Earlier quoted context omitted.
So we have come full circle: starting from a call for help from a librarian seeing lots of people unable to access their accounts because of 2FA, we have proposed various methods of avoiding that, and then concluded that it's better if 100 people are locked out of their own accounts rather than letting one unauthorized person access an account that isn't theirs? I guess that's Google's position as well, because if th…
No, I'm saying those situations aren't comparable. We should not conclude librarians will be poor stewards of MFA reset powers just because they are lax in giving out library cards.
Librarian's Letter to Google Security
321–330 of 484 posts
Re: Librarian's Letter to Google Security
#322Great letter. Wanna bet it was completely ignored? Glad to see it here. Maybe it won't be ignored. Librarians rock. There's even a show about them[0], Starring Number One. I can't access the gMail account I set up, because I made a mistake, when setting the password, and did not save the one I used. It will not allow me to access the account I set up. After a while, I just gave up. I am satisfied that someone can't u…
Re: Librarian's Letter to Google Security
#323Earlier quoted context omitted.
This comment does raise a serious concern. The primary reason why cell phone numbers are bad for 2FA is sim swapping, which can only occur because there is a customer support rep who can fall for it. Email is largely immune to that right now because customer support generally cannot let you into an account you locked yourself out of. This isn't to say that this is an unsolvable problem, it's not, but it's definitely…
I'd like to see the Post Office (in the US) get involved. Post offices are geographically ubiquitous, already deal with identity verification, and already have to maintain the trustworthiness of their workforce. I'd like to see a system where (a) an account [whether GMail, Facebook, Schwab or Bob's Online Pet Food Mart] can be tied to a real-world identity and (b) when you lose access, you can go to the local post of…
Re: Librarian's Letter to Google Security
#324More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support.
> More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support. I would recommend a $5/month email service. It would be nice if free Gmail gave even more free stuff, but only a paid for service can really expect paid support staff. Having said that, this seems like a terrible idea from a security perspective. There may well be no way to desi…
Re: Librarian's Letter to Google Security
#325More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support.
> More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support. I would recommend a $5/month email service. It would be nice if free Gmail gave even more free stuff, but only a paid for service can really expect paid support staff. Having said that, this seems like a terrible idea from a security perspective. There may well be no way to desi…
Google makes more than enough money selling everyone's personal data via advertising to afford to provide customer service.
They simply choose not to.
Re: Librarian's Letter to Google Security
#326Earlier quoted context omitted.
only a paid for service can really expect paid support staff. Why? You make it sound like Google is a pauper, doling out free e-mail accounts and not making any money off of it. Just because it's not billing your credit card doesn't mean you're not paying for GMail. You just pay for it indirectly through advertising. If only a paid service can expect paid support, then how does Google make hundreds of billions of dol…
Even at Google's scale, they cannot afford to provide high-touch tech support for 1.5 billion users. The fact Gmail is possible is partially due to their ability to scale low-touch tech support for free by supplementing the cost from other sources and, sometimes, just providing best-effort support. (Remember, the cost isn't "How do we field calls from a fraction of our 1.5 billion users," it's "How do we tell whether…
Re: Librarian's Letter to Google Security
#327How do they get away with not having a support number. Even Amazon has humans you can eventually talk to as you go through the customer service interface
Re: Librarian's Letter to Google Security
#328Re: Librarian's Letter to Google Security
#329Earlier quoted context omitted.
It's important to understand that Google is, as an organizational body, psychopathic in nature. (Many corporations are, but Google especially, through well-indoctrinated concepts like being solely data-driven and putting scale first, combined with a belief that Google hires the best people and hence is already doing the best possible thing.) Google does not care. You cannot make Google care. Employees who care get fi…
This is an extremely bleak perspective. Individuals care, but most are powerless to make a difference if they don't work in the area of concern. It's often a knowledge sharing game of making sure the right people hear about it which can be hard. They are intentionally shielded from direct feedback to keep them focused, but that is a double edged sword. I honestly believe the reason viral stories get resolved is becau…
Almost every problem out there at some level is an info prop problem, and in cases where it isn't the signal getting lost, it's the remediatory activity being judged as too expensive, and thereby getting the process routed to /dev/null
Re: Librarian's Letter to Google Security
#330STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS
This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longer are having this issue as often as before due to various improvements.
Please delete this from HN. You are essentially DDOS’ing my work email and the library branch phone number making it very difficult for us to perform our duties as civil servants today.
I do not know how this made it onto HN. Someone must have leaked it. If they need to work that out internally then I’m leaving this here for their reference. But I do not want news reporters or random HN readers contacting me or the Free Library over this.