Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

451–460 of 484 posts

Re: Librarian's Letter to Google Security

#451

Earlier quoted context omitted.

> Really, this does not seem like a problem Google caused, The problem is 2FA. 2FA causes people to get locked out of their accounts. Google mail requires 2FA, the government does not. If Google turns off 2FA requirement, the problem in the letter goes away. But they won't. Google is the cause of the problem, and can easily solve it.

Google didn't introduce 2FA for no reason. While Google does lots of things for reasons I don't like, 2FA was most definitely introduced for valid reasons, which could easily result in a problem as bad (or worse) than the one the librarian is discussing. The IRS recently had a problem with people using their online access tools to get other people's refund. Insufficient security on authentication can easily be as bad…

[deleted]

Re: Librarian's Letter to Google Security

#452
The letter has now been updated today, please read:

  STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS
  
  This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longer are having this issue as often as before due to various improvements.
  
  Please delete this from HN. You are essentially DDOS’ing my work email and the library branch phone number making it very difficult for us to perform our duties as civil servants today.
  
  I do not know how this made it onto HN. Someone must have leaked it. If they need to work that out internally then I’m leaving this here for their reference. But I do not want news reporters or random HN readers contacting me or the Free Library over this. 
  
  If you want to learn more about patron privacy and support librarians advocating for patron privacy and against big tech please check out https://libraryfreedom.org/ which is a wonderful organization I am a part of that does work like this. I still firmly believe in and stand by everything that I wrote. But this particular action was not meant to be a public letter and it’s interfering with my ability to do other work. You’re welcome to read this, now redacted, letter, just please stop emailing me and sharing it around.

Re: Librarian's Letter to Google Security

#453
The library customers can install app called "Google Authenticator" provided they own a smartphone. It works without network connectivity.

Just use the app to scan QR code when creating a Gmail account. Or do it anytime later. Then never use network connectivity to generate the 6-digit 2FA code.

Re: Librarian's Letter to Google Security

#454
post #188

Earlier quoted context omitted.

Then it opens up a backdoor for malicious (or socially engineered) library staff to access email accounts.

And given that a lot of the staff working those desks aren't librarians + are working part time, it's also great incentive for bad actors to get jobs in libraries specifically to start stealing that data.

That seems like a movie plot threat: who’s going to go to library school, pass a background check (government job, access to children), and actually do a job which isn’t easy and doesn’t pay anywhere near enough just in the hopes that someone will walk in the door with enough money to be worth scamming in a manner which is both obvious and easily traced to them?

Re: Librarian's Letter to Google Security

#456

[Edited] Removed a link to respect library's privacy

As of your comment, the letter says that they're being essentially DDOS'ed over an issue that was resolved a long time ago and to very specifically NOT ask them anything; posting this link isn't moral and I think you should edit it out.

Re: Librarian's Letter to Google Security

#457
post #143

Earlier quoted context omitted.

My goodness, I think you just might be lacking in empathy. I honestly recommend that you take a step back and reread what you have written here. > But the way the letter is written makes it clear that she's not very familiar with the tech industry or how things are developed And she should not have to be familiar with the tech industry. The tech industry's job is to figure out what the users want, by understanding wh…

I'm a colleague of Shelley's, loosely: I've been working in libraries since 2004, a fair amount of it in public service, and my first job was literally teaching people basic technological skills in a public library. I don't think it's 'lacking empathy' to focus on whether or not the tactics or strategies my allies are using are likely to, you know, work. I would consider it more important that the letter be taken ser…

Focusing on tactic and strategy is the opposite of empathy. An empathetic response communicates that you understand the feelings and experience of someone else. Your comment did the opposite by only focusing on your own thoughts/desires/experience. You may find it useful to research emotional intelligence so that you can respond appropriately and productively to another's emotional state.

https://students.ubc.ca/ubclife/emotional-intelligence-101-e...

Re: Librarian's Letter to Google Security

#458

[Edited] Removed a link to respect library's privacy

As of your comment, the letter says that they're being essentially DDOS'ed over an issue that was resolved a long time ago and to very specifically NOT ask them anything; posting this link isn't moral and I think you should edit it out.

Thank you for bringing this to my attention. Just read the disclaimer and removed the link.

Re: Librarian's Letter to Google Security

#459
Since HN is an entrepreneurial group, this feels like a business opportunity. Probably not a Y-combinator unicorn darling, mind you. Figure out how to help libraries help their patrons get secure reliable access to email and other internet services.

Re: Librarian's Letter to Google Security

#460
post #246
post #213

Earlier quoted context omitted.

a and c can be solved by making it an option for 2fa instead of requiring it.

but you already know what will happen next, don't you? People would stop using 2FA, then some donkey on government contract with access to nuclear weapons gets hacked, and everybody would lose their mind: "how could google be so stupid to allow people not use 2FA?!?!?!"

I'd be asking why was someone using gmail for anything related to nuclear weapons.
Post reply on HN