Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

301–310 of 484 posts

Re: Librarian's Letter to Google Security

#301

Earlier quoted context omitted.

It's not just Google, many corporations are starting to make "assumptions" about their customers, and these assumptions totally exclude entire groups of people. A great example I use is there are a ton of restaurants and fast food places around me. I used to walk to get lunch every day but eventually had to stop, these places realized most customers went through the drive through so they closed the lobby. Now even th…

> A great example I use is there are a ton of restaurants and fast food places around me. I used to walk to get lunch every day but eventually had to stop, these places realized most customers went through the drive through so they closed the lobby. Now even though this place is a 5 minute walk from me, it's no longer accessable if I'm not in a car. I think this may have to do COVID and then staffing shortages creati…

Walking through a drive-thru probably becomes an insurance and liability risk; and depending on local laws, it might be seen as a pedestrian entering traffic.

Re: Librarian's Letter to Google Security

#302
post #174

Earlier quoted context omitted.

It’s an absolutely catastrophic experience, that they clearly don’t take seriously. Regulation solves this. I hate to say that, as so much of tech regulation is a ham-fisted disaster that misunderstands the problem and creates even bigger ones, but this is really a very serious problem that can ruin lives, and regulators really should step in here. I’ve known a couple of people who have been through this experience,…

Can you describe how regulation solves this problem, how exactly are you proposing for this regulation to work?

I’m not GP, but I expect that regulation could help by requiring customer service. Similar to banking.

And there could be an agency similar to CFPB where citizens could appeal who would then make formal investigations.

So regulation would force the workflow described in the article to not have a grim outcome for elderly users of gmail.

Re: Librarian's Letter to Google Security

#303
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

a protocol where trusted civic authorities could be allowed to confirm someone's identity This is already a solved problem, and without getting the government involved. There are plenty of identification confirmation companies out there. If you've ever requested your credit report, or applied for a new apartment online, you've probably interacted with one. Oh, but that's an expense. It might costs pennies per user! G…

A credit report on John Doe doesn't prove that I'm John Doe, it only tells you whether or not John Doe is likely to pay his bills on time.

This thread, in general, is a great example of engineer hubris. It looks at a complicated problem, and all the top discussion sub-threads are highly up-voted non-solutions to it.

Re: Librarian's Letter to Google Security

#304
My mother is 70 years old and recently had a stroke. Every week we're dealing with password issues which are mostly Google related. The good news is I've been able to switch most of her stuff over to Apple based tools and that's helped significantly, but getting over the hump of new technology was a pretty big hurdle, and costly to me in terms of time and money. My mom is in the same situation, and I shudder to think how she would navigate this without help from her family. Not everyone is as fortunate as my mom is, but what this librarian is describing really touched a nerve because I know if it's happening to my mom, a former Sun Microsystems employee, I know it can happen to anyone.

Re: Librarian's Letter to Google Security

#305

Earlier quoted context omitted.

I'd like to see the Post Office (in the US) get involved. Post offices are geographically ubiquitous, already deal with identity verification, and already have to maintain the trustworthiness of their workforce. I'd like to see a system where (a) an account [whether GMail, Facebook, Schwab or Bob's Online Pet Food Mart] can be tied to a real-world identity and (b) when you lose access, you can go to the local post of…

Google already has the ability to generate one time use recovery codes, at least for gmail accounts -- not sure if it is generally integrated into their Authenticator app. You could generate some recovery codes and put them in a safe deposit box or something I guess. This sort of solution (and your post office idea) can be, but they don't satisfy the last resort customer service role, for people who haven't set these…

This IS the reply Shelley Rosen needs to see, understand and impart to her patrons. It does not cost anything, it is secure and it works.

I feel 2FA is a class libraries should be teaching. I am off to my local library to volunteer as a resource for that specific purpose. Anybody going to join me at their local library?

I was going to make the recovery code comment myself, but instead I did a search to see if anyone else had done so. Kudos. If would vote this comment to the top of the discussion if I only could. IMO it should be (part of) a PSA.

Re: Librarian's Letter to Google Security

#306

Earlier quoted context omitted.

This comment does raise a serious concern. The primary reason why cell phone numbers are bad for 2FA is sim swapping, which can only occur because there is a customer support rep who can fall for it. Email is largely immune to that right now because customer support generally cannot let you into an account you locked yourself out of. This isn't to say that this is an unsolvable problem, it's not, but it's definitely…

I'd like to see the Post Office (in the US) get involved. Post offices are geographically ubiquitous, already deal with identity verification, and already have to maintain the trustworthiness of their workforce. I'd like to see a system where (a) an account [whether GMail, Facebook, Schwab or Bob's Online Pet Food Mart] can be tied to a real-world identity and (b) when you lose access, you can go to the local post of…

If the US weren't pathologically schizophrenic about actually providing service to citizens, the post office would

(a) still be a government agency, not a wholly-owned subsidiary,

(b) already provide email via government servers and clients in kiosks at the post office (and the personnel to staff the service and handle high-touch troubleshooting) instead of relying on private corporations and organizations to be the sole providers of what has become a necessary service, and

(c) provide basic banking services, knee-capping the payday lending and check-cashing industries.

... but it isn't that kind of country right now.

Re: Librarian's Letter to Google Security

#307

Earlier quoted context omitted.

I'd like to see the Post Office (in the US) get involved. Post offices are geographically ubiquitous, already deal with identity verification, and already have to maintain the trustworthiness of their workforce. I'd like to see a system where (a) an account [whether GMail, Facebook, Schwab or Bob's Online Pet Food Mart] can be tied to a real-world identity and (b) when you lose access, you can go to the local post of…

I understand, and agree with you, but at the same time, a HUGE number of people don't have that identification. Many homeless people that could qualify for services struggle to prove who they are, and that they are able to receive it (especially vets) because they have lost their ID, have no idea where their birth certificate is (or marriage license), and have no home to show multiple bills to that address in their n…

At some point, though, the solution doesn't become "make it possible for anyone to access any account without any proof of identity", it becomes "make it possible to live in society -- receive medical care, eat, be sheltered -- without any proof of identity".

Proof of identity should be a government function, and that we likely have millions of people in the US with no way to prove their identity has real-world consequences beyond the flaw in my post-office-account-recovery-scheme; it affects access to benefits, as you said, as well as voting and being able to even prove your citizenship. That should be fixed too, but I'm not sure we can do any better for internet identity verification than the post office fallback.

Re: Librarian's Letter to Google Security

#308

Earlier quoted context omitted.

I believe you can set up multiple keys. In this manner, a librarian could keep a "master key." This compromises security somewhat, since the library houses one of the second factors, but IMO it's preferable to total account lockout (and still superior to SMS verification).

if you’re using someone else’s computer, or a computer at a library, you have no security. TLS isn’t enough to be certain they haven’t intercepted the connection, installed their own root certs, or whatever else. I can’t think of any method to securely use someone else’s computer and connection unless you bring a live boot Linux USB or something, which I doubt applies to the intended audience here. Sure, having a phy…

Also consider that the yubikey is only the 2nd factor, the user still needs to enter the password. Obviously password resets are possible but might be a bit more of tip off to the user.

Re: Librarian's Letter to Google Security

#309

Well, this is a tricky situation. At what point did Google agree to become the world's free email provider? We have to decide where their social obligation outranks their share holder obligation. And by "we," I include everyone from users, technology providers, and especially governments that require email addresses to get basic services, everyone. A modest proposal. Can one YubiKey serve several email accounts? Ask…

> Can one YubiKey serve several email accounts?

Yes. I use the same YubiKey with at least three Google accounts.

Re: Librarian's Letter to Google Security

#310

I fully sympathize with the librarian's concerns, but there's this: "Many government welfare forms, housing applications, and jobs applications these days require the use of the internet exclusively with no option to fill things out in person." Why is this? Really, this does not seem like a problem Google caused, but rather a problem caused by the government when they made it mandatory to have internet access to get…

This is flat out incorrect. All _government _forms have paper-equivalents for accessibility reasons, and OMB numbers that coincide. The Paperwork reduction act is a thing, but it also stipulates that within reason, paper forms must be available.

Federal, yes, but also the state and municipal governments that manage services relevant to the internet-in-the-library population?
Post reply on HN