Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

411–420 of 484 posts

Re: Librarian's Letter to Google Security

#411

Earlier quoted context omitted.

> trusted civic authorities They'll need to be resistant to threats and bribes, so it will be difficult to have these on-site at the library. I think we've overlooked an option. Note that the article's objection to FIDO keys was financial, not UX. This sort of confirms the hunch I got when first playing with them: "hey, the key metaphor is so strong and intuitive that these might be even better than passwords for peo…

It is not uncommon for unhoused people to lose all their possessions, so even if purchasing multiple hardware security keys wasn't a huge financial hurdle, the recovery model I use (Yubikey on my keychain, two in my safe, mail one to my parents) falls apart for those on the margins of society. If email is an essential service in modern society, recovering access to it from some first principle of identity is essentia…

The CEO of Fastmail, a company which deals directly with the ID problem as an email provider with customer service, has made some insightful comments on this:

https://news.ycombinator.com/item?id=15864579

I am a happy Fastmail customer, in a large part due to trust inspired by Bron’s comments.

Re: Librarian's Letter to Google Security

#412
This can be solved unilaterally by the library system, with no extra action by google. I would furthermore argue that it should be solved by the library, rather than by google, as the library has the ability to solve this problem more completely.

As a brief introduction, the goal of computer security is generally to make a computer as secure as a door lock. A door lock can be easily broken into, but to do so requires that a person show up to the door in person, and to take some illegal action. A computer, if secured naively, is much less secure than that: if I gain access to the password, I can hack a computer from anywhere in the world. Furthermore, since I have the password, it isn't even clear that I am breaking any rules.

The library system can solve the problem described in the letter while maintaining door-lock level security in the following way: they would give to every library system user a library card, associated with their person. This card would be used to log in to library computers. Certain information would be preserved between logins, namely the browser cookies. Thus, the user would remain logged in to their google account as long as they had access to their library card. If they lost the card, or forget the password, the library would be able to reset the password, or issue a new card, as long as the user could prove they were the owner of the card to the satisfaction of the library employee.

Google, being an internet company, cannot reasonably issue cards to all their users, but libraries regularly do so. For the same reason, Google has difficulty verifying the identity of their users, which libraries can do easily. Google is structured as a profit seeking corporation, and would need to justify charitable behaviour to shareholders. Libraries are well known to exist to provide services for free to their users, and can easily alter their operations to do so differently. Most importantly, libraries already provision physical access to computers. The most important element of our door-lock security model is that a person must appear in person in order to get around our security. The library is the organization operating the physical terminals, and so the library alone can provide this essential element of our security model.

Re: Librarian's Letter to Google Security

#413

I fully sympathize with the librarian's concerns, but there's this: "Many government welfare forms, housing applications, and jobs applications these days require the use of the internet exclusively with no option to fill things out in person." Why is this? Really, this does not seem like a problem Google caused, but rather a problem caused by the government when they made it mandatory to have internet access to get…

One of the issues they mention is that that a person needed paystubs to send in to the government as documentation for their subsidized housing. Even if the government has nice paper options as a backup (around here they usually do, at least) the person will still need to get into their email. Google didn't create the problem, but unfortunately an eMail address has become a centralized point of communication for lots of things.

We probably need some sort of state-sponsored digital inbox for these kinds of documents. The thing that makes Google useful -- that it is a "reasonably" secure location to stash documents -- also makes it really easy to get locked out. There are recovery options, but it isn't obvious how a system could be secure while still allowing recovery for a user who elects to not set any recovery options up.

Perhaps the government could do a better job (at least they have things like social security cards and birth certificates, and have been dealing with the last resort case where these aren't available for longer than any of us have been alive). They also aren't constrained by things like a need to make a profit, and they don't even really need us to be able to communicate out from this inbox, it could be just a one-way channel for the reception of documents, which would avoid some annoying issues ala people using their gmails to harass others.

Re: Librarian's Letter to Google Security

#414

Earlier quoted context omitted.

Yes, but not being able to recover the account, is a bug. The issue was that I used a randomly-generated password from 1Password, and accidentally re-generated, before copying, so the original was lost. That's a fairly common mistake. I'm usually careful to avoid that (now).

At least in bitwarden app they provide history of passwords for every url.

So does 1Password. However, the generator can be run standalone (not connected with an entry). In that case, the password is not saved, because there's no entry to save it to.

It does not offer to automatically create an entry, until after the login, so it's still quite possible to "fall through the cracks," which is what happened here.

Yeah, my bad. :P

Re: Librarian's Letter to Google Security

#415
post #412

This can be solved unilaterally by the library system, with no extra action by google. I would furthermore argue that it should be solved by the library, rather than by google, as the library has the ability to solve this problem more completely. As a brief introduction, the goal of computer security is generally to make a computer as secure as a door lock. A door lock can be easily broken into, but to do so requires…

nope

Re: Librarian's Letter to Google Security

#416
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

a protocol where trusted civic authorities could be allowed to confirm someone's identity This is already a solved problem, and without getting the government involved. There are plenty of identification confirmation companies out there. If you've ever requested your credit report, or applied for a new apartment online, you've probably interacted with one. Oh, but that's an expense. It might costs pennies per user! G…

That doesn't show that you're that person, however, only that you've learned some trivia about them — often details which are visible on Facebook, pilferable from their mail, or known to no longer trustwothy family members & friends. My hope would be that we could find a way to reliably fall back on a government ID check since, for example, an abusive ex who knows all of those details doesn't look like their target.

Re: Librarian's Letter to Google Security

#417
"It must be possible to [...] contact customer support"

I'll stop you right there. While I feel for the folks affected by this, they're not customers. And there ain't no such thing as a free lunch.

Broadband access and an email inbox aren't human rights in the US - even if they should be, we're just not there yet. And Google has no business incentive to provide customer support to the freeloaders.

I think it's crappy that there's no recourse too. But like it or not, users assent to this when they sign up. The solution here is education - people need to be told outright that they have significantly reduced chances of recourse when they're using somebody's service for free.

Society seems to have abetted the notion that all citizens will have Gmail accounts, down to the issue of Chromebooks in elementary schools. What exactly are we teaching people by dropping them off inside these gardens to bang on the walls?

It goes further than Google or Gmail. We need processes that make actual sense. "But the government forms I need to fill out are online-only!" First mistake. Whoever signed off on that in government should be fired immediately.

This isn't a Google problem, despite how easy it may seem to blame the faceless boogeyman. It's an education problem, a process problem, and a common-sense problem.

Re: Librarian's Letter to Google Security

#418

Earlier quoted context omitted.

I don't. Customer support is a cost sink that usually isnt empowered to do anything. Its more PR tactic to make people feel they are "heard" without resorting to twitter. In the email/business apps space, google is clearly not a monopoly. Presence/quality of customer support seems a very reasonable grounds to have normal competition over.

Customer support is a cost sink Too bad. If you have a business (and Google is a business) that goes business with the public (which Google does), you should offer some form of customer services. It's what we human beings call "the right thing to do." Yes, customer service costs money. It costs money for the dry cleaners, the restaurants, the banks, the car washes, the design firms, and every single other company on…

> Too bad. If you have a business (and Google is a business) that goes business with the public (which Google does), you should offer some form of customer services. It's what we human beings call "the right thing to do."

Lets pause on that thought.

Why is there a moral imperative to offer customer service (provided they dont misrepresent that they do)? What is the basis for a moral obligation?

Its not like there is a line in the bible saying "thou shalt offer tech support". Admitidly im not convinced by religious arguments, but i dont see any more modern moral source either.

> Imagine if Google's vendors stopped offering Google customer service. Janitor didn't show up today? Well, clean your own office toilet today, technie. Surely, there's a YouTube tutorial for that.

That's not really a customer support inquiry. That said, one of two things happen - either they are ok with it, or they are not. If they are not they negotiate other terms or hire a different cleaning company.

I'm not saying you have to like google's policies, just that its not unethical for google to have policies you don't like.

> Bullshit. It has billions and billions and billions of dollars that it can throw at the customer service problem, but it doesn't for one simple reason: Greed.

Wait. Are you telling me that a private corporation in america is trying to maximize profits? The horrors. I would have never guessed. What next? Is the sky blue?

> How about the restaurant down the street maximizes its shareholder profits by not honoring your reservation?

A) that action does not maximize shareholder profit.

And b) its wrong because they promised something and didn't deliver. The sin is in the reneging.

If google promised customer support and didn't deliver, that would be wrong. But google didn't promise customer support.

> How about the dry cleaner optimizes its workflow by only being open three minutes a day?

Sounds like a shitty dry cleaner, but i fail to see the ethical issue. If the dry cleaner doesn't meet your needs, don't use it.

Quite frankly, i think this entire thing reeks of entitlement. Just because someone offers to sell you a service, doesn't mean they have an obligation to provide it in the fashion you want. Their obligation is to not mislead, and be honest about what they are offering. Maybe what they are offering works for you, maybe it doesn't. If it doesn't dont do business with them.

> If Google is so wonderful, full of so many smart people, then how come it can't solve its customer service problem?

Because they don't want to and there is nothing wrong with that.

Re: Librarian's Letter to Google Security

#419
post #230

All the anger toward Google misses the larger point – this isn’t only Google's problem. If I get locked out of my Apple account, or my Amazon account, or my account, how do I prove that I am me? A password? I’m glad your memory is much better than mine, because I'm terrible at remembering 1000 passwords that aren’t trivially cracked. Use a password manager? Oh yeah! I do, thanks. On my computer and phone along with..…

The specific anger towards Google comes from the fact that they're an overwhelmingly popular email provider, and email is what a lot of paperless processes (including account resets) assume the existence of. If you get locked out of Amazon, or Facebook, or Instagram, or TikTok, or Reddit, or Twitter, or Netflix, you won't lose the ability to receive welfare benefits, or tax information, or rent / utility bills, or st…

It's not just that. Yahoo is a very popular free email provider as well, and since it doesn't require MFA, it avoids a whole category of these account lockout issues. So the anger is that Google has required this feature but has not identified sufficient flows for recovery, and in particular does not offer any kind of "catch-all" escalation where you can explain your situation to someone who can individually do something about it.

Re: Librarian's Letter to Google Security

#420
post #352

Earlier quoted context omitted.

Customer support is a cost sink Too bad. If you have a business (and Google is a business) that goes business with the public (which Google does), you should offer some form of customer services. It's what we human beings call "the right thing to do." Yes, customer service costs money. It costs money for the dry cleaners, the restaurants, the banks, the car washes, the design firms, and every single other company on…

You nailed it. In the physical goods world, there is no company that is allowed to dump products onto market and pretend like their customers do not exist. If their product cause harm to the consumer, their products will get recalled or they'd get sued. Google has somehow allowed itself to infinitely scale their users but also infinitely shrink their liabilities/duty by binding all users to their ToS which foists arb…

If google's products cause harm, they also get recalled and/or google gets sued.
Post reply on HN