Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

421–430 of 484 posts

Re: Librarian's Letter to Google Security

#421

Earlier quoted context omitted.

> Imagine if Google's vendors stopped offering Google customer service. Janitor didn't show up today? Well, clean your own office toilet today, technie. At their scale, this exact scenario happens all the time. The back-stop is that Google chooses to stop doing business with unreliable service providers. This is also an option for Google users. Gmail competitors are just a click away.

If Google is not satisfied with the level of cleaning in their buildings and fires the custodial contractor, they don't lose access to their buildings because the janitors walked away with the keys. When people start using Gmail, they don't expect to someday lose access to their online banking and utility bills and all the rest, and by the time it does happen to them and they decide to look for a competitor, a lot mo…

Data portability requirements (i think the gdpr has that) are a reasonable regulation. Something that i am pretty sure already exists in the EU.

Having a human to ramble at about vauge complaints is very different

Re: Librarian's Letter to Google Security

#422
post #101

> This elderly woman, looked to be in her 70s, might lose the roof over her head, due to being unable to log into her Google account, because she lost her old phone and with it, her phone number. I think the real issue is outside of Google's reach. You shouldn't have to lose the roof over your head just because you don't have access to your emails. Sure, it sucks that Google doesn't care if these people lose their ac…

We don't want to address the real issue that a democratic government of 350 million people is slow and ineffective, so we demand that private industry make up for the failings of our government. I dont think it is unreasonable for the 22 trillion dollar a year, 250 year old institution of the US government to solve the problem of why it is denying welfare to its own citizens. Or maybe the US government monopoly shoul…

>Or maybe the US government monopoly should be broken up into smaller governments

You mean state/local governments? Federalism? It's how the country started by as each decade passes we willingly cede more and more and more control to the horror of a central government our founders were set on avoiding. It's been nice to see some recent trends back towards states rights and downsizing the federal government - I hope for all of our sake the movement picks up steam.

Re: Librarian's Letter to Google Security

#423

Earlier quoted context omitted.

I'd like to see the Post Office (in the US) get involved. Post offices are geographically ubiquitous, already deal with identity verification, and already have to maintain the trustworthiness of their workforce. I'd like to see a system where (a) an account [whether GMail, Facebook, Schwab or Bob's Online Pet Food Mart] can be tied to a real-world identity and (b) when you lose access, you can go to the local post of…

Google already has the ability to generate one time use recovery codes, at least for gmail accounts -- not sure if it is generally integrated into their Authenticator app. You could generate some recovery codes and put them in a safe deposit box or something I guess. This sort of solution (and your post office idea) can be, but they don't satisfy the last resort customer service role, for people who haven't set these…

This is all well and good if you've got a smartphone with Google's authenticator or have a safe deposit box. The people using a library for Internet access don't necessarily have access to either of those things. They also may have had access at some point in the past but no longer do.

Re: Librarian's Letter to Google Security

#424
Great letter. Sorry about the unwanted publicity :/

Lots of people seem to want Google to be forced to provide customer service. It's an interesting idea, but I'd imagine it would be the end of free Gmail which may just force the very same people who can't afford permanent phones to switch to an even sketchier, unregulated free email service. Either that or the government would have to somehow provide free email, and I think there's actually a strong argument to be made there if an email address is required for welfare / parole / other government processes.

Re: Librarian's Letter to Google Security

#425
post #108

More than all the antitrust regulations being thrown at Google, I'd like to see regulators force Google to provide users customer support.

I don't. Customer support is a cost sink that usually isnt empowered to do anything. Its more PR tactic to make people feel they are "heard" without resorting to twitter. In the email/business apps space, google is clearly not a monopoly. Presence/quality of customer support seems a very reasonable grounds to have normal competition over.

Does it have to be a cost sink? Charge $20 every time you have to field a support call and you fund your call center while also killing the expected value of scammers trying to spoof their way in. And that’d be a pretty easy sell for a public assistance fund for situations like the librarian deals with.

Re: Librarian's Letter to Google Security

#426

Earlier quoted context omitted.

> trusted civic authorities They'll need to be resistant to threats and bribes, so it will be difficult to have these on-site at the library. I think we've overlooked an option. Note that the article's objection to FIDO keys was financial, not UX. This sort of confirms the hunch I got when first playing with them: "hey, the key metaphor is so strong and intuitive that these might be even better than passwords for peo…

How about: the library gets a few Yubikeys and offers to let people register their accounts with them as backup? So, if they get into trouble they can ask the library to unlock their account for them? This essentially grants the librarian what they think they should be able to do. But the next step would be to figure out how to reduce the risk that this system can be abused.

The libraries will just do this with their huge slush funds. They can put the YubiKey desk next to the ball pit back by the employee lounge.

Re: Librarian's Letter to Google Security

#427
post #352

Earlier quoted context omitted.

You nailed it. In the physical goods world, there is no company that is allowed to dump products onto market and pretend like their customers do not exist. If their product cause harm to the consumer, their products will get recalled or they'd get sued. Google has somehow allowed itself to infinitely scale their users but also infinitely shrink their liabilities/duty by binding all users to their ToS which foists arb…

If google's products cause harm, they also get recalled and/or google gets sued.

The librarian's letter that we're commenting on describes many concrete ways in which people are getting harmed and google getting away with doing nothing.

Re: Librarian's Letter to Google Security

#428

Earlier quoted context omitted.

Even at Google's scale, they cannot afford to provide high-touch tech support for 1.5 billion users. The fact Gmail is possible is partially due to their ability to scale low-touch tech support for free by supplementing the cost from other sources and, sometimes, just providing best-effort support. (Remember, the cost isn't "How do we field calls from a fraction of our 1.5 billion users," it's "How do we tell whether…

>Even at Google's scale, they cannot afford to provide high-touch tech support Yet somehow companies of similar scale like Amazon, Apple and Netflix manage to provide robust customer service.

Apple has a full order of magnitude fewer iPhone users than Gmail accounts. I'm pretty sure, unless I have misunderstood, that acquiring an iCloud email account requires ownership of a physical Apple device... If you're suggesting we should back-stop this problem of marginalized users losing access to Gmail by subsidizing the homeless or elderly to own iPhones, I don't think it will work.

Amazon is similarly an order of magnitude fewer users than Gmail accounts (and tends to address this issue by pushing the hard-to-address auth problems onto the seller... There are known exploits for just pushing exorbitant costs onto the seller via buyer fraud). Amazon has a couple hundred million customers... Gmail is in the billions.

I am, perhaps, just simply old enough to remember when not everyone could have a Gmail account. Low touch customer service that works 99 plus percent of the time was necessary to open the floodgates for free. I have never seen a practical explanation of how to scale providing the service otherwise. There's room for improvement, but (a) every simplification of authentication must be balanced against how it can be abused to steal accounts, and (b) I cannot conceive of a solution that would rival high touch customer service, and that scales to the billions. If one exists, I look forward to being extremely pleasantly surprised (having myself been on the receiving end of losing my phone while away from home for an important event: yes, it really sucks, Google's trust model is they trust you zero without some corroboration if all you show up with is the password). But I've watched them hammer at the problem long enough to suspect it's uncrackable at the billions-scale.

Re: Librarian's Letter to Google Security

#430

The author is 100% not wrong, but the problem is that, unfortunately, it is entirely possible that Google cannot have an authentication system that is correct for use by the elderly in a shared-machine environment while being correct for everyone else at the same time. There are options to fix this, but they're social, not technical. To get there, let's start with the technical side of why the author's proposed fix w…

Or perhaps someone can setup an email system primarily for the benefit of public library users. Run it as a non-profit / low-profit and provide basic support, do not require 2-factor authorization. Basically the way email was for many in the late 1990s, when they got email through their schools or universities, or perhaps through AOL or Compuserve.

> Basically the way email was for many in the late 1990s

Keeping in mind that the reason 2FA came along was that we learned the hard way that passwords are not sufficient to secure an account accessible on the public Internet. Too many effective side-channel attacks (both phishing the user and exploiting human psychological vulnerability, i.e. pulling passwords from another site and discovering that the same account and password works elsewhere).

... but such a system could allow for the account recovery solution to be "Go to the library and talk to a human being there, who can hit the account reset button." Libraries offer the advantage of having an already geographically-distributed-and-local staff by virtue of the non-digital service they provide.

Post reply on HN