Live data from Hacker News

Librarian's Letter to Google Security

docs.google.com

61–70 of 484 posts

Re: Librarian's Letter to Google Security

#61
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

> trusted civic authorities

They'll need to be resistant to threats and bribes, so it will be difficult to have these on-site at the library.

I think we've overlooked an option. Note that the article's objection to FIDO keys was financial, not UX. This sort of confirms the hunch I got when first playing with them: "hey, the key metaphor is so strong and intuitive that these might be even better than passwords for people with low tech literacy." I held off on saying anything until their compatibility actually lived up to the hype, which IIRC only happened in 2020 (all major browsers, all major platforms, by default), but it did happen.

As for the financial barrier, yeah, it's wild that these are still $30/ea on Amazon. Can they be bought cheap in bulk? Or does the market need some aggressive new entrants? In any case, they are "near practical" and the shove needed to make them "very practical" is probably 100x smaller than, say, creating a Central Bureau of A12N.

Re: Librarian's Letter to Google Security

#62
post #52

The best solution I can think of that doesn't compromise security is hardware keys. GMail has very good FIDO support. The keys are easier to use than TOTP and vastly more secure than SMS. They do not depend on any phone or phone service, and there is no transferring necessary at any time. The librarian would just need to get the person logged in successfully one time, get the key attached to the person's account, and…

The government should, *especially* if they are requiring mandatory access (though this should be illegal anyway).

But this isn't going to solve the issue of Google being too far gone (too big) to be worth saving : just shut them down.

Re: Librarian's Letter to Google Security

#63
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

In this situation, maybe one thing that could help is if the library holds on to the backup codes for patrons. So they can sort of act as a quasi trusted authority. In fact if these people can't even log in without backup codes, they can just keep their password in their wallet.

Of course, yubikeys also work very well in this situation. So the library could sell a yubikey and keep backup codes on file for in case the yubikey is lost.

Or since you can store so many identities on an individual yubikey, just give the librarians one.

Re: Librarian's Letter to Google Security

#64
post #18
post #8

About a decade ago, a broken iPhone caused me to experience how bad Google's MFA reset process was — there were multiple _years_ where the “hard landing” form triggered a flow which sent an email to an internal mailbox which didn't exist! — and while I was able to use printed backup codes after I returned home the experience left me concerned enough that I went to one of their identity group's public meetings here in…

I agree with your suggestion. I think Post Offices, DMVs, and large reputable retailers (Walmart, Target, Cellular Phone companies, etc.) could verify our identities for a small fee and help us reset our social accounts when needed. I arrived at the same conclusion and wrote a blog post about it a few years ago: https://www.go350.com/posts/now-they-have-2fa-problems/

Aren't half of those things you listed (Walmart, Target, Cellular Phone companies, etc.) also exactly how people get unauthorized access?

You convince the employee to port "your" number and they do so and then you reset that accounts password?

https://www.wptv.com/money/consumer/phone-porting-leads-to-s...

Re: Librarian's Letter to Google Security

#65
It does seem like the library's (and really, anyone who helps the aged with their accounts) first order of business for those that have access to their email should be to get them setup with a secondary account at a different service.

I'm aware of a number of problems though - this is a lot of cognitive load to add to someone who just barely understands how to get to the mail in the first place. And obviously it doesn't help someone who is already locked out and seeking assistance getting back in. It opens another (likely less secure intentionally) way of phishing the seniors. And there is not really a good way to transfer all of your email history from one account to another that I'm aware of.

So while I believe the best "market solution" would be for folks to use some sort of alternative, I'm not sure it's a realistic ask. So Google needs to take this seriously and realize how devastating this can be. It's not "just a free email address" to many people, it's their lifeline to everything.

Heck, even myself as a tech savvy person worries about getting locked out of my Google account given I use an Android phone and have 2FA setup through that device for a large number of services, including my password manager. Note to self, get on that physical version of the digital black book that provides physical copies of anything needed to get back into accounts (2FA codes, backup codes, etc.)

Re: Librarian's Letter to Google Security

#68
Gmail is locked up tight. I like it that way. People who need _really_ security like it that way. I'm confident that I will not lose my email account to a social engineering scam. It's much safer than my phone number.

Not everybody needs this level of security. In fact, as the article and most responses demonstrate, the high security is not desirable for a large number of people.

Honestly, this sounds like the space for some kind of "non-profit startup" -- email services for the at-risk population. Of course part of the solution is non-tech, but there needs to be some real service involved. Interesting.

Re: Librarian's Letter to Google Security

#69
post #52

The best solution I can think of that doesn't compromise security is hardware keys. GMail has very good FIDO support. The keys are easier to use than TOTP and vastly more secure than SMS. They do not depend on any phone or phone service, and there is no transferring necessary at any time. The librarian would just need to get the person logged in successfully one time, get the key attached to the person's account, and…

Reading this comment, I thought Yubikeys, which aren't /expensive/, but aren't cheap either. I was pleased to see they have a key targeted at this specific use case now - the Security Key Series [0]. At $25, that is not too bad a price, and something I'd buy for the members of my family without much hesitation.

The hangup with this, which I think the librarian in question will feel, is what happens when someone loses their key? How can I set up a trust relationship that my local librarian can reset my grandma's Yubikey, but a bad actor can't? And, $25 isn't so bad once, but if we have to replace it every month, that's less fun. Maybe that's just agreeing with you and lamenting the state of things, but maybe someone will read this and think $25 isn't so bad and write a grant to pilot this program.

0. https://www.yubico.com/store/#for-individuals

Re: Librarian's Letter to Google Security

#70

So, what should Google do, here?

Well for a start, not set you into a loop telling you to use your phone to log-in if you've lost your phone.

I mean, even a paid-for, ad hoc ticketing system (e.g. if you need a reset on your account, pay $10 and create a ticket; no need to have an enterprise subscription in advance) would be better than what we have currently.

But financial institutions solve for this all the time when people forget their online banking details or their phone breaks for 2FA. It probably costs them a far amount in customer services support, but they suck it up as the cost of doing business (probably because they legally have to). Whereas Google just foregoes it entirely.

Post reply on HN