This is well meaning and shows an unfortunate side of 2f-auth, but she seems to think that google is in the business of helping people. They are in the business of selling ads. True their search engine has greatly helped a lot of people, as has gmail. But they are in the business of selling ads, and they are not selling enough ads to people who both a) cannot continuously afford a phone number b) are unable to afford…
Regulation can change that.
Librarian's Letter to Google Security
311–320 of 484 posts
Re: Librarian's Letter to Google Security
#312Earlier quoted context omitted.
You're right, that online-only access is definately a government problem. But this: > Even when we clicked “I don’t have my phone” it asked her to open the Google app from the phone that she does not have. That's a google problem. Google fixing their problem would lessen the impact of the government problem. (And, more generally, make gmail a better service for lots of people.)
but what would Google do, how is it possible to fix? What's the point of having 2FA using the phone if you can bypass it by clicking "i don't have my phone"?
Re: Librarian's Letter to Google Security
#313Earlier quoted context omitted.
Library op-sec is pretty weak IME. Mine accepted seeing an email of a utility bill on my phone. Which is probably fine for just checking out books. I still love libraries and the services they provide. But wouldn't want them to be an arbiter of identity any more than a faceless, human hostile corporation.
It's supposed to be easy to get a library card! The threat of an out-of-towner getting a local library card is nothing like a stranger getting access to your inbox.
Re: Librarian's Letter to Google Security
#314All the anger toward Google misses the larger point – this isn’t only Google's problem. If I get locked out of my Apple account, or my Amazon account, or my account, how do I prove that I am me? A password? I’m glad your memory is much better than mine, because I'm terrible at remembering 1000 passwords that aren’t trivially cracked. Use a password manager? Oh yeah! I do, thanks. On my computer and phone along with..…
The specific anger towards Google comes from the fact that they're an overwhelmingly popular email provider, and email is what a lot of paperless processes (including account resets) assume the existence of. If you get locked out of Amazon, or Facebook, or Instagram, or TikTok, or Reddit, or Twitter, or Netflix, you won't lose the ability to receive welfare benefits, or tax information, or rent / utility bills, or st…
Replace 'government should provide a digital identity service' with 'government should provide an email service', and we're back at the same place. You still needs a way to prove that you are you - with legal protection and recourse.
This letter points out the increasingly obvious - that our online identities have become too important to be left to the customer support whims of one or two corporations. The idea that an innocent algorithmic mistake in a microservice running somewhere deep in Google's cloud could lock me out of my life is not the future we want.
Re: Librarian's Letter to Google Security
#315Google consider this flagged as a suspicious fake account and he was never allowed back in to his email.
Re: Librarian's Letter to Google Security
#316Earlier quoted context omitted.
It's not just Google, many corporations are starting to make "assumptions" about their customers, and these assumptions totally exclude entire groups of people. A great example I use is there are a ton of restaurants and fast food places around me. I used to walk to get lunch every day but eventually had to stop, these places realized most customers went through the drive through so they closed the lobby. Now even th…
> A great example I use is there are a ton of restaurants and fast food places around me. I used to walk to get lunch every day but eventually had to stop, these places realized most customers went through the drive through so they closed the lobby. Now even though this place is a 5 minute walk from me, it's no longer accessable if I'm not in a car. I think this may have to do COVID and then staffing shortages creati…
Re: Librarian's Letter to Google Security
#317Earlier quoted context omitted.
It's supposed to be easy to get a library card! The threat of an out-of-towner getting a local library card is nothing like a stranger getting access to your inbox.
So we have come full circle: starting from a call for help from a librarian seeing lots of people unable to access their accounts because of 2FA, we have proposed various methods of avoiding that, and then concluded that it's better if 100 people are locked out of their own accounts rather than letting one unauthorized person access an account that isn't theirs? I guess that's Google's position as well, because if th…
Re: Librarian's Letter to Google Security
#318Earlier quoted context omitted.
Aren't half of those things you listed (Walmart, Target, Cellular Phone companies, etc.) also exactly how people get unauthorized access? You convince the employee to port "your" number and they do so and then you reset that accounts password? https://www.wptv.com/money/consumer/phone-porting-leads-to-s...
Make it a choice. It sure sounds like the patrons of this library would opt in.
Re: Librarian's Letter to Google Security
#319More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support.
Americans with disabilities act? Haha, google doesn't provide good customer service for able bodied, so they provide the equal service for disabled. Big tech needs a reckoning from consumer protection. Oh wait, those laws and the government agency were gutted. Nevermind. Being a relatively new parent, the lack of consumer protection regulation in things like kids apps, youtube ads, and similar is APPALLING. I recall…
What we are seeing is a symptom of the system of corporation government that is unbalanced by design wrought in hell.
Re: Librarian's Letter to Google Security
#320Earlier quoted context omitted.
At what point is it reasonable to start assuming basic security/computer literacy on the part of the public (to the point where, if you screw up, it is your fault for screwing up and not the computer/companies fault for not telling you something)? This is an open question. We are not there yet, but at the same time I don't think it's tenable in the long term to be in the state of assuming the user can't be trusted to…
So, my grandmother knows drastically less about computers than she used to. She actually previously used email with regularity, and has since forgotten about even the existence of the email account she had for fifteen years. Unless we have a cure for memory loss in seniors, new less computer literate people will be occurring every day. So the answer is, unfortunately, never. There will always be people who are not co…
The term of computer illiteracy is useful in more than one way, and that is literacy. We don't structure our societies (including basic government services) around people who cannot read, instead, we we structure them around the understanding that the average citizen can read, and treat regular illiteracy as a problem to be solved, and in the first world where computer literacy is even a problem that can exist, it mostly has.