on the table) would be to serve as a credentials broker for their users. Have the library keep track of the 2FA side of things. Risky and adds expense to the library, but for this userbase that local service is the missing piece of the puzzle. Unfortunately, this isn't something Google is set up to provide…

If the library is holding even a piece of users' credentials, they become liable for either intentional or unintentional harm. On the unintentional side: their 2FA back-stop solution could be compromised or stolen by a third-party because they failed to secure it (they'll be a smaller target... Crooks will get very little from stealing access to a small population of older folks over what they'd get for, say, finding a reliable way to compromise any Gmail user's access... But they'll be a target). On the intentional side: they now have to move the bar on vetting whoever staffs the project from "trusted enough to be a librarian" to "trusted enough to be a keeper of passwords or reset emails..." Which, TBH, may be a lateral move, since librarians know what books we read. ;)

But the insider attack situation here is nasty... A corrupt individual in the loop could trivially trigger a password-reset attempt, use the fact they have control over the user's 2FA (or recovery email) to steal the user's credentials, act on behalf of the user for a bit (reroute benefits to some other address?), and then just wait for the user to discover their password is locked out and kindly help them correct it.

Re: Librarian's Letter to Google Security

#290
I had a gmail lockout scare recently for my custom domain. And I deeply want to change providers. google is currently both my e-mail provider and my domain registrar.

The only thing holding me back is I have a custom domain, I'm not specialized in the web, and it's not super intuitive how to set up my hosting with one company, name registration with another, and e-mail with a third. All for the same custom domain.

Post reply on HN