Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

391–400 of 484 posts

Re: Librarian's Letter to Google Security

#391
post #312
post #187

Earlier quoted context omitted.

but what would Google do, how is it possible to fix? What's the point of having 2FA using the phone if you can bypass it by clicking "i don't have my phone"?

They already have a way, but it requires upfront planning - backup codes. You can get and print single-use 2FA bypass codes.

Yeah. Because I'm a nerd and basically understand how MFA works and how I should prepare for the day my MFA device goes kaput, I saved my backup codes.

For most people, that's too hard. The elderly, marginally educated people being served by the library or in other contexts just don't understand how things work to the degree that they might appreciate backup codes or their importance. They just don't get it. Backup codes are like this noise in the way of account signup.

Ever tried to get friends and family to start using PGP? A password manager?

The technical solutions that are practical already exist, as you've pointed out; and the technical solutions that seem like they're lacking (enrolling a new device without MFA-ing in) are lacking for a reason--they're security holes. You can't say "this email account is super important and access to it unlocks important things in someone's life" and also "account recovery must be as easy as claiming you lost your phone, and you don't have to know any pre-shared or pre-generated secret".

I also don't know what the solution is. Trusted intermediaries (librarians? social workers? police? social security office people?) introduce all kinds of other attack vectors. Elsewhere folks are pointing out that the mistake was probably to rely on email for all of this super important messaging and your account recovery workflow for every system other than email, but that's a society-wide problem that you probably couldn't have controlled in the first place and definitely can't now.

The best you can probably do is aggressively prompt people to prepare for account recovery prospectively, maybe by identifying a trusted intermediary and/or verifying that they have backup codes.

Re: Librarian's Letter to Google Security

#392

Earlier quoted context omitted.

I’m not GP, but I expect that regulation could help by requiring customer service. Similar to banking. And there could be an agency similar to CFPB where citizens could appeal who would then make formal investigations. So regulation would force the workflow described in the article to not have a grim outcome for elderly users of gmail.

Since opening all these offices costs money, this means that the accounts can't be free anymore. I suppose they could be subsidized by the state for low income people.

Could it not be similar to FOSS companies where the software (service) is free but customers pay for support?

Re: Librarian's Letter to Google Security

#393
post #178

I fully sympathize with the librarian's concerns, but there's this: "Many government welfare forms, housing applications, and jobs applications these days require the use of the internet exclusively with no option to fill things out in person." Why is this? Really, this does not seem like a problem Google caused, but rather a problem caused by the government when they made it mandatory to have internet access to get…

What does this have to do with not having an account recovery flow? Many government offices have temporarily(?) gone online-only for covid.

[deleted]

Re: Librarian's Letter to Google Security

#394

Earlier quoted context omitted.

>I made a mistake, when setting the password That's a feature, not a bug.

Yes, but not being able to recover the account, is a bug. The issue was that I used a randomly-generated password from 1Password, and accidentally re-generated, before copying, so the original was lost. That's a fairly common mistake. I'm usually careful to avoid that (now).

At least in bitwarden app they provide history of passwords for every url.

Re: Librarian's Letter to Google Security

#395

Earlier quoted context omitted.

Even at Google's scale, they cannot afford to provide high-touch tech support for 1.5 billion users. The fact Gmail is possible is partially due to their ability to scale low-touch tech support for free by supplementing the cost from other sources and, sometimes, just providing best-effort support. (Remember, the cost isn't "How do we field calls from a fraction of our 1.5 billion users," it's "How do we tell whether…

>Even at Google's scale, they cannot afford to provide high-touch tech support Yet somehow companies of similar scale like Amazon, Apple and Netflix manage to provide robust customer service.

650-253-0000

Re: Librarian's Letter to Google Security

#396
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

> trusted civic authorities They'll need to be resistant to threats and bribes, so it will be difficult to have these on-site at the library. I think we've overlooked an option. Note that the article's objection to FIDO keys was financial, not UX. This sort of confirms the hunch I got when first playing with them: "hey, the key metaphor is so strong and intuitive that these might be even better than passwords for peo…

> > trusted civic authorities

> They'll need to be resistant to threats and bribes, so it will be difficult to have these on-site at the library.

That's why I mentioned things like APP: some people do have a threat model where that's realistic but it's a much smaller number than the people who are inconvenienced by being locked out so it seems like it'd be a net-win for most people to be able to get unlocked easily. There are also ways to mitigate some of that risk like having notifications for all actions with an easy way to report unapproved requests, geographic restrictions, enforced MFA for the civil servant (“tap your FIDO token to approve this request”), rate-limiting, etc. which are all bread-and-butter tasks for one of the major tech companies.

The other thing I think is relevant here is the degree to which things fall back on civic authorities anyway — e.g. Facebook's process where they require scans of your government ID or the various ways you can report a deceased relative. It seems to me like it'd be better to embrace that and work better together rather than pretending there isn't already a fairly large trust relationship.

Re: Librarian's Letter to Google Security

#397
None of this is related to technology and the best Google could do is expend resources on education.

For tech illiterate, maybe the least bad option is that their security is that they won't lose their wallet. I think this is one of those situations where security has to take a back seat to usability.

1. Create a passphrase with this method: https://xkcd.com/936/ 2. Write down your passphrase. 3. Write down recovery codes, and keep them in your wallet.

Also: Tips to make sure you never lose your wallet.

Re: Librarian's Letter to Google Security

#398

Earlier quoted context omitted.

> Imagine if Google's vendors stopped offering Google customer service. Janitor didn't show up today? Well, clean your own office toilet today, technie. At their scale, this exact scenario happens all the time. The back-stop is that Google chooses to stop doing business with unreliable service providers. This is also an option for Google users. Gmail competitors are just a click away.

If Google is not satisfied with the level of cleaning in their buildings and fires the custodial contractor, they don't lose access to their buildings because the janitors walked away with the keys. When people start using Gmail, they don't expect to someday lose access to their online banking and utility bills and all the rest, and by the time it does happen to them and they decide to look for a competitor, a lot mo…

> they don't lose access to their buildings because the janitors walked away with the keys

... You are actually ascribing a larger amount of have-their-shit-togetherness to Google than may be strictly true. Without telling too many stories that aren't mine, I'll say "Usually. They usually don't." ;)

But to extend your analogy a bit... Google doesn't lose physical access to their headquarters because security is not a third-party vendor. They keep the mission-critical stuff in-house. That would translate, analogously, to individual homeless or elderly people running their own mail servers (infeasible)... Or, perhaps, libraries running mail servers and providing accounts for patrons tied to their library cards (might be actually, maybe, feasible?).

> When people start using Gmail, they don't expect to someday lose access to their online banking and utility bills and all the rest, and by the time it does happen to them and they decide to look for a competitor, a lot more damage has been done due to missed bills, etc.

You're absolutely right, and the back stop is almost certainly to make people aware of this very significant risk factor in using Gmail instead of alternatives.

> If regulation improves the terms the users agree to so they have some way to get reasonable help from customer service and Google finds that too expensive, they can either charge for Gmail or shut it down.

If such regulation is impossible at the scale of serving 1.5 billion customers, which I assert it is until somebody can provide a practical road map for getting to that scenario, then your recommended remedy for "Gmail doesn't work reliably for a subset of its users" is "Deny its benefits to all of its users." That seems strictly worse than a solution where we encourage people to be conscious of their risk tolerance before signing up for service with a company that can't guarantee they won't get locked out of their account with no easy method to unlock it.

Re: Librarian's Letter to Google Security

#399

Great letter. Wanna bet it was completely ignored? Glad to see it here. Maybe it won't be ignored. Librarians rock. There's even a show about them[0], Starring Number One. I can't access the gMail account I set up, because I made a mistake, when setting the password, and did not save the one I used. It will not allow me to access the account I set up. After a while, I just gave up. I am satisfied that someone can't u…

> Wanna bet it was completely ignored? I just tweeted it to @Google. Maybe if enough people ping Google about it?

The letter was subsequently updated to say that the situation has improved and in fact the author is currently looking to get less attention (apparently it was posted to HN without their knowledge and now their work email is getting a ton of non-helpful noise from hackernews commenters). So it would probably be better to not tweet about this.

Re: Librarian's Letter to Google Security

#400
@dang could you explain why this post is getting down ranked so hard? It's been 6 hours and I could only find this post by using the search function. We have a ~800 point post from 2 days ago and it's still on the second page

Edit: it's either back on the frontpage now or I missed it somehow

Edit 2: Looks like the doc was updated and it was posted without consent. I think we should delete the post now.

Post reply on HN