Live data from Hacker News

Google launches new security features to protect users from unverified apps

techcrunch.com

21–30 of 65 posts

Re: Google launches new security features to protect users from unverified apps

#21

Does this also appear on websites only using Google OAuth for authentication, requesting only the email address?

No, it doesn't appear for email/basic profile scopes.

Thanks for that info, if it's setup like this it doesn't affect me at all instead of being really annoying to work with (since most of my apps are still in development).

Re: Google launches new security features to protect users from unverified apps

#22

Earlier quoted context omitted.

It is, and with Google in a position of owning much of what happens online, it's also Google acting unilaterally in ways that multiple actors might not. Both statements are true: It's a good thing. It's not right to have one company with so much power No evil Google required.

There are plenty of cases where you might reasonably question how much control they have. But this is a mechanism to protect access controls to your Google account , almost the definition of something first-party that they should gate very carefully.

> you might reasonably question how much control they have

"Доверяй, но проверяй" (trust, but verify)

It's very important to always question decisions made from a position of power; vigilance is the price of freedom. Questioning does not necessarily mean disapproval. Everyone concerned about the future of the internet should be questioning Google's motives and intentions every time they unilaterally exercise their power to judge which apps are "acceptable".

In this case, it shouldn't take long to find the answers to that question: Google should have implemented this kind of dismissible warning a long time ago. Hiding the "continue" option behind the possibly-misleading "Advanced" link is a minor problem, but some sort of warning is obviously necessary. (I'm actually impressed they used a type-this-word check instead of yet another ignorable "go away" button.)

Re: Google launches new security features to protect users from unverified apps

#24
post #6

Earlier quoted context omitted.

I was wondering how HN would spin this into Evil-Google. It's just tiring at this point. This is a perfectly valid security guard that protects their users.

> This is a perfectly valid security guard that protects their users No it's not. It's Google telling it's users which apps to use and not to use. For regular users Google presents itself (just like Apple does) as an authority of what's a good app. Any other apps automatically are not good in the mind of regular users.

When that app gets access to your Google account to do things on your behalf then this is a perfectly valid strategy. Feel free to not integrate with Google's OAuth system if you don't want to deal with them.

Re: Google launches new security features to protect users from unverified apps

#25
post #8

I like the forced UX of typing something, though "continue" might be glossed over. It would be an interesting study to determine if typing "I know the risk" is a better safety mechanism for users (can be A/B tested for less pass-through events) than "continue".

Typing something unique (eg the name of the app) might also be useful as it forces some cognitive processing.

Or "I allow LeetHaxorApp to access all my data"

But I guess that is a bit too much typing for most people.

Re: Google launches new security features to protect users from unverified apps

#26
post #16

I'm not sure I'm a fan of the way Google is re-using the Chrome error page styling for this, but I can't put my finger on why exactly...

Because you associate it with an error that you have no control over? I find that I'm tuned to recognise patterns of behaviour, so when the patterns look similar to other things, but aren't the same, it's quite confusing.

[deleted]

Re: Google launches new security features to protect users from unverified apps

#27

Earlier quoted context omitted.

> This is a perfectly valid security guard that protects their users No it's not. It's Google telling it's users which apps to use and not to use. For regular users Google presents itself (just like Apple does) as an authority of what's a good app. Any other apps automatically are not good in the mind of regular users.

When that app gets access to your Google account to do things on your behalf then this is a perfectly valid strategy. Feel free to not integrate with Google's OAuth system if you don't want to deal with them.

> Feel free to not integrate with Google's OAuth system if you don't want to deal with them

Sorry but that's a bit of an ignorant non-argument. Given the size of Google, I believe that it is important that users can use the apps they want, not the apps that Google wants them to use.

Protectionism does not make using Google's services more secure. It serves Google, not its users.

Re: Google launches new security features to protect users from unverified apps

#28
post #6

Earlier quoted context omitted.

I was wondering how HN would spin this into Evil-Google. It's just tiring at this point. This is a perfectly valid security guard that protects their users.

Where does this attitude stem from anyway?

I think it really started when Google made its ill-spirited push to make everyone use Plus[1]. Before that point, Google was mostly beloved and most users were truly grateful for Google's free products. After that push, many lost YouTube accounts (including me), people who didn't even want to use Plus for chats were pushed to that page as the popular Google Talk app was killed (and then later forcibly moved from plus.google.* to hangouts.google.*).

In a fairly short period of time, people started seeing the same kind of "We're in charge and you're going to use _____ and like it!" attitude that Microsoft was once famous for. People wanted Plus about as much as they wanted Vista, but it got shoved on them anyway.

In more recent years—with AMP pages (and authors on Plus) getting an edge in search, google.com badgering users to install Chrome, a successful embrace->extend->extinguish strategy being executed against open source Android, etc—moves like this one don't look so innocent as they would have coming from the smaller, goofier and cheerier Google of 2005.

1: http://www.businessinsider.com/larry-page-just-tied-employee...

Re: Google launches new security features to protect users from unverified apps

#29
post #16

I'm not sure I'm a fan of the way Google is re-using the Chrome error page styling for this, but I can't put my finger on why exactly...

G-Suite and Chrome are different products, so yes, It's perfectly reasonable to expect them to be separate.

Re: Google launches new security features to protect users from unverified apps

#30

Earlier quoted context omitted.

When that app gets access to your Google account to do things on your behalf then this is a perfectly valid strategy. Feel free to not integrate with Google's OAuth system if you don't want to deal with them.

> Feel free to not integrate with Google's OAuth system if you don't want to deal with them Sorry but that's a bit of an ignorant non-argument. Given the size of Google, I believe that it is important that users can use the apps they want, not the apps that Google wants them to use. Protectionism does not make using Google's services more secure. It serves Google, not its users.

Do you understand what type of apps we are talking about here? It's not Chrome apps. It's not android apps either. It's apps that make use of Google's OAuth connection to do stuff on behalf of the user. So, don't use that if you don't want to deal with the very legitimate security checks.

Again, this is NOT about Android or Chrome apps. So yeah, go use whatever apps you want, as long as it doesn't want the users to grant the developer permission to do stuff with the user's Google account, this does not affect you in the slightest.

Post reply on HN