Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

331–340 of 484 posts

Re: Librarian's Letter to Google Security

#331
!!! PSA : I emailed the author of this this morning while on the toilet and got an email back thanking me for my kind words, but ALSO made it very clear that this was meant to be PRIVATE communications between her and Google, and that it was never meant to be posted here or elsewhere, ESPECIALLY with her private contact information exposed and she has very politely asked that people stop sharing this with her PRIVATE INFORMATION for all to see. She said all the incoming communications are essentially DDOSsing her servers at work and make it hard to do her job.

Idk if mods or anyone wants to do anything about that, but yeah we have a case of someone being doxxed here, and even without malicious intent - its causing her issues in her day to day life.

Re: Librarian's Letter to Google Security

#332

Earlier quoted context omitted.

I'd like to see the Post Office (in the US) get involved. Post offices are geographically ubiquitous, already deal with identity verification, and already have to maintain the trustworthiness of their workforce. I'd like to see a system where (a) an account [whether GMail, Facebook, Schwab or Bob's Online Pet Food Mart] can be tied to a real-world identity and (b) when you lose access, you can go to the local post of…

I understand, and agree with you, but at the same time, a HUGE number of people don't have that identification. Many homeless people that could qualify for services struggle to prove who they are, and that they are able to receive it (especially vets) because they have lost their ID, have no idea where their birth certificate is (or marriage license), and have no home to show multiple bills to that address in their n…

This is also a failure of government that needs to be fixed; saying this problem exists doesn’t absolve us from fixing it.

Its time to bring this stupid, dystopian nightmare we’ve created to an end.

Re: Librarian's Letter to Google Security

#333

Earlier quoted context omitted.

only a paid for service can really expect paid support staff. Why? You make it sound like Google is a pauper, doling out free e-mail accounts and not making any money off of it. Just because it's not billing your credit card doesn't mean you're not paying for GMail. You just pay for it indirectly through advertising. If only a paid service can expect paid support, then how does Google make hundreds of billions of dol…

Even at Google's scale, they cannot afford to provide high-touch tech support for 1.5 billion users. The fact Gmail is possible is partially due to their ability to scale low-touch tech support for free by supplementing the cost from other sources and, sometimes, just providing best-effort support. (Remember, the cost isn't "How do we field calls from a fraction of our 1.5 billion users," it's "How do we tell whether…

>Even at Google's scale, they cannot afford to provide high-touch tech support

Yet somehow companies of similar scale like Amazon, Apple and Netflix manage to provide robust customer service.

Re: Librarian's Letter to Google Security

#334

Librarian has updated the document to say this issue was resolved and overblown: STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longe…

Flag the submission.

Re: Librarian's Letter to Google Security

#335

Earlier quoted context omitted.

Customer support is a cost sink Too bad. If you have a business (and Google is a business) that goes business with the public (which Google does), you should offer some form of customer services. It's what we human beings call "the right thing to do." Yes, customer service costs money. It costs money for the dry cleaners, the restaurants, the banks, the car washes, the design firms, and every single other company on…

> Imagine if Google's vendors stopped offering Google customer service. Janitor didn't show up today? Well, clean your own office toilet today, technie. At their scale, this exact scenario happens all the time. The back-stop is that Google chooses to stop doing business with unreliable service providers. This is also an option for Google users. Gmail competitors are just a click away.

If Google is not satisfied with the level of cleaning in their buildings and fires the custodial contractor, they don't lose access to their buildings because the janitors walked away with the keys. When people start using Gmail, they don't expect to someday lose access to their online banking and utility bills and all the rest, and by the time it does happen to them and they decide to look for a competitor, a lot more damage has been done due to missed bills, etc. It's not as lighthearted as, "Oh, this burger tastes bad, guess I'll go to a competitor's burger shack." If regulation improves the terms the users agree to so they have some way to get reasonable help from customer service and Google finds that too expensive, they can either charge for Gmail or shut it down.

Re: Librarian's Letter to Google Security

#336
post #238

Earlier quoted context omitted.

> More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support. I would recommend a $5/month email service. It would be nice if free Gmail gave even more free stuff, but only a paid for service can really expect paid support staff. Having said that, this seems like a terrible idea from a security perspective. There may well be no way to desi…

*While the social engineering concern is a valid one, I suspect that Google's original reasons for not providing support were not opsec related. Google's 2FA system combined with their lack of support terrifies me as a security-literate user. Here's one example: I was traveling and signed into Google from a new location. Google prompted me to verify myself via two-factor auth, and the only method they allowed me to v…

Google does nothing, nothing!, without it being an attempt to track you. And the golden of tracking, is your real id and real location.

Even if the initial push for 2fa was security, by dev#1, you can be positive dev#2, 3, 4, xxx, 100 came running, and thought "tracking".

Google owes everything it is, to being the sleaziest, sneakiest, slymiest company they can be.

If the internet is an information highway, google is a van, stopping, and asking your kids if they want candy.

Were google a business in your physical neighborhood, tracking people as they do, they'd end up with a molotov cocktail through their window. No one would abide such behaviour, but the average Joe has no idea, and cannot understand, and thus, does no object.

Google is doing to our society, what the new settlers to North America did to Native Americans. Offer them beads, and plets, in exchange for riches, using our own ignorance against us.

Google is a primay example of the "slippery slope". They were given an inch, and they took us out back, and beat us with a 2×4.

If you trust your business to google, you're nuts.

And to the comment I replied to, yes, it is all for tracking.

Edit: yes OK I admit I don't like Google, just to ensure my bias is clear.

Re: Librarian's Letter to Google Security

#337

Earlier quoted context omitted.

This comment does raise a serious concern. The primary reason why cell phone numbers are bad for 2FA is sim swapping, which can only occur because there is a customer support rep who can fall for it. Email is largely immune to that right now because customer support generally cannot let you into an account you locked yourself out of. This isn't to say that this is an unsolvable problem, it's not, but it's definitely…

I'd like to see the Post Office (in the US) get involved. Post offices are geographically ubiquitous, already deal with identity verification, and already have to maintain the trustworthiness of their workforce. I'd like to see a system where (a) an account [whether GMail, Facebook, Schwab or Bob's Online Pet Food Mart] can be tied to a real-world identity and (b) when you lose access, you can go to the local post of…

[deleted]

Re: Librarian's Letter to Google Security

#339

Librarian has updated the document to say this issue was resolved and overblown: STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longe…

[deleted]

Re: Librarian's Letter to Google Security

#340
post #331

!!! PSA : I emailed the author of this this morning while on the toilet and got an email back thanking me for my kind words, but ALSO made it very clear that this was meant to be PRIVATE communications between her and Google, and that it was never meant to be posted here or elsewhere, ESPECIALLY with her private contact information exposed and she has very politely asked that people stop sharing this with her PRIVATE…

[deleted]
Post reply on HN