Live data from Hacker News

Oauth2 support for GMail

pmail.com

131–136 of 136 posts

Re: Oauth2 support for GMail

#131
post #50

Is gmail removing IMAP too? Why support OAUTH at all when you can use the normal method of logging in with IMAP and an app password?

They are likely removing IMAP. IMAP support is already disabled by default in Gmail

If that happens, it sounds like a good chance to move away from gmail to something more robust.

Re: Oauth2 support for GMail

#132
post #115

Earlier quoted context omitted.

Why not run the tool clientside? You don’t need an audit unless you’re doing something with the data on your end.

Are you sure about this?

Yeah, it’s what I was told by a member of the verification team last year (as long as everything is clientside, you can bypass the audit). Before you build anything you should request the restricted scopes in Google’s Cloud Console as if the feature is already built, to kick off the verification process. Then you can ask a human for clarification (IIRC the exemption isn’t mentioned in the FAQ). Assuming it’s okay, you can then build the feature and resubmit your request. Best of luck!

Re: Oauth2 support for GMail

#133
post #64

Earlier quoted context omitted.

> you will be paying that invoice whether or not you needed that assessment They don't just send you a bill for $10k. You can opt-out of the yearly audit by removing your use of restricted scopes. But yes, it is a yearly required audit, and they're serious about it. This limits the kind of apps that can be built on Gmail (basically – no free apps), but it is undoubtedly better for end users. Having gone through the p…

The context here is Free and Open Source Software that accesses email. Software that, for now, under Google's current interpretation of the rules, is allowed to use their OAuth without paying these fees. The question I'm asking is, what happens next year when Google decides to silently change their interpretation of the rules? Do you, as a FOSS email client writer working on JohnnyMail, risk a massive yearly bill of…

This isn’t about profit. Google doesn’t want to pay for security audits. You pay the auditor directly.

I suppose Google could charge for future access. Any platform could. But not retroactively. That would need to be in a contract and it’s not.

Re: Oauth2 support for GMail

#134
post #123
post #62

Earlier quoted context omitted.

Legacy. For example, my email is in Google. There are things related to e.g. evidence for litigation from many years back. I have documents shared with me in Google Docs. Google used to be pretty good about "don't do evil." I've degooglified what I can, but I can't degooglify 100%.

It's never too late to switch.

It kind of is. If I want to have legal proof of when I shared a document with someone, I need my Google Docs.

I guess what I should do is stop putting new stuff in Google.

Re: Oauth2 support for GMail

#135
post #30

I believe many comments here will criticize Google. But objectively, Google is at its best here: - in terms of privacy, applications that have access to your Gmail inbox now require a security audit. - the audit is not required for MVP ( Of course, you have to pay for the audit. But: - it’s only required when you ask for restricted user data (i.e. reading my emails). - Google doesn’t take 30% of your revenue to use i…

Is it my inbox or Google's inbox?

It is part of Google's tracking and advertising system. They let you use it as an inbox.

Re: Oauth2 support for GMail

#136
post #117

Earlier quoted context omitted.

> The USG ostensibly requires due process (a warrant, whatever) to obtain information from US servers. This is no longer true, as Ed Snowden showed us. This is literally the point of their secret interpretation of FAA702. Pretending otherwise is nonsensical. The USG, just like the CCP, gets whatever data they want, about anyone, from servers in their own country, without due process. Anyway, my comment was not about…

I don't think you're totally following the logic. Stipulate that whatever legal process there is in the US for NSA (or any other intelligence agency) to get data is performative and easily bypassed. There is no legal process whatsoever for NSA to obtain that data from foreign targets. If you're worried about the Five Eyes SIGINT agencies, "foreign" servers are strictly less safe.

Foreign servers don't have an API for NSA to download a zip file of your account data without a human being in the loop, like Google does for FAA702.

There's also the issue where Google itself is mass surveillance.

Post reply on HN