Live data from Hacker News

Oauth2 support for GMail

pmail.com

111–120 of 136 posts

Re: Oauth2 support for GMail

#111
post #64

Earlier quoted context omitted.

The wording seems to imply that if, on a yearly whim, someone at Google decides to "empanel" a security assessment team, you have no choice, you will not necessarily be asked permission and you will be paying that invoice whether or not you needed that assessment. Do you have evidence - in writing - to the contrary from a Google official? Abridged wording and my non-lawyer interpretation below in case I'm not clear:…

> you will be paying that invoice whether or not you needed that assessment They don't just send you a bill for $10k. You can opt-out of the yearly audit by removing your use of restricted scopes. But yes, it is a yearly required audit, and they're serious about it. This limits the kind of apps that can be built on Gmail (basically – no free apps), but it is undoubtedly better for end users. Having gone through the p…

It's not necessarily better for the users. I'm one of the founders of a free and open source service which simplifies the process of sending CCPA/GDPR data deletion requests. A common request from our users is to give them good recommendation on who to opt out from.

A new compatitor has implemented a feature where they use the Gmail API to analyse a user's email exchange (from their servers) in order to recommend who to opt out from. It's very effective, and even though I would never give a 3rd party access to my email account most people do.

Now we thought of implementing a similar feature, but from the client side (which is a bit less effective but much more privacy respecting). Now I'm not sure from what I read if we need a security audit or not, but the risk and the extra work isn't worth it for us. We're a nonprofit.

Our compatitors on the other hand are a VC backed commercial organization. They make money buy providing a service to the companies they help people opt out of. The whole opt out side is just a way of manufacturing demand, so you can guess where their loyalty lies. But because they are well funded and because sending opt out emails is basically marketing for them, it makes sense for them to pay for an audit.

At the end of the day, the user suffers.

Re: Oauth2 support for GMail

#113
post #64

Earlier quoted context omitted.

> you will be paying that invoice whether or not you needed that assessment They don't just send you a bill for $10k. You can opt-out of the yearly audit by removing your use of restricted scopes. But yes, it is a yearly required audit, and they're serious about it. This limits the kind of apps that can be built on Gmail (basically – no free apps), but it is undoubtedly better for end users. Having gone through the p…

It's not necessarily better for the users. I'm one of the founders of a free and open source service which simplifies the process of sending CCPA/GDPR data deletion requests. A common request from our users is to give them good recommendation on who to opt out from. A new compatitor has implemented a feature where they use the Gmail API to analyse a user's email exchange (from their servers) in order to recommend who…

the user already suffers by "Google" cross-financing all these free things (from search itself to mail, chrome, android, and ... go, k8s, project zero, and who knows what)

and I've added the quotes because of course everyone else does that, and it trains users (and now since everyone is a user it basically conditions society) to have unrealistic expectations, skews what people value, completely fuck up the market (hard to compete with free)

...

that said, in the end the user gets what it wants "opt out", and it's free for them.

Re: Oauth2 support for GMail

#114
post #87

Earlier quoted context omitted.

This isn't true at all. The reason Google does this is that there is a huge ecosystem of random apps that request full access to people's mail accounts, which are the most sensitive accounts on the entire Internet , and many of those apps were hot garbage that generated a huge account takeover problem. It's perfectly fair to not like the policy (I don't like some things about it), but it's not reasonable to caricatur…

You seem to had never gone trough this approval process. There are many dark patterns there: * Asking for huge amount of money in the of the process (after you wasted hundreds of hours of expensive developer time) * forcing to use restricted scope (read,White,delete) for standard IMAP access even if you need only read-only access or use their proprietary API with read-only scope with unknown rate limits and which is…

I am, because reasons, quite familiar with the security review portion of the process. Not only is it mostly/probably not run this way for anticompetitive reasons, but Google doesn't even run the audits; they picked specific auditors (last I checked, Bishop Fox and Leviathan), both of which have gold-plated reputations.

Like I said, there are things I don't love about the program. But it's not an elaborate hazing ritual.

Re: Oauth2 support for GMail

#115
post #64

Earlier quoted context omitted.

> you will be paying that invoice whether or not you needed that assessment They don't just send you a bill for $10k. You can opt-out of the yearly audit by removing your use of restricted scopes. But yes, it is a yearly required audit, and they're serious about it. This limits the kind of apps that can be built on Gmail (basically – no free apps), but it is undoubtedly better for end users. Having gone through the p…

It's not necessarily better for the users. I'm one of the founders of a free and open source service which simplifies the process of sending CCPA/GDPR data deletion requests. A common request from our users is to give them good recommendation on who to opt out from. A new compatitor has implemented a feature where they use the Gmail API to analyse a user's email exchange (from their servers) in order to recommend who…

Why not run the tool clientside? You don’t need an audit unless you’re doing something with the data on your end.

Re: Oauth2 support for GMail

#116

Earlier quoted context omitted.

Google SHOULD NOT promise anything else. This is critical for users security. Yes, developers and business claim they make user data, privacy and security a top priority. As we have seen from plenty of developers on the facebook platform, if not checked, they far to often lie, betray users trust or are just totally incompetent. At least on the business side, giving restricted scopes access (ie, enabling a third party…

Yeah, imagine if users didn't have benevolent Google protecting them, some unscrupulous company full of unethical developers might scan all their personal email, or monitor what websites they visit, or even collect biometric data and then track their every waking movement in the real world.

Let me repeat this very clearly here. HN folks seem to think that developers in the internet at large are "good" and google is evil. Or that things like google asking random developers from china to go through a security assessment is appalling.

I can tell you that for businesses and others spending money (ie, where the business is the customer and not the product) the perspective is opposite this.

A business wants google to track users so logins from unusual locations / devices go through more rigorous authentication. That is considered a benefit, not a harm.

A business wants google to scan everyone's email - for everything from phising to spam to malware. This is considered a benefit not a harm.

I think folks here underestimate just how trusted and core to many individuals and businesses google is. Many folks trust google MORE than they do their own goverment, including on issues of spying on emails and more.

The goverment leaks everything - from photos of dead celebrities to tax returns. Many goverment are active in spying on their users as much as they are able. Around the world, brands like Apple and Google considered evil here on HN, have just insane brand value.

Again, Google are idiots if they were to go the facebook route and not keep the private info they hold pretty secured. The downsides are SO much larger for them (see Cambridge Analytics) than the upsides of allowing random third party internet developers to access someone's email on an ongoing and programmatic way without these types of controls.

Re: Oauth2 support for GMail

#117
post #81
post #21

Users should not be subjecting all of their correspondents' communications to US warrantless surveillance anyway; Google is doing the world a service by making their service harder and harder to interoperate with. Gmail and other huge centralized points of censorship and surveillance must be destroyed. If you are a user, move away. If you are a developer, do not support these closed systems.

Moving your data out of US jurisdiction doesn't shield it from US warrantless surveillance, but rather maximizes its exposure. The USG ostensibly requires due process (a warrant, whatever) to obtain information from US servers. It does not require any due process to obtain data from foreign servers . Coercively obtaining data from foreign servers is literally the chartered job of the NSA (of all signals intelligence…

> The USG ostensibly requires due process (a warrant, whatever) to obtain information from US servers.

This is no longer true, as Ed Snowden showed us. This is literally the point of their secret interpretation of FAA702. Pretending otherwise is nonsensical. The USG, just like the CCP, gets whatever data they want, about anyone, from servers in their own country, without due process.

Anyway, my comment was not about jurisdiction, just about surveillance.

Regardless, Google obviously has the plaintext if you use Gmail. You don't want that, either. The USG will probably only use it for a subset of things; Google has no/few limitations on the use once you voluntarily give them such a huge trove of data about your life, travel, vendors, and purchases.

Re: Oauth2 support for GMail

#118

Earlier quoted context omitted.

The wording seems to imply that if, on a yearly whim, someone at Google decides to "empanel" a security assessment team, you have no choice, you will not necessarily be asked permission and you will be paying that invoice whether or not you needed that assessment. Do you have evidence - in writing - to the contrary from a Google official? Abridged wording and my non-lawyer interpretation below in case I'm not clear:…

Not sure where this is from but there's a critical part of the quote missing here: > Every app that requests access to restricted scope Google user’s data and has the ability to access data from or through a third party server is required to go through a security assessment An email client that only transmits data to/from Google's own IMAP/SMTP servers does not have the ability to access data through any third party…

I intentionally simplified that language to

> [accesses Gmail and also accesses other servers]

... because that's all that convoluted line means. Break it down:

- Access to "restricted scope Google user's data" (in this case, all we care about is Gmail)

- AND ability to access data from or through a third party server.

It's that last bit that people seem to be getting confused about. For example:

- if your app accesses Gmail and Hotmail accounts, then your app is doing both

- if your app accesses Gmail and also checks today's weather, you're doing both

- if your app accesses Gmail and sends basic usage telemetry. Or checks for updates. Or has plugins that provide spam checking or virus scanning... you're probably doing both

- if your app has ANY plugin system, it could be argued that your app is doing both.

While the language may be unclear, "third party server" is probably intended to reference any non-google service.

And my overall point still stands: YOU do not get to decide what triggers their security review. All you have the right to do is pay the bill.

Re: Oauth2 support for GMail

#119
post #105

Earlier quoted context omitted.

What about e-mail clients which allow you to configure multiple accounts at different e-mail providers? Those will be able to access your Gmail data, and also "data from or through third-party servers" in form of receiving or sending e-mail via different mail servers.

Is it not "proxy" like servers they are talking about? You login and the details are stored on a server which does push notifications and the like... instead of your phone polling or pulling email all the time, the proxy server sends a push to the app to update when new mail arrives... is this what they mean?

It certainly includes that, yes. In fact, mobile push notifications is one case that I hadn't even thought of. If you use a third party to perform push notifications, you are "accessing" data through a third party application.

(I'm presuming the word "accessing" is used here to mean any use of a third party server, regardless of whether read or write - because the whole idea is pointless if transmitting is not included in the definition)

It also includes any email client with a built-in VPN, or potentially any client that can use a VPN (remember, it's at Google's discretion)

Re: Oauth2 support for GMail

#120
post #60

Earlier quoted context omitted.

The wording seems to imply that if, on a yearly whim, someone at Google decides to "empanel" a security assessment team, you have no choice, you will not necessarily be asked permission and you will be paying that invoice whether or not you needed that assessment. Do you have evidence - in writing - to the contrary from a Google official? Abridged wording and my non-lawyer interpretation below in case I'm not clear:…

So basically when your application resolves gmail.com you will access other servers. :P

Well, certainly they haven't ruled it out. DNS servers are third-party servers. VPNs are third-party servers. They can be as kind or as nasty about this as they like,

For all my fear mongering, I should point out that the only reason Google are saying this is to cover their backs when they decide to levy the maximum fee on an unsuspecting competitor. If they don't consider you a direct competitor, you might be ok. They have no reason to use this policy to alienate the majority of desktop applications that connect to email.

But they also have no repercussions if they do.

Post reply on HN