Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

471–480 of 484 posts

Re: Librarian's Letter to Google Security

#471
> There doesn’t seem to be any warning given that if they fail too many times they may permanently lose access to their account.

That can't actually be a thing, because it would allow a malicious person to lock out anyone's account if they just know their gmail address. Not even Google could be that stupid.

Re: Librarian's Letter to Google Security

#472

Earlier quoted context omitted.

>I made a mistake, when setting the password That's a feature, not a bug.

Yes, but not being able to recover the account, is a bug. The issue was that I used a randomly-generated password from 1Password, and accidentally re-generated, before copying, so the original was lost. That's a fairly common mistake. I'm usually careful to avoid that (now).

Some people generate random passwords and never use them, always using recovery to regain access. That has to work.

Re: Librarian's Letter to Google Security

#473

Earlier quoted context omitted.

Keep in mind that all three of these companies provide support primarily to customers who have paid them. If you are on the phone with Apple about being locked out of an account, you have likely spent at least several hundred dollars buying their devices.

Keep in mind that Google makes a fortune selling customer data in the form of advertising. If they want to continue to harvest their customer's data they can provide those customers with support. Also, those Google devices aren't free. You buy a Google device, get no support, and the devices are updated for way fewer years to boot.

> Also, those Google devices aren't free

You keep mixing things up. The topic is the viability of high touch GMail support, not support for Google's home-grown devices.

Re: Librarian's Letter to Google Security

#474

Earlier quoted context omitted.

Walking through a drive-thru probably becomes an insurance and liability risk; and depending on local laws, it might be seen as a pedestrian entering traffic.

It’s private property so traffic laws won’t apply. Pedestrians are allowed all over parking lots.

good point, didn't think of that!

Re: Librarian's Letter to Google Security

#475
post #460
post #246

Earlier quoted context omitted.

but you already know what will happen next, don't you? People would stop using 2FA, then some donkey on government contract with access to nuclear weapons gets hacked, and everybody would lose their mind: "how could google be so stupid to allow people not use 2FA?!?!?!"

I'd be asking why was someone using gmail for anything related to nuclear weapons.

I don't know if you are being sarcastic or naive here... Why would Hillary use her own email server for critical government correspondence? I don't know! Reasons I guess. People on all levels tend do stupid stuff every once in a while

Re: Librarian's Letter to Google Security

#476

Earlier quoted context omitted.

Google is still a huge part of the problem for requiring all kinds of acrobatics to log into their service which you are forced to use due to the fact that it's one of the only free email providers, the fact that email is pointlessly required to use most websites, and the fact that a huge amount of websites only allow gmail and a few other hosts (yes, there are also other stupid websites that go the other way around…

> a huge amount of websites only allow gmail and a few other hosts Is that actually true? I’ve never seen a single site that didn’t allow me to log in with a ‘regular’ email address, even if they pushed Log in with Google first

Lots of sites have whitelists of email domains.

Re: Librarian's Letter to Google Security

#477

I fully sympathize with the librarian's concerns, but there's this: "Many government welfare forms, housing applications, and jobs applications these days require the use of the internet exclusively with no option to fill things out in person." Why is this? Really, this does not seem like a problem Google caused, but rather a problem caused by the government when they made it mandatory to have internet access to get…

> The government caused this problem.

The HN community caused this problem. I precisely remember about 10 years ago on HN I'd see obnoxious articles with thousands of upvotes hyping crap like "we disrupted the goverment" and "we saved a lot of paper by providing a webshit interface to government institutes" and "we replaced non-working COBOL crap with new JS crap it's so much better". And of course they followed suit with "security best practices" such as having a hidden security policy (that an attacker can easily find out) and "advanced risk model", which is something 99% of websites get wrong despite that they all regurgitate the standard "we have a complex risk model, you do not know what you're talking about". What we have now is absolutely, literally what my expected outcome was for this movement, at the time, 10 years ago.

Re: Librarian's Letter to Google Security

#478
post #229

If the US government created its own SSO system and mandated that all government website used it as primary while allowing third parties to use it too this could become a solved problem. It would be a credential that could be accessed via existing paper based systems. Places like Google allowing it as a sign in method would actually solve this case. Sadly I think the tech world in general is so allergic to losing pri…

login.gov exists. It's not mandated, nor does it currently allow non-government users(last I checked), but otherwise it generally solves the technical problems fine.

That is perfect! Just need it to be opened up a little so that places like Google can enable it as a Lyn optional primary login.

Re: Librarian's Letter to Google Security

#479
post #18
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

I agree with your suggestion. I think Post Offices, DMVs, and large reputable retailers (Walmart, Target, Cellular Phone companies, etc.) could verify our identities for a small fee and help us reset our social accounts when needed. I arrived at the same conclusion and wrote a blog post about it a few years ago: https://www.go350.com/posts/now-they-have-2fa-problems/

This is widely implemented and used in Germany: https://www.deutschepost.de/en/p/postident.html

It's a lot easier to implement reliably due to the requirement for everyone to have ID cards though (and the ID cards carry your residence address).

Re: Librarian's Letter to Google Security

#480

Earlier quoted context omitted.

Perhaps they shouldn’t offer services they cannot support?

This! I remember being *stunned* in a positive way by Google's out of the box thinking back when they *invented* "self-service" account management, aka "no phone support provided". I thought that it was a brilliant move and that this little search company was really going places. I hope I might be forgiven for failing to anticipate the consequences for our least affluent sisters and brothers. I am now of the opinion…

It's the opposite. Paid services where you get to speak to a human require more affluence.
Post reply on HN