Live data from Hacker News

End of the road for Google Drive in Transmit

blog.panic.com

21–30 of 196 posts

Re: End of the road for Google Drive in Transmit

#21

Never hitch your wagon to somebody else's horse. Entire companies have been destroyed because they rely on Amazon, Google, or some other service, and then have the rug pulled. Sometimes companies have even been destroyed, notably by Amazon, for having the wrong political viewpoints. My rule of thumb is: Only use open source components, and only run my stuff on Linux. So that way I maintain full control over my stack,…

Then have the write political viewpoints instead. It seems popular.

Re: End of the road for Google Drive in Transmit

#23

Sounds similar to what iA Writer are going through: https://ia.net/topics/our-android-app-is-frozen-in-carbonite

Sure does. The article even says, on the first screenful of text:

> You may have seen iA Writer’s announcement that they are stopping development of their Android version for similar reasons. Our experience was different, but our circumstances are similar. While Google Drive may not be the most popular connection option in Transmit, we know many users rely on it, and we often use it here at Panic to send and receive files from the game developers we work with.

Re: End of the road for Google Drive in Transmit

#24
I wrote this response to another front page HN article on a similar topic: https://news.ycombinator.com/item?id=41664753

I know everyone loves to dunk on Google, and I definitely agree their communication and customer service to app developers is shite, but this change to permissions scope is a good thing. If you have full, unfettered access to large number of people's Google Drive data, you're a huge target for malevolent actors. If you can't afford the new audit requirements (which I've done and are quite easy - if anything I'm sympathetic to the argument that they're more "box ticking" than valuable security audits), then I'd really question your ability to appropriately safeguard so much critically private data. For reference, these audits are about 1/20th as complicated as a full SOC 2 audit, for example.

FWIW I'm not previously familiar with this Transmit app, but based on their use cases (e.g. backup) it sounds like the limited "drive.file" scope wouldn't work for them. Still, if you want complete, unfettered access to my entire Drive account, I don't think it's a bad thing that Google is enforcing some minimal security standards.

Re: End of the road for Google Drive in Transmit

#25

Man... this stuff sucks. If I were panic, I would do the same... but I also wouldn't want to be the one at google to navigate this. With Google Drive now being at the center of so many companies for storing business data, I am certain it is a juicy target, and third party access with full access to read and write to that big hard drive full of proprietary data is one that I would understand want to lock down... but n…

> With Google Drive now being at the center of so many companies for storing business data, I am certain it is a juicy target, and third party access with full access to read and write to that big hard drive full of proprietary data is one that I would understand want to lock down... but not like this?

Could be a Google Workspace policy where you can just set that employees can't access the corporate Drive account through third party apps, while it continues to work for personal accounts.

Re: End of the road for Google Drive in Transmit

#26

I wrote this response to another front page HN article on a similar topic: https://news.ycombinator.com/item?id=41664753 I know everyone loves to dunk on Google, and I definitely agree their communication and customer service to app developers is shite, but this change to permissions scope is a good thing. If you have full, unfettered access to large number of people's Google Drive data, you're a huge target for male…

> which I've done and are quite easy - if anything

Did you read the part where it took multiple months to continue because of slow replies and non-working tooling from Google's side?

It's also pretty expensive for a relatively niche app, it might be fine if you are Dropbox or a big VC funded Mail app but for smaller companies it's not "easy".

> I don't think it's a bad thing that Google is enforcing some minimal security standards.

How would Google find out if the version that they are "scanning" is the same one that gets uploaded to the app store on every small app update? Zero, so there's no security benefit.

Re: End of the road for Google Drive in Transmit

#27

Never hitch your wagon to somebody else's horse. Entire companies have been destroyed because they rely on Amazon, Google, or some other service, and then have the rug pulled. Sometimes companies have even been destroyed, notably by Amazon, for having the wrong political viewpoints. My rule of thumb is: Only use open source components, and only run my stuff on Linux. So that way I maintain full control over my stack,…

Enjoy the ride https://youtu.be/2mdg9h4HjPw?si=f12DQK1pYt9fILSN

Re: End of the road for Google Drive in Transmit

#28
This is both a curse and an opportunity. Compliance is one of those things that is costly and time-consuming but can lead to entrenchment in certain industries. I worked for a client eons ago that went through the enormous hassle of HIPPA compliance and now it is a bit of a moat for them. Having SOC 2 compliance almost feels like table stakes for b2b SaaS these days.

It does disgust me that Google is going this route. I wonder how much influence is coming from governmental agencies. It is possible they are being forced in some way based on some kind of KYC-like requirements. Or perhaps the volume of bad actors is even higher than I imagine and Google is being forced to do this just to keep the lights on for the API at all. But the fact of the matter is that they are offloading the cost of whatever compliance they need onto their platform users, the people who are spending time and effort to improve the Google ecosystem. It feels petty and short-sighted but I suppose that Google has shifted into an extraction phase on behalf of their investors. We'll probably see a lot more of this kind of nickel and diming from them.

Re: End of the road for Google Drive in Transmit

#29

I wrote this response to another front page HN article on a similar topic: https://news.ycombinator.com/item?id=41664753 I know everyone loves to dunk on Google, and I definitely agree their communication and customer service to app developers is shite, but this change to permissions scope is a good thing. If you have full, unfettered access to large number of people's Google Drive data, you're a huge target for male…

> If you can't afford the new audit requirements ... then I'd really question your ability to appropriately safeguard so much critically private data.

Because large companies that can afford it have proven to be exemplars at safeguarding private data?

Re: End of the road for Google Drive in Transmit

#30

I wrote this response to another front page HN article on a similar topic: https://news.ycombinator.com/item?id=41664753 I know everyone loves to dunk on Google, and I definitely agree their communication and customer service to app developers is shite, but this change to permissions scope is a good thing. If you have full, unfettered access to large number of people's Google Drive data, you're a huge target for male…

I think it's relevant that Transmit is a local native app. There's no hosted app exposed to the internet to hack here. Google made one lengthy process that doesn't fit this use case.
Post reply on HN