Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

371–380 of 484 posts

Re: Librarian's Letter to Google Security

#372
post #52

The best solution I can think of that doesn't compromise security is hardware keys. GMail has very good FIDO support. The keys are easier to use than TOTP and vastly more secure than SMS. They do not depend on any phone or phone service, and there is no transferring necessary at any time. The librarian would just need to get the person logged in successfully one time, get the key attached to the person's account, and…

The unhoused are much more likely to be robbed of their possessions than others. They don't have anywhere secure to store things.

Re: Librarian's Letter to Google Security

#374

@dang why is this still up and on the front page (you can at least suppress the story to the second page..)? It's clear the document was shared without her permission and she's being harassed by HN and press: > STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS > This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It we…

> @dang why is this still up and on the front page (you can at least suppress the story to the second page..)? It's clear the document was shared without her permission and she's being harassed by HN and press:

That was added well after the document was posted to Hacker News, so I don't think this is a fair question. Also, I'm sure dang has a life outside of Hacker News, so I don't think it's reasonable to expect everything to be acted upon immediately.

Re: Librarian's Letter to Google Security

#375
post #43

Perhaps the solution is for libraries or local authorities to setup their own email providers. An email address “for life” with your library card, with the necessary support and in-person reset verification that their patrons need. I’m not suggesting this would be an easy or inexpensive undertaking, but maybe that’s just the next step in service evolution for a public information service like a library group.

Indeed, but this will then going to face the issue of Gmail (et al.) refusing to accept e-mail sent from small providers.

This isn't necessarily a "from a small provider" but rather "administered by the library."

It could be any email service that allows the librarian-administer to reset the password for an account. If I mess up my exchange email, the helpdesk can verify my identity and reset my password.

I suspect that most going down this approach would find it easier to use a large hosting service that they provision and administer (along with allowing password resets) than to try to have an underfunded library IT staff stand up an arbitrarily large email service and manage all parts of it.

Re: Librarian's Letter to Google Security

#376

Earlier quoted context omitted.

This blind spot got so big because the vast majority of wealthy Bay Area tech workers have never been poor or homeless. It is difficult for those that have never lived in poverty to understand the struggles that it brings. Just look at his thread, see how many people fail to comprehend that if someone is using the library computers they aren't going to be able to afford a $25 key-chain verifier.

Yes. The overwhelming majority of people that I worked with in SV had never been poor, never been homeless, never worked a fast food or customer facing retail job, and never lacked support from family or some kind of extended network. They were accustomed to lightning fast internet on Macbooks and constant technological churn. Unfortunately for these exceptional people, poverty is logic resistant and nearly impossibl…

There's a strong right-wing libertarian element among tech workers, particularly the near-retirement-age ones and the ones fresh out of school. Their logic is that poor people are poor because they didn't stay in school or were lazy or stupid, and thus aren't deserving of services and support.

The tech scene's obsession with meritocracy is an extension of this.

Re: Librarian's Letter to Google Security

#377

Yeah, Google just doesn't give a shit. I was a gmail user since gmail was in private beta 18 years ago. I never had a phone number associated with it. And yet two or three years ago when I tried to log in Google decided to just... not let me do that, because fuck you, and started extorting me to give it a phone number. If I don't give it a valid phone number it won't let me access my email. But I can't really do that…

This is a great point. My wife and I were attracted to the Google Pixel lineup because they advertised unlimited original quality photo storage through Google Photos. Well they reduced that to just unlimited "high quality" a year or so ago, and I broke my 3A a few months ago. Silly me forgets that newer Google Pixels don't have unlimited photo storage at all, I buy a 5A, and all photos/videos get uploaded to Google P…

The photos would be in Google Photos even if you no longer had access to your old phone and you do not have to reupload them.

Re: Librarian's Letter to Google Security

#378

Great letter. Wanna bet it was completely ignored? Glad to see it here. Maybe it won't be ignored. Librarians rock. There's even a show about them[0], Starring Number One. I can't access the gMail account I set up, because I made a mistake, when setting the password, and did not save the one I used. It will not allow me to access the account I set up. After a while, I just gave up. I am satisfied that someone can't u…

Currently the doc says: """ STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longer are having this issue as often as before due to var…

> we no longer are having this issue as often as before due to various improvements.

Doesn't sound like it was completely resolved. In fact, it sounds like Google may have treated it as a "squeaky wheel," and only that library is getting better help.

In any case, I think that HN (@dang) should honor her request; regardless of its resolution.

I would suggest that the letter is great, and should be made more available, sans the identifying information.

I'd suggest someone try and get her permission to host an anonymized version of the page, on a different server that could handle the lurve.

Re: Librarian's Letter to Google Security

#379

It looks like the author is requesting this link be removed from HN: > STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS > This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. > ...

Yes, this one is a bit of a grey area and I'd love to hear dang's opinion on it, but personally based off the user's EDIT I have used my "flag" on this post.

Re: Librarian's Letter to Google Security

#380

Great letter. Wanna bet it was completely ignored? Glad to see it here. Maybe it won't be ignored. Librarians rock. There's even a show about them[0], Starring Number One. I can't access the gMail account I set up, because I made a mistake, when setting the password, and did not save the one I used. It will not allow me to access the account I set up. After a while, I just gave up. I am satisfied that someone can't u…

Currently the doc says: """ STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longer are having this issue as often as before due to var…

No post body was provided.
Post reply on HN