6 ms·
It may be harder to "recover your password", if you lost your second factor key, but the fact that it still is possible means Google employees (or a fraction of
by linopolus 9y ago
It may be harder to "recover your password", if you lost your second factor key, but the fact that it still is possible means Google employees (or a fraction of them) have a way into your account. I prefer services where this isn’t possible, even though that means the account is lost if I forget my password.
- giarc 9y agoThat doesn't mean an employee has access to your account. If you lose your USB dongle, you'll need to prove your ownership of your account, but that doesn't mean G employees will go in and look at your emails.
- munin 9y ago> that doesn't mean G employees will go in and look at your emails There are two forms of this assurance. The first is running into some guy at a party, or on an internet message board, who either works at Google or "knows a guy" who does, who then spends thirty or forty minutes semi-drunkenly rambling at you about how the security at Google is "military grade" and everything is "locked down" and they have some guy who used to run the Mossad in charge of internal security and he's the best guy ever and nothing or no one ever breaks in and that shit's a fortress. Trust the semi drunken ramblings of this guy you just met, your secrets are safe with the big G. The second form of this assurance is only giving the third party indistinguishable encrypted blobs of data. They can look at them all they want, it doesn't mean anything to them. You don't need to trust anyone, let alone some guy you found on the Internet and transitively a few hundred anonymous computer programmer and IT janitors spread across the world. Go figure, some people are more persuaded by the second argument. Even if you're reading this and you work at G and you know that the ex-Mossad security guys are digitally looking over your shoulder and you shake your fist at this screen muttering "you don't know how much we have it locked down here, clueless Hacker News commentator" you have to realize, somewhere in your heart of hearts, that a zero trust solution is preferable when you are trying to maximize for security.
- 3pt14159 9y agoEmail is a really dumb thing to put this to because 99.999% of the emails you receive will be sent by less paranoid people and 99.99% of the emails you send will be to less paranoid people. Just get a pretty locked down Gmail account and use pen and paper or OTPs or GPG for things that actually need to be secure.
- fixermark 9y agoExactly. Concrete example: The only two sources of Clinton emails being made public were 1) Emails disclosed as part of a legal discovery process that compelled Clinton to hand over the emails herself. 2) Copies of her emails acquired from a correspondent with a much-less-secure configuration of their Gmail account than Clinton's configuration of her private server. Email is, by its nature, a distributed infosec problem.
- ubernostrum 9y agoFor the average person in 2017, the threat of a breach of their email account is not that the contents of emails they sent or received will be published and used for nefarious purposes. Some celebrities, government officials and business people need to worry about that, but they're a tiny subset of the general email-using population. The threat of a breach of the email account is that it's the key to everything else -- pretty much any other account, with any other service, is instantly accessible the moment you're in someone's email, because the email inbox is where credential-reset requests are sent.
- dpark 9y ago> you have to realize, somewhere in your heart of hearts, that a zero trust solution is preferable when you are trying to maximize for security. There’s no such thing as zero trust for email unless you’re going to run your own server (even then it’s iffy because of communication with other untrusted servers). By using a mail service, you have to trust the people running the service. Even if they pinky promise to immediately encrypt every message with your public key a never never never look at it, you cannot know that they aren’t secretly redirecting a copy to the NSA and publishing another copy on the novelty Twitter account @muninmails.
- pricechild 9y agoUnless the secret (password, certificate, hardware token, whatever) isn't absolutely required to access your data "because maths", then employees will have access to your data? I guess there's a distinction to be made... perhaps if you go through that process you can regain control of your handle but not private data. But that wouldn't be useful since unless you're using a system which warns that your identity has changed (e.g. a new pgp key) then old contacts will continue to contact you, spilling the beans on old conversations?
- lostboys67 9y agonot every J random googler I would hope but from experience working on x.400 mail some key people will have access. in the 80's I had root on all the machines for the main UK ADMD and the level beyond root on the two billing systems - the OS was based on ITS A custom version of PR1MOS which is why there was a level beyond root. Of course these days I would have had to have SC or DV clearance - I trust those googlers who do have access are properly security cleared :-)
- dredmorbius 9y agoGoogle have somewhere north of 3.3 billion user profiles registered. That was the count when a third-party service tracking such things was last on-line. Assuming relatively modest rates of 1% of all users needing a password reset per year, the rate of password recoveries approaches one per second. That's about 100k per day. (Google scale is large.) I'm a fan of physical-token multi-factor authentication schemes. I don't think Google's process goes far enough. But I also recognise that it would be absolutely madness to deploy something like this with no means for account recovery. Note that this system does not mention encrypting user data (a step I strongly advocate). In that case, losing a key is very much like losing an SSH key. There's no historical data relying on the old key, so issuing a new key is sufficient for recovery. The critical part is to not issue that new key to the wrong person. If there are data encrypted against the key, the problem gets far more complicated: you both need the means to reconstruct a key, and to ensure that you do so only to the right person, and under the right circumstances. A key-splitting and key-quorum mechanism might be one way to approach this, possibly with a spare set of workfactor left off the keys. I'm also looking into the question of whether or not blockchain-type public ledgers might be useful in recording / reporting on keys recovered in such fashion. Initial inquiries suggest that isn't impossible, though I'm not aware of any extant solutions providing that capability. (On a related note, given mortality statistics, Google also have the issue of dealing with the death of users at a scale of tens of thousands of times daily.)
- tonyztan 9y agoFor user death/disability, Google has the Inactive Account Manager feature, but only if the account owner set it up before the death/disability. https://support.google.com/accounts/answer/3036546?hl=en https://support.google.com/accounts/answer/3036546?hl=en
- dredmorbius 9y agoAnd that isn't going to scale, for the obvious reasons.
- dpark 9y agoGoogle cannot implement what you’re proposing (nor can any email provider). Whatever mail service you choose must be able to send and receive email on your behalf and to do this, they must have access to the email in unencrypted form [1]. Yes, they could encrypt at rest. And yes, they could even encrypt with your public key at rest. This doesn’t eliminate the need to completely trust them [2] but it does completely break critical features like search and a usable mail archive. [1] Yes, if you use gpg and the party you’re communicating does as well, then you don’t need to trust the email service. Good luck with that. [2] If you can’t trust them to not look at your email then you can’t trust that they’ll actually encrypt without keeping a copy (or that they’ll actually encrypt at all). Encryption at rest is a great feature, but not for eliminating the need to trust the organization running the email service.