Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

341–350 of 484 posts

Re: Librarian's Letter to Google Security

#341

Earlier quoted context omitted.

only a paid for service can really expect paid support staff. Why? You make it sound like Google is a pauper, doling out free e-mail accounts and not making any money off of it. Just because it's not billing your credit card doesn't mean you're not paying for GMail. You just pay for it indirectly through advertising. If only a paid service can expect paid support, then how does Google make hundreds of billions of dol…

Even at Google's scale, they cannot afford to provide high-touch tech support for 1.5 billion users. The fact Gmail is possible is partially due to their ability to scale low-touch tech support for free by supplementing the cost from other sources and, sometimes, just providing best-effort support. (Remember, the cost isn't "How do we field calls from a fraction of our 1.5 billion users," it's "How do we tell whether…

[deleted]

Re: Librarian's Letter to Google Security

#342

Yeah, Google just doesn't give a shit. I was a gmail user since gmail was in private beta 18 years ago. I never had a phone number associated with it. And yet two or three years ago when I tried to log in Google decided to just... not let me do that, because fuck you, and started extorting me to give it a phone number. If I don't give it a valid phone number it won't let me access my email. But I can't really do that…

[deleted]

Re: Librarian's Letter to Google Security

#343
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

> trusted civic authorities They'll need to be resistant to threats and bribes, so it will be difficult to have these on-site at the library. I think we've overlooked an option. Note that the article's objection to FIDO keys was financial, not UX. This sort of confirms the hunch I got when first playing with them: "hey, the key metaphor is so strong and intuitive that these might be even better than passwords for peo…

How about: the library gets a few Yubikeys and offers to let people register their accounts with them as backup? So, if they get into trouble they can ask the library to unlock their account for them?

This essentially grants the librarian what they think they should be able to do.

But the next step would be to figure out how to reduce the risk that this system can be abused.

Re: Librarian's Letter to Google Security

#344
post #174

Earlier quoted context omitted.

Can you describe how regulation solves this problem, how exactly are you proposing for this regulation to work?

I’m not GP, but I expect that regulation could help by requiring customer service. Similar to banking. And there could be an agency similar to CFPB where citizens could appeal who would then make formal investigations. So regulation would force the workflow described in the article to not have a grim outcome for elderly users of gmail.

Since opening all these offices costs money, this means that the accounts can't be free anymore.

I suppose they could be subsidized by the state for low income people.

Re: Librarian's Letter to Google Security

#345

Earlier quoted context omitted.

I don't. Customer support is a cost sink that usually isnt empowered to do anything. Its more PR tactic to make people feel they are "heard" without resorting to twitter. In the email/business apps space, google is clearly not a monopoly. Presence/quality of customer support seems a very reasonable grounds to have normal competition over.

Customer support is a cost sink Too bad. If you have a business (and Google is a business) that goes business with the public (which Google does), you should offer some form of customer services. It's what we human beings call "the right thing to do." Yes, customer service costs money. It costs money for the dry cleaners, the restaurants, the banks, the car washes, the design firms, and every single other company on…

This.

The need for unbounded growth is not a valid justification for not acknowledging humans.

Now, I'm not sure what would be the solution. Regulation requiring some level of support? "Right to talk to a capable human" or somesuch? Sounds a bit arbitrary. In the meanwhile, I'm trying to un-Google myself and use more respectul alternatives, as well as raising awareness in my immediate circle.

If you're not able to do business at Google Scale without providing human support (and similarly, not treating support personnel like absolute garbage, as we see with call center operators for ISPs and whatnot), then maybe you just can't operate at that scale?

This goes even further: things like free-to-play games that use psychological manipulation to culture addictive personalities and whatnot seem ethically wrong to me. If your business model depends on absolutely fleecing vulnerable people, then maybe it shouldn't be viable?

I guess the base premise is I don't think companies should "have the right to make all the money in the world".

To be clear, I'm not advocating for the solution above, but I sure believe the problem described _is_ in fact legitimate within my morals.

Re: Librarian's Letter to Google Security

#346

Librarian has updated the document to say this issue was resolved and overblown: STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longe…

I wish mods would pin this comment.

Re: Librarian's Letter to Google Security

#348
post #187

Earlier quoted context omitted.

but what would Google do, how is it possible to fix? What's the point of having 2FA using the phone if you can bypass it by clicking "i don't have my phone"?

When i lost my phone and was locked out of 2fa, most services required a picture of me, with my ID, my face and a letter showing the date all in the same picture. This seemed pretty effective to me.

Google doesn’t have a picture of me linked to my gmail account, so this would require as much planning as printing 2fa backup codes right?

Re: Librarian's Letter to Google Security

#349

The author is 100% not wrong, but the problem is that, unfortunately, it is entirely possible that Google cannot have an authentication system that is correct for use by the elderly in a shared-machine environment while being correct for everyone else at the same time. There are options to fix this, but they're social, not technical. To get there, let's start with the technical side of why the author's proposed fix w…

Or perhaps someone can setup an email system primarily for the benefit of public library users. Run it as a non-profit / low-profit and provide basic support, do not require 2-factor authorization. Basically the way email was for many in the late 1990s, when they got email through their schools or universities, or perhaps through AOL or Compuserve.

Re: Librarian's Letter to Google Security

#350
post #174

Earlier quoted context omitted.

Can you describe how regulation solves this problem, how exactly are you proposing for this regulation to work?

I’m not GP, but I expect that regulation could help by requiring customer service. Similar to banking. And there could be an agency similar to CFPB where citizens could appeal who would then make formal investigations. So regulation would force the workflow described in the article to not have a grim outcome for elderly users of gmail.

I write software at a fintech, and the CFPB regulations are super important for protecting the customer. They also give important guidance on how the customer needs to be taken care of, which is important for a company that wants to do the right thing but doesn't have expertise in customer service.
Post reply on HN