Live data from Hacker News

Oauth2 support for GMail

pmail.com

31–40 of 136 posts

Re: Oauth2 support for GMail

#31

I am wondering if it is really legal for Google to even ask any money from 3rd party developers to use GMAIL (what should be) open standards like SMTP and IMAP. I guess I am so naive...

It might be immoral, but if you're trying to make money using their service I can't see there being a legal reason to prevent them doing this. I meant, they (Google) need the money right? Companies like this seem to get to the point where they feel justified in charging for every little thing that wouldn't kill them to give for free.

If you're in the EU:

https://en.m.wikipedia.org/wiki/Antitrust_cases_against_Goog...

Re: Oauth2 support for GMail

#32
Went through this process with Mail Designer 365. Luckily as we only need sending access, the requirement was less arduous, but the process was not great.

After submitting it took ages to get reviewed and even when it had been processed the status wasn't entirely clear.

At the time it was made clear that using app passwords was considered a risk and users were receiving emails about it being a security risk.

Re: Oauth2 support for GMail

#33
post #30

I believe many comments here will criticize Google. But objectively, Google is at its best here: - in terms of privacy, applications that have access to your Gmail inbox now require a security audit. - the audit is not required for MVP ( Of course, you have to pay for the audit. But: - it’s only required when you ask for restricted user data (i.e. reading my emails). - Google doesn’t take 30% of your revenue to use i…

Is it my inbox or Google's inbox?

Is it your car or the government’s?

Re: Oauth2 support for GMail

#34
post #21

Users should not be subjecting all of their correspondents' communications to US warrantless surveillance anyway; Google is doing the world a service by making their service harder and harder to interoperate with. Gmail and other huge centralized points of censorship and surveillance must be destroyed. If you are a user, move away. If you are a developer, do not support these closed systems.

I agree wholeheartedly in principle, but the reality is that it's nearly impossible to escape Google getting their hands on yours and your correspondents' messages at some point. So many businesses (and third party email providers!) use Google's services on the back end, and many relays out there are owned by Google/Alphabet even if it's not readily apparent, that the only way to even attempt to avoid them is using encrypted email. Unless everyone you communicate with (including companies, governments, and other organizations) is willing to only communicate via encrypted email as well, it's a lost cause.

Re: Oauth2 support for GMail

#35
post #30

I believe many comments here will criticize Google. But objectively, Google is at its best here: - in terms of privacy, applications that have access to your Gmail inbox now require a security audit. - the audit is not required for MVP ( Of course, you have to pay for the audit. But: - it’s only required when you ask for restricted user data (i.e. reading my emails). - Google doesn’t take 30% of your revenue to use i…

Is it my inbox or Google's inbox?

Google will be blamed if someone's data is misused even if that person authorized giving permissions to that app. If you want evidence supporting that, take a look at how much flak Facebook received with the Cambridge Analytica scandal.

Re: Oauth2 support for GMail

#36

I believe many comments here will criticize Google. But objectively, Google is at its best here: - in terms of privacy, applications that have access to your Gmail inbox now require a security audit. - the audit is not required for MVP ( Of course, you have to pay for the audit. But: - it’s only required when you ask for restricted user data (i.e. reading my emails). - Google doesn’t take 30% of your revenue to use i…

If you want to create a video, you’re one of the 17 developers in the world that does.

Your criticism was completely unnecessary. It doesn’t say anything about the Pegasus dev except that he’s normal.

Re: Oauth2 support for GMail

#37
post #21

Users should not be subjecting all of their correspondents' communications to US warrantless surveillance anyway; Google is doing the world a service by making their service harder and harder to interoperate with. Gmail and other huge centralized points of censorship and surveillance must be destroyed. If you are a user, move away. If you are a developer, do not support these closed systems.

I agree wholeheartedly in principle, but the reality is that it's nearly impossible to escape Google getting their hands on yours and your correspondents' messages at some point. So many businesses (and third party email providers!) use Google's services on the back end, and many relays out there are owned by Google/Alphabet even if it's not readily apparent, that the only way to even attempt to avoid them is using e…

No, the perfect is the enemy of the good here. "Email is insecure anyway and Google is big, therefore it's ok to give the adversary 100% of the plaintext" is not sound logic.

This is not some principled stance, it is a clear and practical command: stop using these services.

If your personal email address ends in @gmail.com, you are doing it wrong.

Re: Oauth2 support for GMail

#38
post #9

Once again, i'm glad not to be using GMail.

Yep. All these anti-google complaints sound so useless. What did they expect? These issues are always an entirely self-inflicted problem. Google's terms of service are public, clear, and completely unacceptable. Why people keep using their services is beyond me.

Re: Oauth2 support for GMail

#40
There's a bunch of third party "indie" email apps, how are they doing it? Is this potentially just some boilerplate text and they evaluate the rate based on the size of the project in the end?

I'm currently using https://mimestream.com/ and I somehow doubt all of them had to pay that kind of upfront money.

Post reply on HN