Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

361–370 of 484 posts

Re: Librarian's Letter to Google Security

#361
post #118

If a large percentage of computer users who use the library exclusively have ID, the library could purchase a MF device or cheap android phone running an MFA app and use the same device for every user or many users: show your ID, librarian verifies that you're registered, and then come over and log you in with key + username (user still enters password). Would it be possible for some nefarious person to grab these ke…

Forcing public libraries to use a workaround to fix a problem Google created isn't an ideal solution.

I'm not sure what an ideal solution might look like. Do you have a thought on that?

OTOH this library use case is a specific kind of outlier: I imagine this issue occurs in most/all libraries; it's a situation where changing the level of security is worth the tradeoff; it doesn't affect the security of anyone else; it's relatively inexpensive.

I don't consider this a "blame the victim" solution to the problem. I see it as an accommodation for people with specific but special needs.

Re: Librarian's Letter to Google Security

#362

Great letter. Wanna bet it was completely ignored? Glad to see it here. Maybe it won't be ignored. Librarians rock. There's even a show about them[0], Starring Number One. I can't access the gMail account I set up, because I made a mistake, when setting the password, and did not save the one I used. It will not allow me to access the account I set up. After a while, I just gave up. I am satisfied that someone can't u…

Currently the doc says:

""" STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS

This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longer are having this issue as often as before due to various improvements.

Please delete this from HN. You are essentially DDOS’ing my work email and the library branch phone number making it very difficult for us to perform our duties as civil servants today.

I do not know how this made it onto HN. Someone must have leaked it. If they need to work that out internally then I’m leaving this here for their reference. But I do not want news reporters or random HN readers contacting me or the Free Library over this. """

Seems like it was not ignored and was already resolved.

Re: Librarian's Letter to Google Security

#363
New heading on the doc. Please don’t try to contact the author. Quoting:

STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS

This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longer are having this issue as often as before due to various improvements.

Please delete this from HN. You are essentially DDOS’ing my work email and the library branch phone number making it very difficult for us to perform our duties as civil servants today.

I do not know how this made it onto HN. Someone must have leaked it. If they need to work that out internally then I’m leaving this here for their reference. But I do not want news reporters or random HN readers contacting me or the Free Library over this.

Re: Librarian's Letter to Google Security

#364
post #253

Earlier quoted context omitted.

Do any of them offer phone support?

You're missing the point. When a poor tech illiterate person signs up for an email account, they probably don't consider if they will someday need phone support to recover an account. They will choose a free account over an account that costs $5/month that they don't have. And that assumes that they even know about the paid email services. For a lot of tech illiterate people email and gmail are synonymous.

And the "don't have" you state, is key here. There is no way the poor people the librarian is talking about, can afford that 5 bucks.

Re: Librarian's Letter to Google Security

#365
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

Library op-sec is pretty weak IME. Mine accepted seeing an email of a utility bill on my phone. Which is probably fine for just checking out books. I still love libraries and the services they provide. But wouldn't want them to be an arbiter of identity any more than a faceless, human hostile corporation.

> Mine accepted seeing an email of a utility bill on my phone. Which is probably fine for just checking out books.

I mean, I just got my `REAL ID` from California, and they accepted printed utility bills as proof of address for me. I could have easily modified the name and/or address on them before printing.

The other proof of identity I used was my birth certificate... that I was able to just order online with the only information required from me was my social security number and answering a few questions that would not be that hard to find out about someone.

Proving identity in a way that works for everyone while not allowing anyone to fake it is practically impossible.

Re: Librarian's Letter to Google Security

#366
post #229

If the US government created its own SSO system and mandated that all government website used it as primary while allowing third parties to use it too this could become a solved problem. It would be a credential that could be accessed via existing paper based systems. Places like Google allowing it as a sign in method would actually solve this case. Sadly I think the tech world in general is so allergic to losing pri…

login.gov exists. It's not mandated, nor does it currently allow non-government users(last I checked), but otherwise it generally solves the technical problems fine.

You can sign-in as a non-government user (though they also have CAC support for federal govt users). There's built-in document/identity proofing as well but there are some extra requirements to get that enabled on an application.

You do need to be working with the government to integrate with Login.gov though (but it's just OIDC on the backend)

Re: Librarian's Letter to Google Security

#367

Earlier quoted context omitted.

When i lost my phone and was locked out of 2fa, most services required a picture of me, with my ID, my face and a letter showing the date all in the same picture. This seemed pretty effective to me.

Google doesn’t have a picture of me linked to my gmail account, so this would require as much planning as printing 2fa backup codes right?

They would use photo ID the same way everyone else does. Compare the photo on the ID to the picture the person provides; which is why it needs todays date in the photo.

Re: Librarian's Letter to Google Security

#368
post #187

Earlier quoted context omitted.

but what would Google do, how is it possible to fix? What's the point of having 2FA using the phone if you can bypass it by clicking "i don't have my phone"?

When i lost my phone and was locked out of 2fa, most services required a picture of me, with my ID, my face and a letter showing the date all in the same picture. This seemed pretty effective to me.

Not for people who are homeless or don't have an ID for whatever reason, and need access to social services.

Re: Librarian's Letter to Google Security

#369

New heading on the doc. Please don’t try to contact the author. Quoting: STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longer are ha…

[deleted]

Re: Librarian's Letter to Google Security

#370
post #54

This is one of those situations that make it incredibly clear that even Google, with all its resources, never considers the use case or life experience of anyone besides a wealthy Bay Area tech worker when designing their products. I can't help but wonder how this blind spot got so big - and why they still don't address things like this even with all the user testing & A/B trials they do for ruthless optimization. Is…

This blind spot got so big because the vast majority of wealthy Bay Area tech workers have never been poor or homeless. It is difficult for those that have never lived in poverty to understand the struggles that it brings. Just look at his thread, see how many people fail to comprehend that if someone is using the library computers they aren't going to be able to afford a $25 key-chain verifier.

> It is difficult for those that have never lived in poverty to understand the struggles that it brings.

I think this is giving too big of a pass to wealthy people. If wealthy people put in the effort, it isn't hard to understand the struggles that living in poverty bring. I think a better way of putting it is "It is very easy for those that have never lived in poverty to not consider the struggles that it brings". There is no difficulty in understanding, it is just easier to not every try to understand, so many wealthy people don't. It is a choice, though.

Post reply on HN