Live data from Hacker News

Oauth2 support for GMail

pmail.com

121–130 of 136 posts

Re: Oauth2 support for GMail

#121
post #64

Earlier quoted context omitted.

The wording seems to imply that if, on a yearly whim, someone at Google decides to "empanel" a security assessment team, you have no choice, you will not necessarily be asked permission and you will be paying that invoice whether or not you needed that assessment. Do you have evidence - in writing - to the contrary from a Google official? Abridged wording and my non-lawyer interpretation below in case I'm not clear:…

> you will be paying that invoice whether or not you needed that assessment They don't just send you a bill for $10k. You can opt-out of the yearly audit by removing your use of restricted scopes. But yes, it is a yearly required audit, and they're serious about it. This limits the kind of apps that can be built on Gmail (basically – no free apps), but it is undoubtedly better for end users. Having gone through the p…

The context here is Free and Open Source Software that accesses email.

Software that, for now, under Google's current interpretation of the rules, is allowed to use their OAuth without paying these fees.

The question I'm asking is, what happens next year when Google decides to silently change their interpretation of the rules? Do you, as a FOSS email client writer working on JohnnyMail, risk a massive yearly bill of 1/6th or more of your salary that you are contractually obliged to pay - or just say "Sorry Google, you've outpriced me" while their interpretations are still favourable?

It's not "undoubtedly better for end users" that free email apps be excluded from Gmail. It's not better for end users that open source software developers are given a sword of Damocles hovering above their heads. Sure, it's undoubtedly better if these free apps can be guaranteed to be secure, it would be even better if Google could do that in a way that didn't cost a massive amount or a surprise bill.

I'm glad you had the resources to be able to go through the process, and that you found it a useful process to go through. But it doesn't justify the uncertainty.

Re: Oauth2 support for GMail

#122
post #81
post #21

Users should not be subjecting all of their correspondents' communications to US warrantless surveillance anyway; Google is doing the world a service by making their service harder and harder to interoperate with. Gmail and other huge centralized points of censorship and surveillance must be destroyed. If you are a user, move away. If you are a developer, do not support these closed systems.

Moving your data out of US jurisdiction doesn't shield it from US warrantless surveillance, but rather maximizes its exposure. The USG ostensibly requires due process (a warrant, whatever) to obtain information from US servers. It does not require any due process to obtain data from foreign servers . Coercively obtaining data from foreign servers is literally the chartered job of the NSA (of all signals intelligence…

Do you honestly think that using Gmail protects me from the NSA? If the NSA wants into my computer, it's in.

Secret services swap their data, so they can all read my santa letters.

There is the viewpoint that one should prefer one's own jurisdiction regarding storing data (I know you don't like Schneier but he e.g. holds that viewpoint).

I use an email provider from my country. If a judge from my country wants to persecute me, they have to complete a legal request which is tested by my provider.

If I used an email provider from Switzerland or the US, is that also the case?

Also, it's important to think of the economical aspect. If i financially support providers in my home country that lobby for better privacy laws and don't engage in surveillance capitalism like Google does, isn't that creating a good alternative that can also be properly regulated?

Plus, it's one dependency less from a (more than) half MAGA country.

So your recommendation makes sense if you are a citizen of the USA, but not everyone here is.

Addendum: what do you actually mean by "security"? For me, that is also "being able to access my email account whenever I want" and that this account doesn't get closed, even if I do shit on the internet, whoever that decides. Google shouldn't have the right to say "these actions are uncool so let's kick this guy" (never happened to me, but I don't even have a contract with Google!, they have the right to cancel my account whenever they want.).

Re: Oauth2 support for GMail

#123
post #62

Earlier quoted context omitted.

Yep. All these anti-google complaints sound so useless. What did they expect? These issues are always an entirely self-inflicted problem. Google's terms of service are public, clear, and completely unacceptable. Why people keep using their services is beyond me.

Legacy. For example, my email is in Google. There are things related to e.g. evidence for litigation from many years back. I have documents shared with me in Google Docs. Google used to be pretty good about "don't do evil." I've degooglified what I can, but I can't degooglify 100%.

It's never too late to switch.

Re: Oauth2 support for GMail

#124
post #115

Earlier quoted context omitted.

It's not necessarily better for the users. I'm one of the founders of a free and open source service which simplifies the process of sending CCPA/GDPR data deletion requests. A common request from our users is to give them good recommendation on who to opt out from. A new compatitor has implemented a feature where they use the Gmail API to analyse a user's email exchange (from their servers) in order to recommend who…

Why not run the tool clientside? You don’t need an audit unless you’re doing something with the data on your end.

Are you sure about this?

Re: Oauth2 support for GMail

#126
post #117
post #81

Earlier quoted context omitted.

Moving your data out of US jurisdiction doesn't shield it from US warrantless surveillance, but rather maximizes its exposure. The USG ostensibly requires due process (a warrant, whatever) to obtain information from US servers. It does not require any due process to obtain data from foreign servers . Coercively obtaining data from foreign servers is literally the chartered job of the NSA (of all signals intelligence…

> The USG ostensibly requires due process (a warrant, whatever) to obtain information from US servers. This is no longer true, as Ed Snowden showed us. This is literally the point of their secret interpretation of FAA702. Pretending otherwise is nonsensical. The USG, just like the CCP, gets whatever data they want, about anyone, from servers in their own country, without due process. Anyway, my comment was not about…

I don't think you're totally following the logic. Stipulate that whatever legal process there is in the US for NSA (or any other intelligence agency) to get data is performative and easily bypassed. There is no legal process whatsoever for NSA to obtain that data from foreign targets. If you're worried about the Five Eyes SIGINT agencies, "foreign" servers are strictly less safe.

Re: Oauth2 support for GMail

#127
post #9

Once again, i'm glad not to be using GMail.

Yep. All these anti-google complaints sound so useless. What did they expect? These issues are always an entirely self-inflicted problem. Google's terms of service are public, clear, and completely unacceptable. Why people keep using their services is beyond me.

It's not easy to convince everyone to send mail to your new address. Especially the countless random websites where you signed up with the old one.

Re: Oauth2 support for GMail

#128

Earlier quoted context omitted.

Yeah, imagine if users didn't have benevolent Google protecting them, some unscrupulous company full of unethical developers might scan all their personal email, or monitor what websites they visit, or even collect biometric data and then track their every waking movement in the real world.

Let me repeat this very clearly here. HN folks seem to think that developers in the internet at large are "good" and google is evil. Or that things like google asking random developers from china to go through a security assessment is appalling. I can tell you that for businesses and others spending money (ie, where the business is the customer and not the product) the perspective is opposite this. A business wants g…

Yes, obviously business are happy to fob off liability to Google (right up until Big G closes their account and kills their business). What's your point? That businesses don't have users' interests at heart? Next you'll tell us the tooth fairy isn't real.

The point isn't that Google is evil and random devs are good. The point is that Google is amoral and harmful - and also enormous and powerful. Random small developers may be good, bad, whatever, but they are diverse and individually powerless. Should you be more afraid of the Stasi or of a neighborhood burglar?

Re: Oauth2 support for GMail

#129

I have one question in this regard: will I still be able to access my mail through my own script I myself wrote? I understand I will probably have to make some changes and click some things in GMail settings but is this still going to be possible or will I too have to "publish app" even if I only mean it for my own private usage?

Development apps are exempt from the requirement. (They are also limited to 100 accounts)

But i find the token problem frequently. It seems it expires after 2-3 days. I don't know why :(

Re: Oauth2 support for GMail

#130

I'm sympathetic to the extremely legitimate security concerns here, but it's pretty rich for the "open, we're so open" company to be running a classic 90s Microsoft Embrace Extend Extinguish playbook on SMTP/IMAP which, for all its faults, is one of the more important open protocols undergirding the internet.

you can use SMTP to access GMail and auth via a web browser based flow (OAuth2/OIDC), this added extra security is needed if there's an additional server in the mix that manages the OIDC tokens for the user

> https://news.ycombinator.com/item?id=31421066

Post reply on HN