Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

431–440 of 484 posts

Re: Librarian's Letter to Google Security

#431

Earlier quoted context omitted.

>Even at Google's scale, they cannot afford to provide high-touch tech support Yet somehow companies of similar scale like Amazon, Apple and Netflix manage to provide robust customer service.

Keep in mind that all three of these companies provide support primarily to customers who have paid them. If you are on the phone with Apple about being locked out of an account, you have likely spent at least several hundred dollars buying their devices.

Keep in mind that Google makes a fortune selling customer data in the form of advertising.

If they want to continue to harvest their customer's data they can provide those customers with support.

Also, those Google devices aren't free. You buy a Google device, get no support, and the devices are updated for way fewer years to boot.

Re: Librarian's Letter to Google Security

#432

Earlier quoted context omitted.

>Even at Google's scale, they cannot afford to provide high-touch tech support Yet somehow companies of similar scale like Amazon, Apple and Netflix manage to provide robust customer service.

Apple has a full order of magnitude fewer iPhone users than Gmail accounts. I'm pretty sure, unless I have misunderstood, that acquiring an iCloud email account requires ownership of a physical Apple device... If you're suggesting we should back-stop this problem of marginalized users losing access to Gmail by subsidizing the homeless or elderly to own iPhones, I don't think it will work. Amazon is similarly an order…

Google makes more than enough money to be able to provide customer support.

They simply choose not to.

Re: Librarian's Letter to Google Security

#433
@dang maybe worth removing this post?

> STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS

> This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longer are having this issue as often as before due to various improvements.

> Please delete this from HN. You are essentially DDOS’ing my work email and the library branch phone number making it very difficult for us to perform our duties as civil servants today.

> I do not know how this made it onto HN. Someone must have leaked it. If they need to work that out internally then I’m leaving this here for their reference. But I do not want news reporters or random HN readers contacting me or the Free Library over this.

Re: Librarian's Letter to Google Security

#434

Earlier quoted context omitted.

only a paid for service can really expect paid support staff. Why? You make it sound like Google is a pauper, doling out free e-mail accounts and not making any money off of it. Just because it's not billing your credit card doesn't mean you're not paying for GMail. You just pay for it indirectly through advertising. If only a paid service can expect paid support, then how does Google make hundreds of billions of dol…

Even at Google's scale, they cannot afford to provide high-touch tech support for 1.5 billion users. The fact Gmail is possible is partially due to their ability to scale low-touch tech support for free by supplementing the cost from other sources and, sometimes, just providing best-effort support. (Remember, the cost isn't "How do we field calls from a fraction of our 1.5 billion users," it's "How do we tell whether…

> Even at Google's scale, they cannot afford to provide high-touch tech support for 1.5 billion users.

This doesn’t seem that hard. Charge for support if they have to (eg charge per minute or call).

In terms of working out if a call is an attack, far juicier targets such as banks are able to manage, I think they can work it out.

Re: Librarian's Letter to Google Security

#435

Earlier quoted context omitted.

Or perhaps someone can setup an email system primarily for the benefit of public library users. Run it as a non-profit / low-profit and provide basic support, do not require 2-factor authorization. Basically the way email was for many in the late 1990s, when they got email through their schools or universities, or perhaps through AOL or Compuserve.

> Basically the way email was for many in the late 1990s Keeping in mind that the reason 2FA came along was that we learned the hard way that passwords are not sufficient to secure an account accessible on the public Internet. Too many effective side-channel attacks (both phishing the user and exploiting human psychological vulnerability, i.e. pulling passwords from another site and discovering that the same account…

That's right! What better form of 2-factor authorization than giving someone a human to talk to and show some form of ID (if needed) for someone to reset access to a system? Of course there needs to be trust for the public library employee, but that one person could have more rigorous forms of 2FA than the average public library user. Google isn't the company to offer this sort of thing, so I am hopeful there could be some alternative. However, encouraging random library users to sign up for a non-Gmail (non-Hotmail / non-Outlook / non-Yahoo) email system is the primary challenge.

Re: Librarian's Letter to Google Security

#436
post #352

Earlier quoted context omitted.

You nailed it. In the physical goods world, there is no company that is allowed to dump products onto market and pretend like their customers do not exist. If their product cause harm to the consumer, their products will get recalled or they'd get sued. Google has somehow allowed itself to infinitely scale their users but also infinitely shrink their liabilities/duty by binding all users to their ToS which foists arb…

If google's products cause harm, they also get recalled and/or google gets sued.

You seriously believe in business karma? Apply it to oil, arms dealing, pill pushing pharma. It may happen, but the profit was still there.

The article states some types of harm causes, and those people are struggling for an few dollars, they can’t sue Google.

Re: Librarian's Letter to Google Security

#437

@dang maybe worth removing this post? > STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS > This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longer are having this issue as often as bef…

Posting a summary might be better. The discussion here is good and the points interesting.

Re: Librarian's Letter to Google Security

#438
post #314

Earlier quoted context omitted.

The specific anger towards Google comes from the fact that they're an overwhelmingly popular email provider, and email is what a lot of paperless processes (including account resets) assume the existence of. If you get locked out of Amazon, or Facebook, or Instagram, or TikTok, or Reddit, or Twitter, or Netflix, you won't lose the ability to receive welfare benefits, or tax information, or rent / utility bills, or st…

You're absolutely right - everyone has offloaded the 'identity verification problem' to your email provider. Because doing it well is an intrinsically hard/expensive problem. Replace 'government should provide a digital identity service' with 'government should provide an email service', and we're back at the same place. You still needs a way to prove that you are you - with legal protection and recourse. This letter…

> You still needs a way to prove that you are you - with legal protection and recourse.

You actually have something that you can use- your reputation. It is difficult to fake your likeness, even moreso to people who actually know you. A combination of past preshared secrets (memories) alongside your likeness is enough to get people who DO have ID to vouch for your identity- family, your landlord, your neighbor, your lawyer, your employer, past schoolteacher, anyone who can reasonably be expected to recognize you and have had some experiences with you, can discern whether or not you are who you say you are.

From there you could have access to your theoretical USPS or Library email, add an additional PGP key to publicly-funded keyservers, and generally use the power of this vouch to escalate from there.

Even if you make an extreme edge-case argument, saying that someone has some extreme amnesia and finds themselves far away from their home, the government could just let you generate a completely new identity for a small fee, so that you aren't left high and dry without one.

Re: Librarian's Letter to Google Security

#439

I fully sympathize with the librarian's concerns, but there's this: "Many government welfare forms, housing applications, and jobs applications these days require the use of the internet exclusively with no option to fill things out in person." Why is this? Really, this does not seem like a problem Google caused, but rather a problem caused by the government when they made it mandatory to have internet access to get…

> Really, this does not seem like a problem Google caused, The problem is 2FA. 2FA causes people to get locked out of their accounts. Google mail requires 2FA, the government does not. If Google turns off 2FA requirement, the problem in the letter goes away. But they won't. Google is the cause of the problem, and can easily solve it.

Google didn't introduce 2FA for no reason. While Google does lots of things for reasons I don't like, 2FA was most definitely introduced for valid reasons, which could easily result in a problem as bad (or worse) than the one the librarian is discussing.

The IRS recently had a problem with people using their online access tools to get other people's refund. Insufficient security on authentication can easily be as bad or worse than 2FA.

Re: Librarian's Letter to Google Security

#440

Earlier quoted context omitted.

Even at Google's scale, they cannot afford to provide high-touch tech support for 1.5 billion users. The fact Gmail is possible is partially due to their ability to scale low-touch tech support for free by supplementing the cost from other sources and, sometimes, just providing best-effort support. (Remember, the cost isn't "How do we field calls from a fraction of our 1.5 billion users," it's "How do we tell whether…

> Even at Google's scale, they cannot afford to provide high-touch tech support for 1.5 billion users. This doesn’t seem that hard. Charge for support if they have to (eg charge per minute or call). In terms of working out if a call is an attack, far juicier targets such as banks are able to manage, I think they can work it out.

There are legal requirements of banks carrying enough PII on a person to reliably unwind an auth attack (and also to send the cops after them if they are the ones who commit fraud).

This would be one solution. But it would require Google to hold significantly more PII, explicitly, on every Gmail user than they do right now (and make the process of opening a Gmail account take a bit of time, like it does at a bank). This is one of the better suggestions I've heard, though it would threaten the integrity of the existing 1.5 billion accounts unless Google grandfathered them into a "low-identification" status.

Post reply on HN