Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

291–300 of 484 posts

Re: Librarian's Letter to Google Security

#291

I had a gmail lockout scare recently for my custom domain. And I deeply want to change providers. google is currently both my e-mail provider and my domain registrar. The only thing holding me back is I have a custom domain, I'm not specialized in the web, and it's not super intuitive how to set up my hosting with one company, name registration with another, and e-mail with a third. All for the same custom domain.

Get a brick and mortar Internet shop to help you

Re: Librarian's Letter to Google Security

#292

Earlier quoted context omitted.

The main reason we don't want a ubiquitous national ID is that once it's there, everything will require it, which means everything you do will be tracked. Which is okay until the government decides to go psycho and attack some section of the population. Right now, literally every red state would love to get their hands on logs filled with IDs of people who have anything to do with abortion (a Texas bill makes it ille…

I'd be more sympathetic to this argument if all that info weren't a couple subpoenas or search-warrants away at most —in fact, the government can often just pay for access to these things, usually with the implicit threat that if access isn't granted at a reasonable rate, the business may find itself in some trouble . Like, if we banned private parties from collecting tons of info about us, then maybe that concern wo…

Yes, the government can trace people right now, if people are not protecting their identity. Because there is no ubiquitous ID, it is still possible for you to protect your identity in almost every part of society. But that possibility will rapidly disappear when a ubiquitous ID arrives.

The difference between rounding up people or not is often just whether it is logistically feasible. Right now, even if they collect every kind of data from every business, it would be a nightmare to attempt to collate it all, because it comes in so many sources with so many differing fields that may be out of date or inaccurate or wrong and would have to be normalized etc etc etc. Impractical to do on a very large scale. Except when there's a single identifier they could look for, which would completely solve the problem for them, and make it easy to round people up.

Companies that sell data to the government without the consent of the public is a huge problem we need to deal with, for obvious constitutional reasons (4th amendment).

Re: Librarian's Letter to Google Security

#293
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

In this situation, maybe one thing that could help is if the library holds on to the backup codes for patrons. So they can sort of act as a quasi trusted authority. In fact if these people can't even log in without backup codes, they can just keep their password in their wallet. Of course, yubikeys also work very well in this situation. So the library could sell a yubikey and keep backup codes on file for in case the…

I was thinking among options:

- Library is a Group Administrator for patrons' Google accounts.

- Library offers its own email services to patrons.

- Library holds recovery codes (perferably under some sort of escrow).

All of these put burden on the library, of course. Though there's already a substantial burden.

There's also the issue of itenerant / mobile patrons who may only be using a library on a temporary basis or operate between several locations. How much this is a use pattern I've no idea.

The USPS offering email services might be yet another option. Points of presence in every ZIP code, often several.

Given other ongoing challenges (housing is now a full-blown crisis), the problem of mobile / indigent / precarious indivudal will only grow.

The pattern is also likely to be repeated in other global regions.

Re: Librarian's Letter to Google Security

#295
post #77

This is well meaning and shows an unfortunate side of 2f-auth, but she seems to think that google is in the business of helping people. They are in the business of selling ads. True their search engine has greatly helped a lot of people, as has gmail. But they are in the business of selling ads, and they are not selling enough ads to people who both a) cannot continuously afford a phone number b) are unable to afford…

Regulation can change that.

Re: Librarian's Letter to Google Security

#296

Earlier quoted context omitted.

> More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support. I would recommend a $5/month email service. It would be nice if free Gmail gave even more free stuff, but only a paid for service can really expect paid support staff. Having said that, this seems like a terrible idea from a security perspective. There may well be no way to desi…

only a paid for service can really expect paid support staff. Why? You make it sound like Google is a pauper, doling out free e-mail accounts and not making any money off of it. Just because it's not billing your credit card doesn't mean you're not paying for GMail. You just pay for it indirectly through advertising. If only a paid service can expect paid support, then how does Google make hundreds of billions of dol…

Even at Google's scale, they cannot afford to provide high-touch tech support for 1.5 billion users. The fact Gmail is possible is partially due to their ability to scale low-touch tech support for free by supplementing the cost from other sources and, sometimes, just providing best-effort support.

(Remember, the cost isn't "How do we field calls from a fraction of our 1.5 billion users," it's "How do we tell whether that phone call is an actual user, or just an attacker treating our phone service as yet another attack vector?")

Re: Librarian's Letter to Google Security

#297

Earlier quoted context omitted.

I don't. Customer support is a cost sink that usually isnt empowered to do anything. Its more PR tactic to make people feel they are "heard" without resorting to twitter. In the email/business apps space, google is clearly not a monopoly. Presence/quality of customer support seems a very reasonable grounds to have normal competition over.

Customer support is a cost sink Too bad. If you have a business (and Google is a business) that goes business with the public (which Google does), you should offer some form of customer services. It's what we human beings call "the right thing to do." Yes, customer service costs money. It costs money for the dry cleaners, the restaurants, the banks, the car washes, the design firms, and every single other company on…

> Imagine if Google's vendors stopped offering Google customer service. Janitor didn't show up today? Well, clean your own office toilet today, technie.

At their scale, this exact scenario happens all the time. The back-stop is that Google chooses to stop doing business with unreliable service providers.

This is also an option for Google users. Gmail competitors are just a click away.

Re: Librarian's Letter to Google Security

#298
post #18
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

I agree with your suggestion. I think Post Offices, DMVs, and large reputable retailers (Walmart, Target, Cellular Phone companies, etc.) could verify our identities for a small fee and help us reset our social accounts when needed. I arrived at the same conclusion and wrote a blog post about it a few years ago: https://www.go350.com/posts/now-they-have-2fa-problems/

Walmart may be a reputable retailer, but it is utterly disreputable in being a reliable arbiter of identity. It doesn't train its employees well, its employees are often not the brightest bolts an the box, and those that are often don't give a shit.

As for post offices, they aren't eligible because half the government is actively trying to kill them.

Re: Librarian's Letter to Google Security

#299
post #187

Earlier quoted context omitted.

You're right, that online-only access is definately a government problem. But this: > Even when we clicked “I don’t have my phone” it asked her to open the Google app from the phone that she does not have. That's a google problem. Google fixing their problem would lessen the impact of the government problem. (And, more generally, make gmail a better service for lots of people.)

but what would Google do, how is it possible to fix? What's the point of having 2FA using the phone if you can bypass it by clicking "i don't have my phone"?

When i lost my phone and was locked out of 2fa, most services required a picture of me, with my ID, my face and a letter showing the date all in the same picture.

This seemed pretty effective to me.

Re: Librarian's Letter to Google Security

#300

Someone needs to tell this librarian Google has 2FA backup codes you can just write on a piece of paper.

I've attempted this multiple times through the years.

As of my most recent attempt, the OTP flow still mandates input of a phone number. Those who lack phones cannot request OTP.

Post reply on HN