About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…
I think something like this could work iff the accounts were required to be set up by said civic authorities with confirmable paperwork. Otherwise, librarians are stuck awkwardly trying to decide if 'John Doe' really owns the email account 'ILoveButts64@gmail.com'. I also doubt this will ever happen since it would require more $$$ for things that are not profit generating and supports a population that is useless fro…
Librarian's Letter to Google Security
401–410 of 484 posts
Re: Librarian's Letter to Google Security
#402Earlier quoted context omitted.
Even at Google's scale, they cannot afford to provide high-touch tech support for 1.5 billion users. The fact Gmail is possible is partially due to their ability to scale low-touch tech support for free by supplementing the cost from other sources and, sometimes, just providing best-effort support. (Remember, the cost isn't "How do we field calls from a fraction of our 1.5 billion users," it's "How do we tell whether…
>Even at Google's scale, they cannot afford to provide high-touch tech support Yet somehow companies of similar scale like Amazon, Apple and Netflix manage to provide robust customer service.
Re: Librarian's Letter to Google Security
#403Earlier quoted context omitted.
It's important to understand that Google is, as an organizational body, psychopathic in nature. (Many corporations are, but Google especially, through well-indoctrinated concepts like being solely data-driven and putting scale first, combined with a belief that Google hires the best people and hence is already doing the best possible thing.) Google does not care. You cannot make Google care. Employees who care get fi…
This is an extremely bleak perspective. Individuals care, but most are powerless to make a difference if they don't work in the area of concern. It's often a knowledge sharing game of making sure the right people hear about it which can be hard. They are intentionally shielded from direct feedback to keep them focused, but that is a double edged sword. I honestly believe the reason viral stories get resolved is becau…
Google has designed itself to be psychopathic from a human frame of reference because it is more streamlined (profitable) to be psychopathic. It is a product of its environment.
Re: Librarian's Letter to Google Security
#404@dang could you explain why this post is getting down ranked so hard? It's been 6 hours and I could only find this post by using the search function. We have a ~800 point post from 2 days ago and it's still on the second page Edit: it's either back on the frontpage now or I missed it somehow Edit 2: Looks like the doc was updated and it was posted without consent. I think we should delete the post now.
Re: Librarian's Letter to Google Security
#405@dang could you explain why this post is getting down ranked so hard? It's been 6 hours and I could only find this post by using the search function. We have a ~800 point post from 2 days ago and it's still on the second page Edit: it's either back on the frontpage now or I missed it somehow Edit 2: Looks like the doc was updated and it was posted without consent. I think we should delete the post now.
Have you read it? The author would like this post not to be shared. The situation has improved and they are getting more disruption than help from public attention at this point.
Re: Librarian's Letter to Google Security
#406Earlier quoted context omitted.
I’m not GP, but I expect that regulation could help by requiring customer service. Similar to banking. And there could be an agency similar to CFPB where citizens could appeal who would then make formal investigations. So regulation would force the workflow described in the article to not have a grim outcome for elderly users of gmail.
Since opening all these offices costs money, this means that the accounts can't be free anymore. I suppose they could be subsidized by the state for low income people.
Re: Librarian's Letter to Google Security
#407Earlier quoted context omitted.
Not sure data theft from homeless or poor people is a major threat. What could an attacker gain from that?
I can see some value in it for scammers, hackers, and businesses that pray on the poor. (For example the 'buy now, pay later' Aaron's Rent-A-Center type businesses). Or for identity theft.
Re: Librarian's Letter to Google Security
#408Earlier quoted context omitted.
Even at Google's scale, they cannot afford to provide high-touch tech support for 1.5 billion users. The fact Gmail is possible is partially due to their ability to scale low-touch tech support for free by supplementing the cost from other sources and, sometimes, just providing best-effort support. (Remember, the cost isn't "How do we field calls from a fraction of our 1.5 billion users," it's "How do we tell whether…
Perhaps they shouldn’t offer services they cannot support?
I remember being *stunned* in a positive way by Google's out of the box thinking back when they *invented* "self-service" account management, aka "no phone support provided". I thought that it was a brilliant move and that this little search company was really going places.
I hope I might be forgiven for failing to anticipate the consequences for our least affluent sisters and brothers.
I am now of the opinion (for many, many reasons) that human-interactive customer support is a mandatory cost of doing business when your business is materially important in the lives of the customers (both paying and not paying customers).
That Gmail is "materially important" is well established already, yes?
Re: Librarian's Letter to Google Security
#409Earlier quoted context omitted.
Then it opens up a backdoor for malicious (or socially engineered) library staff to access email accounts.
I think it would be fine for the library to have/be the 2ND FACTOR and the user would still need their password. Being at a physical location seems like a reasonable 2FA (more reasonable than a phone in these cases). Could the library buy a few FIDO tokens, hot glue them into the backs of the computers, users add them as 2fa to their accounts and now the computer being wiped between users is no longer an obstacle?
- Users would only be able to use the exact same computer each time. If it’s out of order, too bad
- Users wouldn’t have unique tokens between each other, so there’s a risk of other library patrons shoulder surfing and then logging in with the same token after you
Re: Librarian's Letter to Google Security
#410This is not really Google's "fault". (trust me I'm not a fan of their cavalier attitudes to beta services and lack of customer support) They are working "in the future" where every human has access to the virtual world by "right". You cannot cut off someone's gas or phone without huge regulatory hurdles. And we will see something similar for access to internet We just aren't there. And that's the problem. And this co…
I am guessing this is what a bunch of companies offering the "photo of you and your id" services are waiting for.
Which to me implies it should never be a proprietary solution - anyone know of a FOSS version of this out there? Anyone want to start one ?