Librarian's Letter to Google Security
docs.google.com
docs.google.com
Librarians rock. There's even a show about them[0], Starring Number One.
I can't access the gMail account I set up, because I made a mistake, when setting the password, and did not save the one I used.
It will not allow me to access the account I set up.
After a while, I just gave up. I am satisfied that someone can't use my gMail address to impersonate me (because even I can't get it). I have plenty of other eMail accounts.
I just tweeted it to @Google. Maybe if enough people ping Google about it?
Google does not care. You cannot make Google care. Employees who care get fired, or burn out trying to make the company care, and inevitably quit. Google is Google, and the only thing that's going to make it change is regulation.
Almost every problem out there at some level is an info prop problem, and in cases where it isn't the signal getting lost, it's the remediatory activity being judged as too expensive, and thereby getting the process routed to /dev/null
Google has designed itself to be psychopathic from a human frame of reference because it is more streamlined (profitable) to be psychopathic. It is a product of its environment.
Well, looking at the date...
> "Today, July 19th 2021"
That's a feature, not a bug.
The issue was that I used a randomly-generated password from 1Password, and accidentally re-generated, before copying, so the original was lost.
That's a fairly common mistake. I'm usually careful to avoid that (now).
It does not offer to automatically create an entry, until after the login, so it's still quite possible to "fall through the cracks," which is what happened here.
Yeah, my bad. :P
OG Mystique as well. Rebecca Romijn has done some great roles.
""" STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS
This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longer are having this issue as often as before due to various improvements.
Please delete this from HN. You are essentially DDOS’ing my work email and the library branch phone number making it very difficult for us to perform our duties as civil servants today.
I do not know how this made it onto HN. Someone must have leaked it. If they need to work that out internally then I’m leaving this here for their reference. But I do not want news reporters or random HN readers contacting me or the Free Library over this. """
Seems like it was not ignored and was already resolved.
Doesn't sound like it was completely resolved. In fact, it sounds like Google may have treated it as a "squeaky wheel," and only that library is getting better help.
In any case, I think that HN (@dang) should honor her request; regardless of its resolution.
I would suggest that the letter is great, and should be made more available, sans the identifying information.
I'd suggest someone try and get her permission to host an anonymized version of the page, on a different server that could handle the lurve.
One of the things which I was struck by was how unseriously they appeared to view their role in modern life. People were generally very casual about the need and were especially uninterested in anything which required them to work with outside parties.
My suggestion was that they consider a protocol where trusted civic authorities could be allowed to confirm someone's identity, which sounds like it would be useful for this case: let the person initiate a mediated reset flow where someone like a librarian, police officer, etc. could authenticate in their official capacity and check a box saying that they've confirmed the photo ID for the person standing in front of them. Most of the benefits from MFA are preventing things like phishing attacks which are also stymied by limiting it to people in your geographic area, although you might want to disable this for high-risk people enrolled in Google's Advanced Protection Program.
You convince the employee to port "your" number and they do so and then you reset that accounts password?
https://www.wptv.com/money/consumer/phone-porting-leads-to-s...
HN demanded for such security holes to be disabled and prevented - what changed since then?
If the worst thing that people could commit in this discussion is hypocrisy, I'm sure they're willing to step over that line.
For me, the larger threat is that someone impersonates me and takes everything I have. If I lost my email, it would be a nightmare but I could work around significant portions of the system. For my cousin, the larger threat is losing her email, as she has no significant assets to steal but could run into every problem in the email.
There are likely people in the middle as well, and other threat vectors. (For example: caregivers committing fraud, dementia, state actors, and 20 other we could brainstorm pretty quickly.) Perhaps the right answer is that we need 20 different services that can segment. Perhaps the problem is that some sectors aren't profitable: maybe we need a grant for emails for poor people with a circle of trust.
I don't have answers. Maybe we need a collection of people to think deeply about this problem.
As for post offices, they aren't eligible because half the government is actively trying to kill them.
It's a lot easier to implement reliably due to the requirement for everyone to have ID cards though (and the ID cards carry your residence address).
by that logic, slip some policeman a $50 and they might plant drugs on your enemy or shoot him because he had a wallet that looked like a gun.
Have employees of private conoaniea never been involved in fraud?
I still love libraries and the services they provide. But wouldn't want them to be an arbiter of identity any more than a faceless, human hostile corporation.
To be fair, tons of places use those as proof of residence. It’s not as if it makes a real difference if you print them first.
I mean, I just got my `REAL ID` from California, and they accepted printed utility bills as proof of address for me. I could have easily modified the name and/or address on them before printing.
The other proof of identity I used was my birth certificate... that I was able to just order online with the only information required from me was my social security number and answering a few questions that would not be that hard to find out about someone.
Proving identity in a way that works for everyone while not allowing anyone to fake it is practically impossible.
I also doubt this will ever happen since it would require more $$$ for things that are not profit generating and supports a population that is useless from the tech companies' POV.
Or for identity theft.
Could the library buy a few FIDO tokens, hot glue them into the backs of the computers, users add them as 2fa to their accounts and now the computer being wiped between users is no longer an obstacle?
- Users would only be able to use the exact same computer each time. If it’s out of order, too bad
- Users wouldn’t have unique tokens between each other, so there’s a risk of other library patrons shoulder surfing and then logging in with the same token after you
Identity is too critical a business for services companies like Google to walk away from. It’s stupid, because once the camel gets it’s nose in the tent, it will cost them more.
They'll need to be resistant to threats and bribes, so it will be difficult to have these on-site at the library.
I think we've overlooked an option. Note that the article's objection to FIDO keys was financial, not UX. This sort of confirms the hunch I got when first playing with them: "hey, the key metaphor is so strong and intuitive that these might be even better than passwords for people with low tech literacy." I held off on saying anything until their compatibility actually lived up to the hype, which IIRC only happened in 2020 (all major browsers, all major platforms, by default), but it did happen.
As for the financial barrier, yeah, it's wild that these are still $30/ea on Amazon. Can they be bought cheap in bulk? Or does the market need some aggressive new entrants? In any case, they are "near practical" and the shove needed to make them "very practical" is probably 100x smaller than, say, creating a Central Bureau of A12N.
https://news.ycombinator.com/item?id=15864579
I am a happy Fastmail customer, in a large part due to trust inspired by Bron’s comments.
This essentially grants the librarian what they think they should be able to do.
But the next step would be to figure out how to reduce the risk that this system can be abused.
> They'll need to be resistant to threats and bribes, so it will be difficult to have these on-site at the library.
That's why I mentioned things like APP: some people do have a threat model where that's realistic but it's a much smaller number than the people who are inconvenienced by being locked out so it seems like it'd be a net-win for most people to be able to get unlocked easily. There are also ways to mitigate some of that risk like having notifications for all actions with an easy way to report unapproved requests, geographic restrictions, enforced MFA for the civil servant (“tap your FIDO token to approve this request”), rate-limiting, etc. which are all bread-and-butter tasks for one of the major tech companies.
The other thing I think is relevant here is the degree to which things fall back on civic authorities anyway — e.g. Facebook's process where they require scans of your government ID or the various ways you can report a deceased relative. It seems to me like it'd be better to embrace that and work better together rather than pretending there isn't already a fairly large trust relationship.
Of course, yubikeys also work very well in this situation. So the library could sell a yubikey and keep backup codes on file for in case the yubikey is lost.
Or since you can store so many identities on an individual yubikey, just give the librarians one.
- Library is a Group Administrator for patrons' Google accounts.
- Library offers its own email services to patrons.
- Library holds recovery codes (perferably under some sort of escrow).
All of these put burden on the library, of course. Though there's already a substantial burden.
There's also the issue of itenerant / mobile patrons who may only be using a library on a temporary basis or operate between several locations. How much this is a use pattern I've no idea.
The USPS offering email services might be yet another option. Points of presence in every ZIP code, often several.
Given other ongoing challenges (housing is now a full-blown crisis), the problem of mobile / indigent / precarious indivudal will only grow.
The pattern is also likely to be repeated in other global regions.
Regulation solves this. I hate to say that, as so much of tech regulation is a ham-fisted disaster that misunderstands the problem and creates even bigger ones, but this is really a very serious problem that can ruin lives, and regulators really should step in here.
I’ve known a couple of people who have been through this experience, and one in particular who not only couldn’t get back in to their account - but had no way of knowing if someone else was able to get in to the account later. They’ll never know. It will never be possible to know. The kicker is that they could never have their data deleted due to the same problem. And no amount of help or time spent with chat support ever changed anything.
And there could be an agency similar to CFPB where citizens could appeal who would then make formal investigations.
So regulation would force the workflow described in the article to not have a grim outcome for elderly users of gmail.
I suppose they could be subsidized by the state for low income people.
I don’t know Google well enough to know what they would need to do to offer non-shitty service. Maybe they show more ads.
I also think they could automate good service if they wanted to, but it’s not a priority and they aren’t required. I used financial services before and after CFPB and I don’t remember price increases on my bank accounts. So perhaps something similar would apply here.
But let's put aside the efficacy of said institution, and presume it's working very well. They got call from some Joe. He claims that certain email address belongs to him, but can't prove it. Forgot password, no access to phone. What this customer service of yours going to do? Let's imagine they can order Google to give the guy access to account. Is that a right thing to do? What if that email belongs to a journalist or a whistleblower and you just gave access to it to a Russian intelligence? Remember, benefits are one thing, but it's not the only thing for which email is used.
And if it really comes down to this, why is Google under obligation to provide emails for government use? Government can provide email access to everyone who needs it. If they require email in order to access benefits, well go ahead and set up necessary infrastructure. Why Google had to do it? Google provides service on as-is basis. If that service level is unacceptable for government use, well newsflash: it's not the only provider.
If you have an Android phone, your e-mail is on Gmail. It doesn't need to be, but it is, because you didn't know that when you were funnelled into the e-mail when you set up the account and oops now that you're locked out ten years later it's too late to make a choice.
Remember scale when thinking of potential solutions here! it’s not just the US that would be affected by this as well. The reality is that google does a better job at identity any than US government institution (ssn, drivers license). How many people have their identity stolen versus having their 2fa protected gmail account stolen?
As far as support, how would it be better if support gave you access to an email account if you complained enough? please consider the abuse side before you suggest a solution.
Backup codes wouldn’t help here, and the person I was referring to had their 2FA to hand.
Forgetting a password is unrecoverable on gmail - they even had recovery options on the account (secondary email and phone), but the recovery form never asked for that information so it could never be used (it insisted on the previous password). As no member of staff has access to prompt the system to offer a different one of the specified recovery options, the account is permanently frozen to this user (but not potentially to an attacker in the future, assuming that other information could be obtained somehow).
Helping the elderly is hard, but Google’s system is horrifically dangerous to people in ways even Google aren’t aware of.
This was an elderly gentleman, not well versed in computers, but all the savviness in the world couldn’t have helped him. He was forced to just walk away and hope for the best. Holiday snaps, photos of grandkids, personal files - all permanently retained by Google but locked out of his reach forever.
Today it requires almost always a Android/iOS phone AFAIK, but it could easily be massaged to solve this problem.
The system is set up so that your account is owned by the state, and you can register with documents to providers; then after certification they run the actual SSO process.
A library provider could set up a computer that automatically passes the SSO login for your national account after certificating your identity.
Honestly this feels a bit too open to social engineering attacks, but probably there is a good middle ground.
Edit: Maybe in the US this is already almost possible by extending something like https://en.m.wikipedia.org/wiki/FIPS_201
This is already a solved problem, and without getting the government involved.
There are plenty of identification confirmation companies out there. If you've ever requested your credit report, or applied for a new apartment online, you've probably interacted with one.
Oh, but that's an expense. It might costs pennies per user! Google doesn't do expenses. It would rather spend money on rooms full of toys and gourmet catering than on helping people use its own products.
This thread, in general, is a great example of engineer hubris. It looks at a complicated problem, and all the top discussion sub-threads are highly up-voted non-solutions to it.
But SPAM should be resolved with strict adherence to standards like SPF, DKIM, etc. and where those fail it should be improved
Today many companies, large and small, as well as government agencies, large and small do SPF and DKIM very very very wrong.
Unless we can get this right I fail to see how regulations would do anything other than make things worse
Some of the biggest SPAM abusers are not the small providers but the Large companies like Gmail and Microsoft who do not vet their customers very well
It could be any email service that allows the librarian-administer to reset the password for an account. If I mess up my exchange email, the helpdesk can verify my identity and reset my password.
I suspect that most going down this approach would find it easier to use a large hosting service that they provision and administer (along with allowing password resets) than to try to have an underfunded library IT staff stand up an arbitrarily large email service and manage all parts of it.
"Many government welfare forms, housing applications, and jobs applications these days require the use of the internet exclusively with no option to fill things out in person."
Why is this? Really, this does not seem like a problem Google caused, but rather a problem caused by the government when they made it mandatory to have internet access to get the benefits they should get. Would they have made it mandatory to call them on the phone, back when phone access was not yet universal? If they had, would AT&T have been at fault?
The government caused this problem.
I'm all in favor of finding a non-government solution (charity sponsored by HN people to get people Yubikey or equivalent, maybe). But this is not really a problem caused by Google, and if these people were having their benefits scammed away from them because their email accounts were hacked, people would be excoriating them for not instituting 2FA.
> Even when we clicked “I don’t have my phone” it asked her to open the Google app from the phone that she does not have.
That's a google problem.
Google fixing their problem would lessen the impact of the government problem. (And, more generally, make gmail a better service for lots of people.)
I don't know what the right answer is, but that certainly isn't it.
This seemed pretty effective to me.
If you want to enable 2FA, Do one of the following - upload the front and back of your ID - UBI Key or other hardware Cert, - etc. etc.
2FA by phone is a flawed architecture due to being subject to change. Sim-swaps are a known vulnerability.
But mainly, do not force me to have 2FA.
For most people, that's too hard. The elderly, marginally educated people being served by the library or in other contexts just don't understand how things work to the degree that they might appreciate backup codes or their importance. They just don't get it. Backup codes are like this noise in the way of account signup.
Ever tried to get friends and family to start using PGP? A password manager?
The technical solutions that are practical already exist, as you've pointed out; and the technical solutions that seem like they're lacking (enrolling a new device without MFA-ing in) are lacking for a reason--they're security holes. You can't say "this email account is super important and access to it unlocks important things in someone's life" and also "account recovery must be as easy as claiming you lost your phone, and you don't have to know any pre-shared or pre-generated secret".
I also don't know what the solution is. Trusted intermediaries (librarians? social workers? police? social security office people?) introduce all kinds of other attack vectors. Elsewhere folks are pointing out that the mistake was probably to rely on email for all of this super important messaging and your account recovery workflow for every system other than email, but that's a society-wide problem that you probably couldn't have controlled in the first place and definitely can't now.
The best you can probably do is aggressively prompt people to prepare for account recovery prospectively, maybe by identifying a trusted intermediary and/or verifying that they have backup codes.
Many government offices have temporarily(?) gone online-only for covid.
All _government _forms have paper-equivalents for accessibility reasons, and OMB numbers that coincide.
The Paperwork reduction act is a thing, but it also stipulates that within reason, paper forms must be available.
The problem is 2FA. 2FA causes people to get locked out of their accounts. Google mail requires 2FA, the government does not. If Google turns off 2FA requirement, the problem in the letter goes away. But they won't.
Google is the cause of the problem, and can easily solve it.
The IRS recently had a problem with people using their online access tools to get other people's refund. Insufficient security on authentication can easily be as bad or worse than 2FA.
Is that actually true? I’ve never seen a single site that didn’t allow me to log in with a ‘regular’ email address, even if they pushed Log in with Google first
It isn't just government forms, it is also private companies, employers, landlords, and even out-of-touch charities that are run by people who are used to having 24/7 access to reliable internet.
We probably need some sort of state-sponsored digital inbox for these kinds of documents. The thing that makes Google useful -- that it is a "reasonably" secure location to stash documents -- also makes it really easy to get locked out. There are recovery options, but it isn't obvious how a system could be secure while still allowing recovery for a user who elects to not set any recovery options up.
Perhaps the government could do a better job (at least they have things like social security cards and birth certificates, and have been dealing with the last resort case where these aren't available for longer than any of us have been alive). They also aren't constrained by things like a need to make a profit, and they don't even really need us to be able to communicate out from this inbox, it could be just a one-way channel for the reception of documents, which would avoid some annoying issues ala people using their gmails to harass others.
The HN community caused this problem. I precisely remember about 10 years ago on HN I'd see obnoxious articles with thousands of upvotes hyping crap like "we disrupted the goverment" and "we saved a lot of paper by providing a webshit interface to government institutes" and "we replaced non-working COBOL crap with new JS crap it's so much better". And of course they followed suit with "security best practices" such as having a hidden security policy (that an attacker can easily find out) and "advanced risk model", which is something 99% of websites get wrong despite that they all regurgitate the standard "we have a complex risk model, you do not know what you're talking about". What we have now is absolutely, literally what my expected outcome was for this movement, at the time, 10 years ago.
It's well overdue time they realised that if you want to be the sole way people communicate with each other, pay their bills, communicate with the government, and hold cherished memories, that they have a strong responsibility to provide a very strong level of support to prevent people from losing their entire online identity - and thus their entire offline identity as well.
I think that Silicon Valley talks big on social issues precisely because they know they walk in the wrong direction.
What really bugs me is that the employees of the Google seem to have their own political agenda, but none of that includes the people the company is actually ill serving. I guess that's just not cool or edgy. Its the company they work for that has become a tyrant.
It is a federal program that provides up to $30/month, paid directly to your ISP so that they can take that amount off your bill. I work for an ISP[1] that offers a $30/month, 200Mbps plan which is free when using ACP (we don't even take your credit card). Most ISPs now have an ACP section of their web site if you search for it.
Having worked extensively on implementing this program at my company, I have seen exactly what this librarian is talking about. The people who need programs like ACP are also disproportionately people who have low tech literacy, and often poor literacy/education in general, and the existing systems don't work for them. I wrote about that recently in another thread[2].
When a customer is locked out of their ACP account, luckily the ACP support line is able to reset their password over the phone. But it's not always an easy process. Often, we need to have multiple, in-person meetings with these customers in order to get pictures of their ID, and often ACP will not do anything to an account unless the customer is physically on the phone or in person with us asking them to.
If our customers could always get access to their Gmail, it wouldn't be nearly as big of an issue. They could reset their password the way you'd expect. But as the article is pointing out, if you're locked out of your Gmail there is absolutely no way in.
It's really striking just how much work it is to be poor. Google needs to fix this, and remove one more barrier to people who need to use email with government services.
The security wisdom I've always seen was to use 2FA and prevent other attempts at authentication, but if Google is evil for doing this security... what's the answer?
Anyway, I think the the common case is that most data is recoverable with an ID or whatever they require. FWIW, searching HN for: “locked out of icloud” doesn’t produce much.
They were accustomed to lightning fast internet on Macbooks and constant technological churn. Unfortunately for these exceptional people, poverty is logic resistant and nearly impossible to understand second-hand.
The tech scene's obsession with meritocracy is an extension of this.
I think this is giving too big of a pass to wealthy people. If wealthy people put in the effort, it isn't hard to understand the struggles that living in poverty bring. I think a better way of putting it is "It is very easy for those that have never lived in poverty to not consider the struggles that it brings". There is no difficulty in understanding, it is just easier to not every try to understand, so many wealthy people don't. It is a choice, though.
> losing their welfare benefits, their housing, and struggle to find work.
because of technical decisions centered on security.
I'm not sure what would be the best way forward, for the moment I'm in the "less tech is the best" camp, especially when it comes to interactions between citizens and the State, probably that tendency will only grow.
More like “incompetent, self-proclaimed security experts.” The three pillars of security are availability, integrity and confidentiality. Google’s auth flow aggressively face plants on the first requirement.
The librarian would just need to get the person logged in successfully one time, get the key attached to the person's account, and get the key onto the person's physical keychain. The librarian would also print out the backup codes, laminate them, and put them in the person's wallet. Once that's done, this particular library patron should have few authentication issues going forward. Assuming lots of repeat clientele, the auth night mare will largely end once everyone is setup.
Yeah, the key and codes might get lost, broken, or stolen, but that's the best you can do. If the person lost their actual keys and wallet, they've got bigger problems.
The question really is who is going to pay for these keys? They're a lot cheaper than phones at least, but not cheap enough.
But this isn't going to solve the issue of Google being too far gone (too big) to be worth saving : just shut them down.
The hangup with this, which I think the librarian in question will feel, is what happens when someone loses their key? How can I set up a trust relationship that my local librarian can reset my grandma's Yubikey, but a bad actor can't? And, $25 isn't so bad once, but if we have to replace it every month, that's less fun. Maybe that's just agreeing with you and lamenting the state of things, but maybe someone will read this and think $25 isn't so bad and write a grant to pilot this program.
This compromises security somewhat, since the library houses one of the second factors, but IMO it's preferable to total account lockout (and still superior to SMS verification).
Sure, having a physical key makes it easy for a non-technical librarian to steal someone’s identity, but perhaps having some kind of yubikey safe deposit box would be an appropriate compromise.
This has not been my experience, even for more knowledgeable people let alone normal users.
>> this particular library patron should have few authentication issues going forward
Until they lose or break the physical key, which will happen more often than losing or breaking their phone with the TOTP
Some of the problem remains: If the user forgets their password the second factor won’t help them, and that includes the backup keys.
I’ve read the letter, and I see the massive problem, but I don’t think it’s been fully solved yet.
Q: “How do we remotely authenticate a single user, in a way that cannot be forged, without relying on their memory?”
There are solutions to every part of that sentence, but I do not know of one that solves it entirely.
They could write their password down, but then they’re exposing themselves to the obvious risk of it being stolen. You could trust the librarian in a 2-of-3 system, but this seems very easy to abuse by the library staff.
Genuinely not sure of how this is solved.
A cryptographically-strong biometric key store at the library (e.g. finger-print or face scanner) that will only authenticate a physically present user and release a FIDO signature that could then be used in a multisig authentication?
I think biometrics sounds like the best solution. YubiKeys will get lost/damaged/stolen and then you're back to square one. With biometrics you shift the burden of paying for and managing hardware onto the library and individual users don't need to be responsible for anything.
Of course this doesn't solve the issue of the user who is already locked out, but librarians could at least proactively enroll users who have access to their account in order to prevent the issue from happening in the future.
Do they? Typically for those sorts of things you have recovery options. Your landlord will be able to get you a new key, your bank can issue you a new card.
Looking through my wallet, the only thing that would have a significant hurdle to replacing it is my Egyptian residence permit (I'd have to travel to Egypt to re-issue it). The only significant "loss" would be my current monthly public transport ticket, but if I can produce some kind of payment proof and am willing to argue with metro staff I might even be able to get that replaced.
Point being, there is a lot of recourse for offline things, but if you get into this situation with a tech company - there is none. I have a lost 10+ year old Gmail account and I could not regain access to it through any means even while working as an SRE at Google.
Maybe don't carry that in your wallet if you don't need it where you are and it's so hard to replace. :)
It's one of those things you just kinda forget about when you don't need them for a while ...
> STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS
> This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longer are having this issue as often as before due to various improvements.
> Please delete this from HN. You are essentially DDOS’ing my work email and the library branch phone number making it very difficult for us to perform our duties as civil servants today.
> I do not know how this made it onto HN. Someone must have leaked it. If they need to work that out internally then I’m leaving this here for their reference. But I do not want news reporters or random HN readers contacting me or the Free Library over this.
When Uber and Lyft became popular and you still needed a smartphone and mobile connection to use it, it basically became a way to keep poor people segregated in transportation. If you couldn't afford a smartphone, or a data plan, or only sporadically, you were relegated to the public transportation options which are slowly defunded as Lyft and Uber lobby governments to become the "more affordable" alternative to public transit. As a result, 'hacks' (illegal taxis) are widely used in many cities because you don't need a smartphone or data plan and they are cheaper, yet are more dangerous.
Mega-corporations that design for "the 80% of users" implicitly make life harder for vulnerable and poor people. It's time for us to not only hold Government accountable to treat people well, we have to hold Corporations accountable to the same standards (at minimum).
(as an aside: I love the Free Library of Philadelphia. they get out in the city and meet all kinds of people, help them get access, always generous with their time and friendly. they are a vital service to the community and I hope Google listens to them)
I emailed lyft support asking why this was. Never got a response.
It doesn't seem to have occurred to a bunch of silicon valley techbros that lots of people only have one credit card, or only one card they're comfortable using (using a debit card for credit card transactions is a huge risk due to more direct access to money and lower fraud protections.)
Uber and Lyft were a massive, widely praised improvement specifically for poor people because for the first time ever, poor people got access to a taxi service that was not bigoted against them. Before Uber, bigoted taxi drivers routinely refused to pick up passengers with the wrong skin color and refused to drive to poor, outlying neighborhoods. Uber and Lyft did away with that nonsense. Doesn't matter what you look like or what you are wearing or where you live, if you can get a phone, you get a ride.
I'd like to see another letter drafted to other librarians recommending specific competing email providers that people who are MFA-challenged should use for anything important.
STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS
This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longer are having this issue as often as before due to various improvements.
Please delete this from HN. You are essentially DDOS’ing my work email and the library branch phone number making it very difficult for us to perform our duties as civil servants today.
I do not know how this made it onto HN. Someone must have leaked it. If they need to work that out internally then I’m leaving this here for their reference. But I do not want news reporters or random HN readers contacting me or the Free Library over this.
If you want to learn more about patron privacy and support librarians advocating for patron privacy and against big tech please check out https://libraryfreedom.org/ which is a wonderful organization I am a part of that does work like this. I still firmly believe in and stand by everything that I wrote. But this particular action was not meant to be a public letter and it’s interfering with my ability to do other work. You’re welcome to read this, now redacted, letter, just please stop emailing me and sharing it around.On the other hand, you have the perspective of computer repair people who routinely field calls and service computers due to the elderly (mostly, but also everyone, including tech literate folks) getting scammed, account takeovers, downloading malware, and worse!
So maybe the solution here is not to *force everyone and their literal grandma* to be using these machines for all of their business??
Why not allow the owner of a Google account to delegate a trusted third party who can handle MFA/otherwise approve logins on their behalf. I kind of do this already by setting the recovery emails for family members (especially aged parents) Google accounts to those that I control, but to my knowledge it is not possible to do the same for the mobile number used to secure the account.
This way, at least as I imagine the authors scenario, the library's regulars could delegate them as the trusted third party, problem solved.
Oh yes, and also what they write -- add an on/off setting for "Be less anal about logins from unrecognized devices".
You could add a feature like this, and maybe it helps one out of every hundred people who try to log in at this library, and that's optimistic at best.
Fair enough. I live in the EU, we all have state-issued ID cards and no cultural problem with using them, so presenting those via some channel to Google would work here, but I can't imagine it working in the states.
This is an open question. We are not there yet, but at the same time I don't think it's tenable in the long term to be in the state of assuming the user can't be trusted to know what 2FA is.
So the answer is, unfortunately, never. There will always be people who are not computer literate, and if we want basic services to be available via the Internet, as many government services now are, we have to include systems that include these people.
You can't just discard the poor because they aren't computer literate.
The term of computer illiteracy is useful in more than one way, and that is literacy. We don't structure our societies (including basic government services) around people who cannot read, instead, we we structure them around the understanding that the average citizen can read, and treat regular illiteracy as a problem to be solved, and in the first world where computer literacy is even a problem that can exist, it mostly has.
What I need is a way to get into my personal accounts when I find myself naked and alone on the street (don’t judge, you don’t know how I got there). And the only way to do that is to be able to physically present myself at some place and have them verify my identity, allowing me access to my digital life again – and hopefully let me to call my wife to being me some clothes.
Basic identity verification is the type of function that everyone will need at some point as a common public service. The kind I would expect a government to provide.
Also, it's considered sufficient for all those non-google tech services to just use your email address to get you back into their system. Netflix can send you an email. Facebook can send you an email. Twitter can send you an email. Netflix can send one, too. Gmail can't send you an email to authenticate you. You can never use email to get access to email. Using a Gmail account to try to unlock a Gmail account is an absurdity, like Baron Munchausen pulling himself out of a swamp by his own hair. You can use a cell phone to unlock email, but cell phone service will always cost money, and phones can be lost, broken, stolen, or sold for emergency funds. No library anywhere provides access to phones that make texts, and even if they did it wouldn't work because they'd be shared by people which would make them unsuitable for identification.
That's the reason for the focus. Fixing Gmail sort of "does the heavy lifting" for all the other services that need to get you to prove that you're you.
Replace 'government should provide a digital identity service' with 'government should provide an email service', and we're back at the same place. You still needs a way to prove that you are you - with legal protection and recourse.
This letter points out the increasingly obvious - that our online identities have become too important to be left to the customer support whims of one or two corporations. The idea that an innocent algorithmic mistake in a microservice running somewhere deep in Google's cloud could lock me out of my life is not the future we want.
You actually have something that you can use- your reputation. It is difficult to fake your likeness, even moreso to people who actually know you. A combination of past preshared secrets (memories) alongside your likeness is enough to get people who DO have ID to vouch for your identity- family, your landlord, your neighbor, your lawyer, your employer, past schoolteacher, anyone who can reasonably be expected to recognize you and have had some experiences with you, can discern whether or not you are who you say you are.
From there you could have access to your theoretical USPS or Library email, add an additional PGP key to publicly-funded keyservers, and generally use the power of this vouch to escalate from there.
Even if you make an extreme edge-case argument, saying that someone has some extreme amnesia and finds themselves far away from their home, the government could just let you generate a completely new identity for a small fee, so that you aren't left high and dry without one.
Not everybody needs this level of security. In fact, as the article and most responses demonstrate, the high security is not desirable for a large number of people.
Honestly, this sounds like the space for some kind of "non-profit startup" -- email services for the at-risk population. Of course part of the solution is non-tech, but there needs to be some real service involved. Interesting.
But they are in the business of selling ads, and they are not selling enough ads to people who both a) cannot continuously afford a phone number b) are unable to afford an internet connection at home to be worth dealing with the complaints, manual verification and prevent fraud.
Google is in the business of making money. You make very little money from poor people, and you lose money if they cost even more to service.
This does not mean that it doesn't suck for the homeless lady, but this is reality.
1. Overcoming business incentivisation requires some external influence.
2. Individual action alone won't accomplish this.
3. We're part of that larger conversation.
Writing Google first shows a good-faith effort. Google's failed to respond to that. HN is upping the ante. Regulatory action is another level.
These are not exclusive or independent actions.
The Googles of the world exist because they provide inexpensive services through automation and at scale. They are poorly positioned to provide services that cannot be automated at scale. Chances are that any attempt to do so would likely bankrupt them even though we are talking about extremely wealthy corporations. (Keep in mind that we only hear of a fraction of the complaints about Google. Few people have the reach or ability to have their voices heard.)
On the other hand, libraries are already embedded in the community. They already have personnel who can better understand and respond to situations that Google would regard as edge cases. They are also much smaller organizations that have less bureaucracy to deal with and a mission that aligns with the needs of the community.
I am not saying that they have to provide the actual email servers. They could contract that out, perhaps even to Google (though I suspect they would try to find another organization). They would be managing the email accounts themselves, including authentication and recovery.
https://webapps.stackexchange.com/questions/127464/enabling-...
It looks like it is a pain in the neck, but also possible to use it as the main second factor, for people without phones.
This reminds me, I need to move 100% off google’s ecosystem.
Also, accounts without MFA were also also causing harm. Some vulnerable populations also didn't realize how easily a non-MFA'ed account could be taken over remotely due to a weak password. And then due to "password reset" functionality, a Gmail account takeover can pivot to cause greater harm.
This is a classically difficult problem: improving security often reduces convenience. The trade-off Google chose to mandate for all users was not the best for users without stable phone access.
I think the real issue is outside of Google's reach. You shouldn't have to lose the roof over your head just because you don't have access to your emails. Sure, it sucks that Google doesn't care if these people lose their access to Gmail. But I don't see how Google has a greater responsibility than the state/government in this.
But is your position really that losing access to your email isn't a big deal with real-world consequences? Forget government services, nearly everything you do online requires access to an email address.
I dont think it is unreasonable for the 22 trillion dollar a year, 250 year old institution of the US government to solve the problem of why it is denying welfare to its own citizens.
Or maybe the US government monopoly should be broken up into smaller governments to foster a spirit of competition in the marketplace if it can't meet the needs of its customers.
You mean state/local governments? Federalism? It's how the country started by as each decade passes we willingly cede more and more and more control to the horror of a central government our founders were set on avoiding. It's been nice to see some recent trends back towards states rights and downsizing the federal government - I hope for all of our sake the movement picks up steam.
Can anyone suggest what a good alternative to Gmail would be for this population?
I would hope that libraries would have fixed IP addresses, so surely that could be factored into the authentication process? Some FIDO keys used to be able to be bought for as little as $5 (https://wiert.me/category/power-user/security/u2f-fido-secur...) so it shouldn't be beyond the budget of any self-respecting town/county/state?
I'm aware of a number of problems though - this is a lot of cognitive load to add to someone who just barely understands how to get to the mail in the first place. And obviously it doesn't help someone who is already locked out and seeking assistance getting back in. It opens another (likely less secure intentionally) way of phishing the seniors. And there is not really a good way to transfer all of your email history from one account to another that I'm aware of.
So while I believe the best "market solution" would be for folks to use some sort of alternative, I'm not sure it's a realistic ask. So Google needs to take this seriously and realize how devastating this can be. It's not "just a free email address" to many people, it's their lifeline to everything.
Heck, even myself as a tech savvy person worries about getting locked out of my Google account given I use an Android phone and have 2FA setup through that device for a large number of services, including my password manager. Note to self, get on that physical version of the digital black book that provides physical copies of anything needed to get back into accounts (2FA codes, backup codes, etc.)
Has GOOG done anything about it in the past year?
There needs to be a better way.
It's not just a GOOG problem. In fact, Yahoo makes me want to show up and yell at some business people: They lock people out of their accounts and then CHARGE THEM TO CALL IN and fix it. Another general issue is how much of this population uses/sticks with old products: There is a large number of Yahoo, AOL, and Hotmail addresses still being used, as well as old ISP mailboxes.
MS did well on this one, I agree. (And I also hate MS but credit where credit is due.)
1. When creating a Google account, you can choose that the account will be owned by a specified library (or other institution). This can also be done for already created accounts.
2. When that account is then locked out due to missing 2FA, the library holds the backup codes and can be provided upon identification.
This is similar to how Google accounts can be managed by a company that you are employed at.
You do need to be working with the government to integrate with Login.gov though (but it's just OIDC on the backend)
If available, it seems to me it would be the best option for this demographic.
I picture a world in 2050 where there is no more Google because everybody got locked out or banned.
They are working "in the future" where every human has access to the virtual world by "right". You cannot cut off someone's gas or phone without huge regulatory hurdles. And we will see something similar for access to internet
We just aren't there. And that's the problem.
And this conversation should not be about "google should reduce its security" it should be about how do we regulate ISPs and google and facebook and Email providers so that they are on par with the gas company?
Is access to http a basic utility? Access to an email inbox?
In short Internet access is a necessity for access to civil society, and now we work out who pays for it. it's going to be a fun decade
I am guessing this is what a bunch of companies offering the "photo of you and your id" services are waiting for.
Which to me implies it should never be a proprietary solution - anyone know of a FOSS version of this out there? Anyone want to start one ?
Another annoyance is if you enter a landline number most of these things just assume it's a cell and then ask you for the verification code that they just sent into the ether.
The best part for me is "try to" rather than the much more common and nonsensical "try and" that I see all the time. I think I would pay for a Chrome extension to automatically replace all occurrences of "try and" with "try to."
It takes a librarian...
Also, thanks for changing Google for the better, and helping those who need help the most!
Side note: she did unfortunately use "try and" once.
Would it be possible for some nefarious person to grab these keys? Yes, but essentially you're reducing the MFA back down to SFA, a cost I think likely worth it for this group.
OTOH this library use case is a specific kind of outlier: I imagine this issue occurs in most/all libraries; it's a situation where changing the level of security is worth the tradeoff; it doesn't affect the security of anyone else; it's relatively inexpensive.
I don't consider this a "blame the victim" solution to the problem. I see it as an accommodation for people with specific but special needs.
Second, while Gmail is popular, they are not the only contenders in the space. Can these users not also have an outlook, AOL, or yahoo email address?
I understand switching email providers is not an easy thing, but it is not impossible.
I'll stop you right there. While I feel for the folks affected by this, they're not customers. And there ain't no such thing as a free lunch.
Broadband access and an email inbox aren't human rights in the US - even if they should be, we're just not there yet. And Google has no business incentive to provide customer support to the freeloaders.
I think it's crappy that there's no recourse too. But like it or not, users assent to this when they sign up. The solution here is education - people need to be told outright that they have significantly reduced chances of recourse when they're using somebody's service for free.
Society seems to have abetted the notion that all citizens will have Gmail accounts, down to the issue of Chromebooks in elementary schools. What exactly are we teaching people by dropping them off inside these gardens to bang on the walls?
It goes further than Google or Gmail. We need processes that make actual sense. "But the government forms I need to fill out are online-only!" First mistake. Whoever signed off on that in government should be fired immediately.
This isn't a Google problem, despite how easy it may seem to blame the faceless boogeyman. It's an education problem, a process problem, and a common-sense problem.
s/man/woman, in this case of course.
> STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS
> This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longer are having this issue as often as before due to various improvements.
> Please delete this from HN. You are essentially DDOS’ing my work email and the library branch phone number making it very difficult for us to perform our duties as civil servants today.
That was added well after the document was posted to Hacker News, so I don't think this is a fair question. Also, I'm sure dang has a life outside of Hacker News, so I don't think it's reasonable to expect everything to be acted upon immediately.
And by "we," I include everyone from users, technology providers, and especially governments that require email addresses to get basic services, everyone.
A modest proposal. Can one YubiKey serve several email accounts? Ask patrons to sign up for a library card. Register each library card with one key, such that one key can serve many patrons. Help them enroll with multi-factor authentication. Whenever they need it, simply request the token from the librarian desk.
(Put the token on a giant brick or yardstick, so that it never leaves the library. Sort of like how they do at gas station bathrooms.)
Maybe they shouldn't have offered email for free to the world if they didn't want to be the world's free email provider.
Yes. I use the same YubiKey with at least three Google accounts.
Why is Google making it hard for the poor to access their email in these times?
it’s not like google just launched today. They have the data of these users, who use internet from public libraries.
Lots of people seem to want Google to be forced to provide customer service. It's an interesting idea, but I'd imagine it would be the end of free Gmail which may just force the very same people who can't afford permanent phones to switch to an even sketchier, unregulated free email service. Either that or the government would have to somehow provide free email, and I think there's actually a strong argument to be made there if an email address is required for welfare / parole / other government processes.
> Please delete this from HN. You are essentially DDOS’ing my work email and the library branch phone number making it very difficult for us to perform our duties as civil servants today.
What protects us from invasive search is not lack of a uniformly accessible system for identification - its due process. And if the government chooses to compel you against your will and without due process - whether or not you have a laminated ID in your pocket will be irrelevant.
A national ID would make the few cases where you need to hide your identity (like you're a 10 year old girl who was raped and needs an abortion, or the doctor that needs to perform it - https://www.seattletimes.com/nation-world/10-year-old-rape-v...) much harder. Until our government decides not to be so fucking crazy, we need to push back on its ability to unjustly track and then punish its citizens.
Point is, they don't need a national ID to pin you to some cell phone records that place you at location X at time Y, to get your CC usage data, to find out pretty much anything they like, to connect that to a license plate, to snag toll and other photo records of the vehicle from various sources, et c., and the only reason there are any restrictions whatsoever on that ability isn't because we don't have a national ID, but because we're not yet living under a tyranny. Difficulty IDing people isn't the limiting factor.
The public-private hybrid ID we have now is terrible and also carries all the same risks under tyranny as a national ID, which is at least not-terrible.
It's not like having a national ID would mean all the spying-data companies collect on us would automatically be shared with the government—more than it already is, anyway. It'd be the same as now, except with fewer ID-related problems for people.
The difference between rounding up people or not is often just whether it is logistically feasible. Right now, even if they collect every kind of data from every business, it would be a nightmare to attempt to collate it all, because it comes in so many sources with so many differing fields that may be out of date or inaccurate or wrong and would have to be normalized etc etc etc. Impractical to do on a very large scale. Except when there's a single identifier they could look for, which would completely solve the problem for them, and make it easy to round people up.
Companies that sell data to the government without the consent of the public is a huge problem we need to deal with, for obvious constitutional reasons (4th amendment).
If you think Gmail is bad, stop using it. They aren't the only game in town.
This works without JS enabled:
https://docs.google.com/document/d/1f6HPQbUjslcbjVHkJkAgYmQm...
As a brief introduction, the goal of computer security is generally to make a computer as secure as a door lock. A door lock can be easily broken into, but to do so requires that a person show up to the door in person, and to take some illegal action. A computer, if secured naively, is much less secure than that: if I gain access to the password, I can hack a computer from anywhere in the world. Furthermore, since I have the password, it isn't even clear that I am breaking any rules.
The library system can solve the problem described in the letter while maintaining door-lock level security in the following way: they would give to every library system user a library card, associated with their person. This card would be used to log in to library computers. Certain information would be preserved between logins, namely the browser cookies. Thus, the user would remain logged in to their google account as long as they had access to their library card. If they lost the card, or forget the password, the library would be able to reset the password, or issue a new card, as long as the user could prove they were the owner of the card to the satisfaction of the library employee.
Google, being an internet company, cannot reasonably issue cards to all their users, but libraries regularly do so. For the same reason, Google has difficulty verifying the identity of their users, which libraries can do easily. Google is structured as a profit seeking corporation, and would need to justify charitable behaviour to shareholders. Libraries are well known to exist to provide services for free to their users, and can easily alter their operations to do so differently. Most importantly, libraries already provision physical access to computers. The most important element of our door-lock security model is that a person must appear in person in order to get around our security. The library is the organization operating the physical terminals, and so the library alone can provide this essential element of our security model.
We need to start seriously spreading the word that Google cannot be trusted to hold anything important to you
Email is an inherently insecure service. Security professionals had been clamoring for default 2fa, E2EE, etc. due to various breaches, leaks, and security issues that have occurred over the years. Remedying the aforementioned security issues necessitates certain practices to be phased out and the people who relied upon them to be caught up to speed or left behind.
My Indian friends tell me it's much worse there. All of their government services are tied to a specific phone number that they must keep forever. So all of the ex-pats living here still pay for their Indian phone number back home so that they can still interact with the government when they need to.
@dang
I vaguely remember someone posting about a hypothetical scenario where their house burnt down and they lost all their physical devices and couldn’t get into anything etc.
This one? "I've locked myself out of my digital life": https://news.ycombinator.com/item?id=31652650
The only thing holding me back is I have a custom domain, I'm not specialized in the web, and it's not super intuitive how to set up my hosting with one company, name registration with another, and e-mail with a third. All for the same custom domain.
Edit: it's either back on the frontpage now or I missed it somehow
Edit 2: Looks like the doc was updated and it was posted without consent. I think we should delete the post now.
Or, you know, an email account with its own security policies? I got my first ever Unix shell account from a library.
That can't actually be a thing, because it would allow a malicious person to lock out anyone's account if they just know their gmail address. Not even Google could be that stupid.
Just use the app to scan QR code when creating a Gmail account. Or do it anytime later. Then never use network connectivity to generate the 6-digit 2FA code.
---
[1] People with these are part of the demographic being discussed.
Google consider this flagged as a suspicious fake account and he was never allowed back in to his email.
Or is SMS the only possible second factor authentication method?
Outlook.com as it's the simplest to use. Their immediate concern is their livelihood so they need a free email account and not have to think about anything else including its lifetime.
To a techie audience?
ProtonMail, FastMail, Tutanota, GMail, Postfix...
* Relatively better, but still lower than what I expect.
I recommend subscribing to "Talks at Google" on Youtube to see the kind of things that occupies the minds of people working at Google.
Many have tried. Many have failed.
The best the author can do is encourage people to move to alternative providers.
There are options to fix this, but they're social, not technical. To get there, let's start with the technical side of why the author's proposed fix won't work.
Google has no idea who anyone is. The only way they can know is the authentication process. And that process is under perpetual, high-investment attack by basically everyone because Google is a valuable target. Everyone from script kiddies to state actors have tried every method to not only compromise individual accounts but to build frameworks for systemic compromise, because when you focus on a single target you can invest the resources to, for example, set up a server that mimics the Google login page or a phone bot that sounds like it's making calls from Google Security. Our author bemoans the lack of a back-channel to recover one's account, but that back-channel is (a) perpetually overloaded with requests to access accounts (b) one of the major vectors for attempting to steal an account, because the back-channel is just one more interface on the systematically-attacked system.
(Source: I know someone who used to be in the loop on the back-channel. Scammers would call crying about kidnapped children who were going to die in a couple of hours unless they could get into a GMail account to get an address in a ransom note. Google had to train their phone crew to understand that probability was heavily skewed in the direction that if they capitulated, they were, within a statistically-negligible margin of error, never saving a kid and they were always letting an abusive significant other into their former partner's account so they could ransack it for passwords and vulnerable 1FA access codes and fuck up someone's life. Truly sick, heartbreaking stuff).
So that's the system under attack. How to address the problem that the elderly and impoverished can't afford to keep up with Google's security measures?
There are a couple of options here. In the short run, the cheapest is "Don't use Google." Use an email provider under less persistent threat, and one small enough to offer high-touch technical support. This is one of those situations where free may be the enemy of "cheap but affordable," and to bridge the gap someone could even start fundraising to pay for accounts on a service like that. There may even be meat on the bones of someone being a non-profit high-touch email provider of that sort, who can secure a person's account by having them log in from a specific, privileged machine within sight of an operator who knows them personally. Go back to the old days of how the DARPANET was actually secured by "every node is locked behind a door."
Another option is that a service libraries could provide (at possibly great expense to themselves, but options on the table) would be to serve as a credentials broker for their users. Have the library keep track of the 2FA side of things. Risky and adds expense to the library, but for this userbase that local service is the missing piece of the puzzle. Unfortunately, this isn't something Google is set up to provide; they're too centralized, they aren't actually in the communities where the need lies.
This. I wrote as much in an earlier comment. Why not allow the option to delegate a trusted third party to manage $ACCOUNT MFA flow? I'd use it (and kind of already do, via the recovery email addresses) for managing my aged parents accounts.
This seems like not that hard in terms of implementation and UX. What is the risk/expense from the libraries PoV you are alluding to?
But the insider attack situation here is nasty... A corrupt individual in the loop could trivially trigger a password-reset attempt, use the fact they have control over the user's 2FA (or recovery email) to steal the user's credentials, act on behalf of the user for a bit (reroute benefits to some other address?), and then just wait for the user to discover their password is locked out and kindly help them correct it.
Keeping in mind that the reason 2FA came along was that we learned the hard way that passwords are not sufficient to secure an account accessible on the public Internet. Too many effective side-channel attacks (both phishing the user and exploiting human psychological vulnerability, i.e. pulling passwords from another site and discovering that the same account and password works elsewhere).
... but such a system could allow for the account recovery solution to be "Go to the library and talk to a human being there, who can hit the account reset button." Libraries offer the advantage of having an already geographically-distributed-and-local staff by virtue of the non-digital service they provide.
Surely this problem is of a scale that warrants government action?
For tech illiterate, maybe the least bad option is that their security is that they won't lose their wallet. I think this is one of those situations where security has to take a back seat to usability.
1. Create a passphrase with this method: https://xkcd.com/936/ 2. Write down your passphrase. 3. Write down recovery codes, and keep them in your wallet.
Also: Tips to make sure you never lose your wallet.
I'll print out all the comments and forward them on to the Free Library. The next time a patron gets stuck, the librarian can read one of our comments out to them.
Credential stuffing is a big problem. It is a really big problem for email accounts, which often are all you need to reset a password for other critical accounts. 2FA, even SMS-based 2FA observably reduces the rate of account theft. 2FA also fundamentally requires access to some extra thing that you posses, often a computing device. So it also adds friction and can lock people out (as can losing passwords). I think in part because 2FA appeared later, we seem to be okay with people getting locked out of accounts if they lose their password but not okay with people getting locked out of accounts because they cannot access their second factor.
Library computers are also untrusted devices. They are also not the only untrusted devices that people want to use to login to their accounts.
As for solutions.
Printable access codes are supported in gmail. This is a pain to do over and over but does permit 2FA without any additional computing device. You can let people disable 2FA (which is possible), though you can expect another letter pointing at the suffering this causes and arguing the opposite.
You could enroll the library in a "Bob uses this library to authenticate, don't ask for 2FA here" mechanism that does not use cookies but I'm not sure what this would actually be given that the library is deliberately resetting state on the machine after each session. Perhaps there is some acceptable state that the library could keep around? A solution in this vein requires coordination between email providers and libraries but is maybe the most promising approach. Or you could do something like a family account that permits the librarian's account to tell gmail to temporarily permit 2FA-less logins for a particular account/device pair.
You could recognize that 2FA most protects against stuffing and not let people choose their own passwords to guarantee uniqueness, but I suspect you'll get an equal number of people who fail to remember their long password of random characters and get locked out, leading to a similar letter complaining that Google is harming people who need memorable passwords.
Those sorts of password reset systems are regularly bypassed by convincing scammers who have stolen some personal information.
How do they verify requests coming from Police and courts who want data?
People who forgot their login can go to Police or maybe some govt office who can help them to prove their identity and then approach Google.
I am sure Google has brilliant people who can come up with a solution if a law is passed for such things.
You would need to verify your real-world identity before losing your account which people would really hate if mandatory and nobody would bother with if optional.
I mean, even a paid-for, ad hoc ticketing system (e.g. if you need a reset on your account, pay $10 and create a ticket; no need to have an enterprise subscription in advance) would be better than what we have currently.
But financial institutions solve for this all the time when people forget their online banking details or their phone breaks for 2FA. It probably costs them a far amount in customer services support, but they suck it up as the cost of doing business (probably because they legally have to). Whereas Google just foregoes it entirely.
If a user has chosen to link their account to a real ID in this way, they must be able to regain access to their account regardless of password/2FA blah blah by presenting a valid ID.
Banks and lots of institutions have processes to do this. The librarian is right, "how" is not an issue because verifying identity is _not_ an unsolved problem lol.
I was a gmail user since gmail was in private beta 18 years ago. I never had a phone number associated with it. And yet two or three years ago when I tried to log in Google decided to just... not let me do that, because fuck you, and started extorting me to give it a phone number. If I don't give it a valid phone number it won't let me access my email. But I can't really do that because, you see, I don't actually own a phone number.
So now I'm essentially locked out of my almost two decades old email account, for no good reason whatsoever except the fact that Google is a bully. Fortunately I've long since migrated to another email address on my own domain as my main address, so it doesn't really matter.
Do not depend on any Google-provided service. They don't care about you, and they will screw you over sooner or later. You're just a number to them. Most importantly, pay for any critical service you need (like email). Do not wait until it's too late. Do it NOW.
A great example I use is there are a ton of restaurants and fast food places around me. I used to walk to get lunch every day but eventually had to stop, these places realized most customers went through the drive through so they closed the lobby. Now even though this place is a 5 minute walk from me, it's no longer accessable if I'm not in a car.
Same thing with my TV and Router, both of which required an app to just setup. The TV required an internet connection to "activate" and I realized that if some family saved up and bought this TV but didn't have an smartphone or internet connection, well they just bought a $500 brick.
And that's why authentication standards like FIDO scare me. To me it almost seems that the standard was written by a bunch of out of touch tech bros thinking to themselves: "Well of course EVERYONE has a phone these days"
I’m a huge fan of shoving crap like that back in the box, and returning it DOA. The soulless bastards that built it don’t know if I’m computer literate or not.
I think this may have to do COVID and then staffing shortages creating a necessity rather than a active business decision. It would be ridiculous but couldn't you walk through the drive through? (I probably wouldn't do it either but I can't really think of a reason you couldn't)
There's a Starbucks near me that was built as drive-through only. Where there should be a lobby, it's just blacked-out glass and a door for the employees to enter through. Makes the whole strip mall look really scary, especially since vagrants sleep in the doorway.
I assume it's for commuters, which means all Starbucks contributes to the neighborhood is traffic and crime. Thanks, Starbucks!
It would be ridiculous but couldn't you walk through the drive through?
I used to do this all the time when I was a kid, but more and more places won't serve walk-ups at drive throughs. They claim it's for safety, hygiene, insurance, or whatever the excuse-du-jour is. They just close the window and ignore you.
I was told "Sir please come back in a vehicle" when I tried. When I told the guy I don't have a car, the guy gave me a blank stare.
Off the top of my head, both Xfinity and Google Home have this problem and it aggravates me to no end. I can reset my gateway from my PC but for some reason, *need* to use my phone to manage Xfinity or any of my Nest routers
STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS
This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longer are having this issue as often as before due to various improvements.
Please delete this from HN. You are essentially DDOS’ing my work email and the library branch phone number making it very difficult for us to perform our duties as civil servants today.
I do not know how this made it onto HN. Someone must have leaked it. If they need to work that out internally then I’m leaving this here for their reference. But I do not want news reporters or random HN readers contacting me or the Free Library over this.
Maybe, just maybe, if people are sobbing, maybe there's a good reason why! And maybe, just maybe, if you don't want to receive such support, you can advocate for a system in which you could opt out of all such processes entirely, instead of arguing that any form of account remediation shouldn't exist.
They could preauthorize a random token amount on credit card with matching details, have you call the number on the back of your card to figure out that amount and then you have to input that number to authorize the access in an oath like flow.
Please tell me if you see something wrong with my procedure?
edit: I saw something wrong, I have forgotten about the vast unbanked population in the rest of the world as we don't have that problem in Canada¹
1) https://www.gfmag.com/global-data/economic-data/worlds-most-...
a) google will have to require a credit card in order to open an email
b) person opening an email account must actually have a line of credit, e.g.: many of the people mentioned in the OP will not have it
c) opens a new attack vector on google accounts, e.g.: people who secured their emails using 2FA app for example can now be attacked via a credit card process
This isn't to say that this is an unsolvable problem, it's not, but it's definitely worth talking about.
Post offices are geographically ubiquitous, already deal with identity verification, and already have to maintain the trustworthiness of their workforce.
I'd like to see a system where (a) an account [whether GMail, Facebook, Schwab or Bob's Online Pet Food Mart] can be tied to a real-world identity and (b) when you lose access, you can go to the local post office to verify your identity and get a one-time recovery token for a given account.
This sort of solution (and your post office idea) can be, but they don't satisfy the last resort customer service role, for people who haven't set these kinds of recovery options up.
I feel 2FA is a class libraries should be teaching. I am off to my local library to volunteer as a resource for that specific purpose. Anybody going to join me at their local library?
I was going to make the recovery code comment myself, but instead I did a search to see if anyone else had done so. Kudos. If would vote this comment to the top of the discussion if I only could. IMO it should be (part of) a PSA.
Proof of identity should be a government function, and that we likely have millions of people in the US with no way to prove their identity has real-world consequences beyond the flaw in my post-office-account-recovery-scheme; it affects access to benefits, as you said, as well as voting and being able to even prove your citizenship. That should be fixed too, but I'm not sure we can do any better for internet identity verification than the post office fallback.
Its time to bring this stupid, dystopian nightmare we’ve created to an end.
(a) still be a government agency, not a wholly-owned subsidiary,
(b) already provide email via government servers and clients in kiosks at the post office (and the personnel to staff the service and handle high-touch troubleshooting) instead of relying on private corporations and organizations to be the sole providers of what has become a necessary service, and
(c) provide basic banking services, knee-capping the payday lending and check-cashing industries.
... but it isn't that kind of country right now.
I would recommend a $5/month email service. It would be nice if free Gmail gave even more free stuff, but only a paid for service can really expect paid support staff.
Having said that, this seems like a terrible idea from a security perspective. There may well be no way to design a service that is resistant to social engineering and lets you unlock your account via a phone call.
Surprise! There is. https://workspace.google.com/intl/en_ie/pricing.html
> Google Workspace Standard Support—Standard Support is included with your Google Workspace license. It provides support with a 4-hour service-level objective (SLO) for P1 cases. If you're interested in faster response times and additional Support services, Enhanced or Premium Support might be a better fit for your business.
https://support.google.com/a/answer/10105075?hl=en&ref_topic...
A good question is what does P1 case means. Locked out of email or "sorry Google, I just wanted to say your global email network is down, when it's gonna be up?"
EDIT: it's not $5 in the US (between $6 and $7). I've called support a bunch of times.
Google's 2FA system combined with their lack of support terrifies me as a security-literate user. Here's one example: I was traveling and signed into Google from a new location. Google prompted me to verify myself via two-factor auth, and the only method they allowed me to verify by was by opening up the Google app on my iPhone and by confirming the provided number. I tapped "try another way", and gone was the option to verify via authenticator app.
I'm lucky that I had my phone on hand but I was dumbstruck. What if I lost my phone? I'd be screwed, locked out of my account with no way to fix it, even after following the best security practice of enabling 2FA via authenticator app, because Google took it upon themselves to say "screw your choice of security, open our app on the phone" (also, thereby coercing me to link my two devices to my ip address/location for analytics/targeting reasons, I'm guessing).
I could have done everything right and still gotten locked out of my account.
Even if the initial push for 2fa was security, by dev#1, you can be positive dev#2, 3, 4, xxx, 100 came running, and thought "tracking".
Google owes everything it is, to being the sleaziest, sneakiest, slymiest company they can be.
If the internet is an information highway, google is a van, stopping, and asking your kids if they want candy.
Were google a business in your physical neighborhood, tracking people as they do, they'd end up with a molotov cocktail through their window. No one would abide such behaviour, but the average Joe has no idea, and cannot understand, and thus, does no object.
Google is doing to our society, what the new settlers to North America did to Native Americans. Offer them beads, and plets, in exchange for riches, using our own ignorance against us.
Google is a primay example of the "slippery slope". They were given an inch, and they took us out back, and beat us with a 2×4.
If you trust your business to google, you're nuts.
And to the comment I replied to, yes, it is all for tracking.
Edit: yes OK I admit I don't like Google, just to ensure my bias is clear.
Why?
You make it sound like Google is a pauper, doling out free e-mail accounts and not making any money off of it.
Just because it's not billing your credit card doesn't mean you're not paying for GMail. You just pay for it indirectly through advertising.
If only a paid service can expect paid support, then how does Google make hundreds of billions of dollars every quarter? If GMail wasn't making any money, it would have been shut down years ago.
(Remember, the cost isn't "How do we field calls from a fraction of our 1.5 billion users," it's "How do we tell whether that phone call is an actual user, or just an attacker treating our phone service as yet another attack vector?")
I remember being *stunned* in a positive way by Google's out of the box thinking back when they *invented* "self-service" account management, aka "no phone support provided". I thought that it was a brilliant move and that this little search company was really going places.
I hope I might be forgiven for failing to anticipate the consequences for our least affluent sisters and brothers.
I am now of the opinion (for many, many reasons) that human-interactive customer support is a mandatory cost of doing business when your business is materially important in the lives of the customers (both paying and not paying customers).
That Gmail is "materially important" is well established already, yes?
Yet somehow companies of similar scale like Amazon, Apple and Netflix manage to provide robust customer service.
If they want to continue to harvest their customer's data they can provide those customers with support.
Also, those Google devices aren't free. You buy a Google device, get no support, and the devices are updated for way fewer years to boot.
You keep mixing things up. The topic is the viability of high touch GMail support, not support for Google's home-grown devices.
Amazon is similarly an order of magnitude fewer users than Gmail accounts (and tends to address this issue by pushing the hard-to-address auth problems onto the seller... There are known exploits for just pushing exorbitant costs onto the seller via buyer fraud). Amazon has a couple hundred million customers... Gmail is in the billions.
I am, perhaps, just simply old enough to remember when not everyone could have a Gmail account. Low touch customer service that works 99 plus percent of the time was necessary to open the floodgates for free. I have never seen a practical explanation of how to scale providing the service otherwise. There's room for improvement, but (a) every simplification of authentication must be balanced against how it can be abused to steal accounts, and (b) I cannot conceive of a solution that would rival high touch customer service, and that scales to the billions. If one exists, I look forward to being extremely pleasantly surprised (having myself been on the receiving end of losing my phone while away from home for an important event: yes, it really sucks, Google's trust model is they trust you zero without some corroboration if all you show up with is the password). But I've watched them hammer at the problem long enough to suspect it's uncrackable at the billions-scale.
They simply choose not to.
I'd be interested to see a workable solution but, to-date, I never have.
This doesn’t seem that hard. Charge for support if they have to (eg charge per minute or call).
In terms of working out if a call is an attack, far juicier targets such as banks are able to manage, I think they can work it out.
This would be one solution. But it would require Google to hold significantly more PII, explicitly, on every Gmail user than they do right now (and make the process of opening a Gmail account take a bit of time, like it does at a bank). This is one of the better suggestions I've heard, though it would threaten the integrity of the existing 1.5 billion accounts unless Google grandfathered them into a "low-identification" status.
Google makes more than enough money selling everyone's personal data via advertising to afford to provide customer service.
They simply choose not to.
Customer support is a cost sink that usually isnt empowered to do anything. Its more PR tactic to make people feel they are "heard" without resorting to twitter.
In the email/business apps space, google is clearly not a monopoly. Presence/quality of customer support seems a very reasonable grounds to have normal competition over.
Too bad. If you have a business (and Google is a business) that goes business with the public (which Google does), you should offer some form of customer services. It's what we human beings call "the right thing to do."
Yes, customer service costs money. It costs money for the dry cleaners, the restaurants, the banks, the car washes, the design firms, and every single other company on the planet. It's a basic part of the financials of running a business, and is called "cost of doing business."
Imagine if Google's vendors stopped offering Google customer service. Janitor didn't show up today? Well, clean your own office toilet today, technie. Surely, there's a YouTube tutorial for that.
Just because Google's a "tech" company, people on HN pretend like it's OK to not provide customer service. Bullshit. It has billions and billions and billions of dollars that it can throw at the customer service problem, but it doesn't for one simple reason: Greed.
How about the restaurant down the street maximizes its shareholder profits by not honoring your reservation? How about the dry cleaner optimizes its workflow by only being open three minutes a day? How about your kid's school right-sizes its workforce responsibilities by kicking your kid out on the street when you got stuck in traffic and couldn't pick him up at the exact moment the school bell rang?
If Google is so wonderful, full of so many smart people, then how come it can't solve its customer service problem? Ignoring the problem isn't a solution. You can do better™.
At their scale, this exact scenario happens all the time. The back-stop is that Google chooses to stop doing business with unreliable service providers.
This is also an option for Google users. Gmail competitors are just a click away.
... You are actually ascribing a larger amount of have-their-shit-togetherness to Google than may be strictly true. Without telling too many stories that aren't mine, I'll say "Usually. They usually don't." ;)
But to extend your analogy a bit... Google doesn't lose physical access to their headquarters because security is not a third-party vendor. They keep the mission-critical stuff in-house. That would translate, analogously, to individual homeless or elderly people running their own mail servers (infeasible)... Or, perhaps, libraries running mail servers and providing accounts for patrons tied to their library cards (might be actually, maybe, feasible?).
> When people start using Gmail, they don't expect to someday lose access to their online banking and utility bills and all the rest, and by the time it does happen to them and they decide to look for a competitor, a lot more damage has been done due to missed bills, etc.
You're absolutely right, and the back stop is almost certainly to make people aware of this very significant risk factor in using Gmail instead of alternatives.
> If regulation improves the terms the users agree to so they have some way to get reasonable help from customer service and Google finds that too expensive, they can either charge for Gmail or shut it down.
If such regulation is impossible at the scale of serving 1.5 billion customers, which I assert it is until somebody can provide a practical road map for getting to that scenario, then your recommended remedy for "Gmail doesn't work reliably for a subset of its users" is "Deny its benefits to all of its users." That seems strictly worse than a solution where we encourage people to be conscious of their risk tolerance before signing up for service with a company that can't guarantee they won't get locked out of their account with no easy method to unlock it.
Having a human to ramble at about vauge complaints is very different
The need for unbounded growth is not a valid justification for not acknowledging humans.
Now, I'm not sure what would be the solution. Regulation requiring some level of support? "Right to talk to a capable human" or somesuch? Sounds a bit arbitrary. In the meanwhile, I'm trying to un-Google myself and use more respectul alternatives, as well as raising awareness in my immediate circle.
If you're not able to do business at Google Scale without providing human support (and similarly, not treating support personnel like absolute garbage, as we see with call center operators for ISPs and whatnot), then maybe you just can't operate at that scale?
This goes even further: things like free-to-play games that use psychological manipulation to culture addictive personalities and whatnot seem ethically wrong to me. If your business model depends on absolutely fleecing vulnerable people, then maybe it shouldn't be viable?
I guess the base premise is I don't think companies should "have the right to make all the money in the world".
To be clear, I'm not advocating for the solution above, but I sure believe the problem described _is_ in fact legitimate within my morals.
In the physical goods world, there is no company that is allowed to dump products onto market and pretend like their customers do not exist. If their product cause harm to the consumer, their products will get recalled or they'd get sued.
Google has somehow allowed itself to infinitely scale their users but also infinitely shrink their liabilities/duty by binding all users to their ToS which foists arbitration on all of them.
The article states some types of harm causes, and those people are struggling for an few dollars, they can’t sue Google.
I do not claim that some sort of utopia of ultimate consumer protection exists. It does not for google, nor for physical goods companies.
Yeah, lawyers are just lining up to represent those homeless folks, elderly grandmothers, and people who just don't get tech.
Except they're not.
Clearly you've never been poor.
Represent them for what precisely? The tort of not providing a good user interface?
I don't think wealth has much to do with the lack of google being sued here. Wealth may buy better lawyers, but it doesn't create grounds for a lawsuit out of thin air.
> Clearly you've never been poor.
Life often sucks and is not fair. It is not google's responsibility to eradicate poverty
Lets pause on that thought.
Why is there a moral imperative to offer customer service (provided they dont misrepresent that they do)? What is the basis for a moral obligation?
Its not like there is a line in the bible saying "thou shalt offer tech support". Admitidly im not convinced by religious arguments, but i dont see any more modern moral source either.
> Imagine if Google's vendors stopped offering Google customer service. Janitor didn't show up today? Well, clean your own office toilet today, technie. Surely, there's a YouTube tutorial for that.
That's not really a customer support inquiry. That said, one of two things happen - either they are ok with it, or they are not. If they are not they negotiate other terms or hire a different cleaning company.
I'm not saying you have to like google's policies, just that its not unethical for google to have policies you don't like.
> Bullshit. It has billions and billions and billions of dollars that it can throw at the customer service problem, but it doesn't for one simple reason: Greed.
Wait. Are you telling me that a private corporation in america is trying to maximize profits? The horrors. I would have never guessed. What next? Is the sky blue?
> How about the restaurant down the street maximizes its shareholder profits by not honoring your reservation?
A) that action does not maximize shareholder profit.
And b) its wrong because they promised something and didn't deliver. The sin is in the reneging.
If google promised customer support and didn't deliver, that would be wrong. But google didn't promise customer support.
> How about the dry cleaner optimizes its workflow by only being open three minutes a day?
Sounds like a shitty dry cleaner, but i fail to see the ethical issue. If the dry cleaner doesn't meet your needs, don't use it.
Quite frankly, i think this entire thing reeks of entitlement. Just because someone offers to sell you a service, doesn't mean they have an obligation to provide it in the fashion you want. Their obligation is to not mislead, and be honest about what they are offering. Maybe what they are offering works for you, maybe it doesn't. If it doesn't dont do business with them.
> If Google is so wonderful, full of so many smart people, then how come it can't solve its customer service problem?
Because they don't want to and there is nothing wrong with that.
You seem to be working with a different definition of "wrong" than the rest of the planet.
There are people becoming homeless and losing government benefits because of Google.
Either you didn't read the letter, or you are a deeply amoral person who should seek professional help.
How would you define it then?
I know this is sort of a trick question, as defining morality is something moral philosophers have struggled with since forever.
Generally though, i think that if you give something to someone for free, you're not responsible to teach them how to use it or make it accessible to use (Unless you promised otherwise).
e.g. We don't think Linus is responsible for teaching a course on how to use Linux.
> There are people becoming homeless and losing government benefits because of Google.
Is it really because of google? I would think the primary party to blame here would be the government that seems to insist using email to communicate about benefits. This seems highly inappropriate given the audience they are trying to serve.
> Either you didn't read the letter, or you are a deeply amoral person who should seek professional help.
You can be sympathetic to the situation without thinking google is at fault here. Or alternatively think the situation is really sad and unfortunate but think that imposing a duty to provide support is a bad solution.
Haha, google doesn't provide good customer service for able bodied, so they provide the equal service for disabled.
Big tech needs a reckoning from consumer protection. Oh wait, those laws and the government agency were gutted. Nevermind.
Being a relatively new parent, the lack of consumer protection regulation in things like kids apps, youtube ads, and similar is APPALLING. I recall from my youth TV programming was highly regulated, arguably a bit too much, but at least the advertising industry had to stay within bounds.
App and youtube ads are the wild west, especially freemium games using any and all addictive mechanisms to extract money from kids and their parents.
Aside from that, big tech can't have it both ways. They can't be major providers of "cyberspace" services and provide no means for customer service or protection from their security automated services locking out someone. Why this isn't subject to large civil penalties, massive class action lawsuits, and even criminal violation of federal law is beyond me.
Terms of Service can't cover all of those, but then again, I haven't read them so...
Online services are steadily gaining importance equal to things like banking. Can you imagine a bank locking you out of your accounts and providing no means to get YOUR MONEY? Well, replace money with information. Why can't you get access to YOUR INFORMATION?
I understand the ToS providing the rights to analyze and use YOUR INFORMATION as part of the service, but we need federal legislation equal to the EU laws that I think do a better (but from what I can tell incomplete) job of delimiting the rights you have to YOUR INFORMATION.
What we are seeing is a symptom of the system of corporation government that is unbalanced by design wrought in hell.
Idk if mods or anyone wants to do anything about that, but yeah we have a case of someone being doxxed here, and even without malicious intent - its causing her issues in her day to day life.
STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS
This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google. It was not an open letter. It went directly to the security team and we had a conversation about it and it’s over. This is from well over a year ago and we no longer are having this issue as often as before due to various improvements.
Please delete this from HN. You are essentially DDOS’ing my work email and the library branch phone number making it very difficult for us to perform our duties as civil servants today.
I do not know how this made it onto HN. Someone must have leaked it. If they need to work that out internally then I’m leaving this here for their reference. But I do not want news reporters or random HN readers contacting me or the Free Library over this.
> STOP EMAILING ME AND CALLING THE LIBRARY ABOUT THIS
> This was shared without my permission. This was not supposed to be public. It was meant to be shared internally to Google.
> ...
This is a direct consequence of garbage cultures that have been left uncontended:
- UN*X, for not providing sane protocols that anyone would want to use (email is garbage in the first place. aside from the other 10000 problems with it, you should be able to generate addresses on the fly for each contact you interact with, which also solves spam and removes the need to have a "super smart" central "trusted" server with spam filter created with 10000 man hours of work that you can never create yourself). SQL injection was a UN*X braindamaged phenomena; no sane protocol would require embedding strings in the concrete syntax by hand, except when you have a bunch of idiots following the "everything is text" and "text is the lowest common denominator" mantra
- (continued) The email end game from the beginning (due to the spam problem) is that anyone who tries to make their own email provider will be blocked temporarily or permanently. There are already only a few remaining email services in existence. Due to UN*X braindamage, your email address is tied to a domain name, which will also be blocked as this is the natural meta of such a system: Admins get to look at the pointless string at the end of your address and decide if they don't like a substring of it, or only allow a set of known domains. Of course, if a sane protocol was in use, your address would just be a long string of meaningless bits and there would be no location or English word to discriminate on.
- Webshit, for allowing corpos to create interactive nonsensical applications instead of forcing them to use well established protocols with static pages describing the address of said services. Why in the hell can a website run code? Immediately the first thing I thought of when I heard of that was, "oh but wait what about all the stupid people who will make crap code that will freeze your browser?". This is such a terrible nonsense idea. And all the web standards are crap too. The web is a relic like Flash player.
- Infosec, for floating this idea that the user is an absolute idiot, and cannot be trusted to manage his credentials, not even with an "I'm an infosec expert, opt me out" option (ironically, anyone in infosec probably _can't_ manage their credentials). The only reason they are partially right is because of UN*Xy practices which make the most trivial tasks insecure (for instance, you could just dump the database of 99% of websites between 2000 and 2010 due to SQL injection, so for casual/lazy users who use the same login on multiple pages, you could login to all their services).
- Login voodoo, this started with "frequent flyer number" bullshit, where you could never tell if someone could use your stupid questions to get into your account without your password (they could), and password reset, which means your email address is essentially the public key for your account, and stuff like the Steam vuln where you could literally just press "i forgot my password" and it would let you into whatever account you wanted
- Hyperstatism, the narrative will eventually shift (if it hasn't already) to "you have to have a complex login mechanism because you need to be identified [by cell phone, government ID]"
This thread is a good example of how you are all helping nothing. We need real solutions to technical problems. Not solutions for people who don't know how to do anything properly. We can trivially have a cell phone that stores private keys, and public keys of other people and maps names to them, and is trivial and intuitive to use by lay people, but instead you will pander the dumbest possible thing like "biometrics", or some other forced 2FA crap, because poor people are supposedely too stupid to use anything else, like even a simple password which would still be better that what companies like google do. That's not how it works, you implement a PROPER solution and let the user friendly amendments to it trickle down. We even see now the capability folks reusing UN*X and javascript, the two worst OS and language to try and appeal to get uptake of their projects. Literally no solution the hacker has put forth today solves the problem, they just want to pander to specific nonsense that makes them feel pragmatic about themselves.
This side steps the issue that often these are scenarios where the patron is already locked out of their account and coming into a library as a last resort - so lecturing them on backup codes will be of no avail.
So, no, nobody has printouts of backup codes except the people who are already aware of Google's reliability problem.
I'm starting to wonder if she's the smarter one.
As of my most recent attempt, the OTP flow still mandates input of a phone number. Those who lack phones cannot request OTP.
If I were a Google engineer, this would read like one of dozens of pleas we get constantly to change X, Y, or Z for some small portion of the served population. And software devs in general find those demands annoying, particularly given some of the language that Shelley uses.
I think this would have gotten more reach and been better received if Shelley had a co-writer that acknowledged the reasons for 2FA from a security standpoint and emphasized the trade-offs that are being made + suggest other security measures. Likewise, having someone with a better understanding of tech would mean being able to do things like present some solutions that don't amount to "Oh most magic of Google Oracles, please fix this." Also the suggestion that they could contact her to learn about where patrons get stuck made me cringe slightly.
Basically, there's a misaimed moralizing tone throughout the letter that I think is at odds with its stated purpose, and it could have been written better, but the problem is real.
yikes*10000. cringe^inf.
I care more about getting the problem fixed than the writer's feelings not being hurt, and I think that things would be more likely to change if she'd written it differently.
> I care more about getting the problem fixed than the writer's feelings not being hurt
i don't really follow how the writer's feelings could be hurt in any case. you seem to have an odd perspective on all of this.
That doesn't make me 'cringe^inf' or boil down my tactical critiques to '"she's not asking nicely enough'. I presumed you were attempting to call me out for tone policing, and usually the point of that call out is to protect the feelings of the person being critiqued. Or to prevent the person making the tone argument from making it for biased reasons, but as I am ALSO a female librarian, that doesn't really apply here.
> you seem to have an odd perspective on all of this.
Yes, I imagine I would. I differ from both HN's average readership and the average librarian enough that my views on things are odd. I also did some time in communications work and I can't turn that off either. It's like seeing poorly written code for me.
no masters need to be pleased, no egos massaged (it's time for that obnoxious culture to die). they done bad and it's time to make it right.
embarrassing companies in public is an old tactic that predates consumer technology companies by a large margin. in the old days letters would appear in trade rags or newspapers to the same effect.
also, thank you for your time in public service.
Also libraries have a major cultural issue of their own, which is that they love credentialism and gatekeeping, and part of that manifests through assumptions that they and only they know the right thing to do (you'll note she suggests that Google contact her for more information rather than perform their own research or, God forbid, asking the userbase directly). Related to this, librarians, because of their vocational awe, are very, very susceptible to forms of communication that affirm their righteousness, and I see signs of that in this letter. From a communications standpoint, it's just not ideal to ask people do something by shaming them and assuming a stance of superiority while ignoring some context. That's just asking to be dismissed.
So that's where I'm coming from.
I actually greatly agree that tech culture needs to change.
> embarrassing companies in public is an old tactic that predates consumer technology companies by a large margin. in the old days letters would appear in trade rags or newspapers to the same effect.
Same problem, though. Embarrassing a company in a trade rag means that your employees are going to be judged by their peers and you're going to have a hard time hiring new employees. Using a newspaper meant that it went through some sort of editorial gatekeeping and the newspaper determined it was an issue that was likely to blow up. There were also plenty of cranky letters to the editor/opinion pieces in newspapers (especially smaller ones) that were dismissed as 'lol old people be cranky'. You have to have a strategy there.
I actually miss public service a lot.
Google in particular created a moral problem by choosing to implement a security solution that doesn’t serve people who depend on the services. They have the metrics to know better, but didn’t consider the use case.
I provide services to users in these use cases. It’s very possible to serve them in a way that is both secure and respectful to humans.
> The solution is so poorly delivered librarians are an ad hoc support team for thousands of people.
Well, yes. We're also expected to be teachers, social workers, etc. Everybody has been outsourcing/dumping the unprofitable work on us for decades now, why would Google and other tech companies act any differently? It's a problem that goes deeper than Google and the tech companies; it's a general assumption that infrastructure design can ignore the worst off parts of society and that people like volunteers and librarians will step in without considering whether or not we have the capacity for that as a society.
I just think instead of 'Google, fix it', it would have been wiser to make clear that this is a general problem (not a Google specific one) and to suggest things like partnerships between the GMail team and the PLA, etc.
I'm saying this in the spirit of 'yes, we need to take this territory but maybe a cavalry charge isn't the best way to do that given the other side has machine guns'.
And it might be even larger than that since you need to be rich enough too...
> But the way the letter is written makes it clear that she's not very familiar with the tech industry or how things are developed
And she should not have to be familiar with the tech industry. The tech industry's job is to figure out what the users want, by understanding what they do.
> And software devs in general find those demands annoying, particularly given some of the language that Shelley uses.
No no I hope not! I hope that engineers who possess some empathy will see a letter like this and feel their pain and feel compelled to do something for them. If someone feels nothing after reading this letter, they are lacking in empathy.
I don't think it's 'lacking empathy' to focus on whether or not the tactics or strategies my allies are using are likely to, you know, work. I would consider it more important that the letter be taken seriously and lead to actual change than people pat themselves on the back for their empathy in agreeing. It's because I have empathy for the people affected by this issue that I care more about effectiveness than the feelings of the people reading/writing the letter.
> And she should not have to be familiar with the tech industry. The tech industry's job is to figure out what the users want, by understanding what they do.
I mean, she's a librarian. I do expect people in our profession to be able to look at an issue, understand where our experience is lacking, and seek to either remedy it or find someone with complementary skills. For a librarian to run into a problem and not act to acquire relevant information is something I (as another librarian) am pretty comfortable judging as 'unwise'.
> The tech industry's job is to figure out what the users want, by understanding what they do.
The tech industry's job is to make money.
> No no I hope not! I hope that engineers who possess some empathy will see a letter like this and feel their pain and feel compelled to do something for them. If someone feels nothing after reading this letter, they are lacking in empathy.
I would like the world to be that way. It would be great. I would feel much more optimistic!
https://students.ubc.ca/ubclife/emotional-intelligence-101-e...
The moralizing is in fact aimed directly and purposefully at google
I think Google's poor implementation of 2FA is a result of misaligned incentives, unknown unknowns in the product development cycle (because she's right that engineers assume a baseline technological literacy and access that isn't there for everyone), and deeper social issues.
Lying it directly at Google's feet and implying that they made that choice maliciously rather than ignorantly (or to maximize their actual goal, which is $$$) + not noting that the bad decisions have also been picked up by their competitors makes it read more as a judgment than an invitation for collaboration/plea for help. I think a different approach would have been more effective.
I have a tactical disagreement with Shelley. No disagreement on the actual issue, which she's right is a huge problem and one I've personally encountered hundreds of times.