Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

441–450 of 484 posts

Re: Librarian's Letter to Google Security

#441

Earlier quoted context omitted.

Apple has a full order of magnitude fewer iPhone users than Gmail accounts. I'm pretty sure, unless I have misunderstood, that acquiring an iCloud email account requires ownership of a physical Apple device... If you're suggesting we should back-stop this problem of marginalized users losing access to Gmail by subsidizing the homeless or elderly to own iPhones, I don't think it will work. Amazon is similarly an order…

Google makes more than enough money to be able to provide customer support. They simply choose not to.

That's a pretty [citation needed] assertion. Again, we're talking a risk surface stretched across 1.5 billion users. There are few architectures of that scale in existence today; we're talking Chinese government, every-bank-on-Earth numbers.

I'd be interested to see a workable solution but, to-date, I never have.

Re: Librarian's Letter to Google Security

#442
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

It’s an absolutely catastrophic experience, that they clearly don’t take seriously. Regulation solves this. I hate to say that, as so much of tech regulation is a ham-fisted disaster that misunderstands the problem and creates even bigger ones, but this is really a very serious problem that can ruin lives, and regulators really should step in here. I’ve known a couple of people who have been through this experience,…

I really don’t understand how regulation makes it better? you can simply write down codes if you want a way of recovering a gmail account. Most users don’t do this because they’re not educated and they don’t understand opsec. If a government agency had the power to recover any account, it would be abused by corrupt government officials.

Remember scale when thinking of potential solutions here! it’s not just the US that would be affected by this as well. The reality is that google does a better job at identity any than US government institution (ssn, drivers license). How many people have their identity stolen versus having their 2fa protected gmail account stolen?

As far as support, how would it be better if support gave you access to an email account if you complained enough? please consider the abuse side before you suggest a solution.

Re: Librarian's Letter to Google Security

#443
post #352

Earlier quoted context omitted.

You nailed it. In the physical goods world, there is no company that is allowed to dump products onto market and pretend like their customers do not exist. If their product cause harm to the consumer, their products will get recalled or they'd get sued. Google has somehow allowed itself to infinitely scale their users but also infinitely shrink their liabilities/duty by binding all users to their ToS which foists arb…

If google's products cause harm, they also get recalled and/or google gets sued.

If google's products cause harm, they also get recalled and/or google gets sued.

Yeah, lawyers are just lining up to represent those homeless folks, elderly grandmothers, and people who just don't get tech.

Except they're not.

Clearly you've never been poor.

Re: Librarian's Letter to Google Security

#445

Earlier quoted context omitted.

Customer support is a cost sink Too bad. If you have a business (and Google is a business) that goes business with the public (which Google does), you should offer some form of customer services. It's what we human beings call "the right thing to do." Yes, customer service costs money. It costs money for the dry cleaners, the restaurants, the banks, the car washes, the design firms, and every single other company on…

> Too bad. If you have a business (and Google is a business) that goes business with the public (which Google does), you should offer some form of customer services. It's what we human beings call "the right thing to do." Lets pause on that thought. Why is there a moral imperative to offer customer service (provided they dont misrepresent that they do)? What is the basis for a moral obligation? Its not like there is…

they don't want to and there is nothing wrong with that

You seem to be working with a different definition of "wrong" than the rest of the planet.

There are people becoming homeless and losing government benefits because of Google.

Either you didn't read the letter, or you are a deeply amoral person who should seek professional help.

Re: Librarian's Letter to Google Security

#446

Earlier quoted context omitted.

It’s an absolutely catastrophic experience, that they clearly don’t take seriously. Regulation solves this. I hate to say that, as so much of tech regulation is a ham-fisted disaster that misunderstands the problem and creates even bigger ones, but this is really a very serious problem that can ruin lives, and regulators really should step in here. I’ve known a couple of people who have been through this experience,…

I really don’t understand how regulation makes it better? you can simply write down codes if you want a way of recovering a gmail account. Most users don’t do this because they’re not educated and they don’t understand opsec. If a government agency had the power to recover any account, it would be abused by corrupt government officials. Remember scale when thinking of potential solutions here! it’s not just the US th…

You’ve misunderstood the problem.

Backup codes wouldn’t help here, and the person I was referring to had their 2FA to hand.

Forgetting a password is unrecoverable on gmail - they even had recovery options on the account (secondary email and phone), but the recovery form never asked for that information so it could never be used (it insisted on the previous password). As no member of staff has access to prompt the system to offer a different one of the specified recovery options, the account is permanently frozen to this user (but not potentially to an attacker in the future, assuming that other information could be obtained somehow).

Helping the elderly is hard, but Google’s system is horrifically dangerous to people in ways even Google aren’t aware of.

This was an elderly gentleman, not well versed in computers, but all the savviness in the world couldn’t have helped him. He was forced to just walk away and hope for the best. Holiday snaps, photos of grandkids, personal files - all permanently retained by Google but locked out of his reach forever.

Re: Librarian's Letter to Google Security

#447
You should not use gMail to access federal/state resources, but "state mail". Like DigiD in Netherlands, DataBox in Czech Republic. Both are state ran, associated with your identity. Lost password can be unlocked by going physically to office.

Re: Librarian's Letter to Google Security

#448

Earlier quoted context omitted.

Indeed, but this will then going to face the issue of Gmail (et al.) refusing to accept e-mail sent from small providers.

I am sure a another huge vendor like Amazon, facebook, or Microsoft will step in to provide the email services :)

Ah yes, I can see how this even worse situation could easily happen trying to "fix" the previous one...

Re: Librarian's Letter to Google Security

#449

Earlier quoted context omitted.

I will pass on that, no one should be required to accept messages from anyone

How about "required to not mark as spam"?

If they are refusing messages, there's no need to bother marking them as spam.

Re: Librarian's Letter to Google Security

#450
post #123

Earlier quoted context omitted.

But in this case the affected "portion of the served population" is not even "small" !

It's a small proportion of the served population, not a small population in absolute numbers.

But it still isn't ! Last time I checked, about 20% of the population was not computer literate (and that in a rich country!)

And it might be even larger than that since you need to be rich enough too...

Post reply on HN