Live data from Hacker News

End of the road for Google Drive in Transmit

blog.panic.com

101–110 of 196 posts

Re: End of the road for Google Drive in Transmit

#101
post #97

Earlier quoted context omitted.

This is what everyone said they wanted after Cambridge Analytica! For platforms to exercise due diligence before allowing users to delegate their access to third parties.

Wasn't a significant part of the Cambridge Analytica scandal that Facebook gave them access to user data _without_ the user's consent?

In the same sense that if someone uses a third-party Google Drive client, the input of other collaborators on shared documents is exposed without their consent. (It was data about friends of users who authorized the application in Facebook's case).

Re: End of the road for Google Drive in Transmit

#102
post #97

Earlier quoted context omitted.

This is what everyone said they wanted after Cambridge Analytica! For platforms to exercise due diligence before allowing users to delegate their access to third parties.

Wasn't a significant part of the Cambridge Analytica scandal that Facebook gave them access to user data _without_ the user's consent?

This is a fair thing to point out! I as a user feel I'm being much more respected when I'm allowed to use some independent client software of my choices, than being told that "for my own good" I must use the absolute abomination that is most of the software provided by Big Tech firms themselves. Like, thanks for your opinion, Google, but 90% of these "security audits" are about box checking and ass-covering. It's the technology equivalent of all of the silliest parts of the TSA process, meaning that it contributes nothing to security while employing a lot of people to do valueless work at the expense of those doing useful work.

Re: End of the road for Google Drive in Transmit

#103

Earlier quoted context omitted.

never forget that Old Cloudflare kept lulzsec's site up /while they were defacing .gov pages/, then gave a talk at DEF CON about how they managed it. we can have better standards for speech and platforming than "you didn't moderate enough".

Cloudflare is AWS?

why should pre-2016 cloudflare be the only company with a commitment to free speech and platforming?

Re: End of the road for Google Drive in Transmit

#104
post #51

As per mentioned Ghisler page: "The security assessment would have to be performed by a specialized company, and costs up to $75'000 per year and program (so $150'000 for 32bit+64-bit). This is not sustainable even with a subscription." [0] This is death kiss to indie developement. But paradoxically it is great. Killing interoperability is nail to coffin. This brings more and more focus to alternative solutions out o…

I'm surprised that there isn't more support for just using object storage via a GUI. I would love for as user friendly way to just use Backblaze or some other S3 compatible provider as my drive. Edit: I guess that's sort of exactly what Transmit does, but I want something that is simple enough that anyone can use it.

Transmit is as "easy" as one could imagine software of that type being.

You do have to know what a file is and what a directory is, mind you, which is something I can non-ironically say does rule out half of GenZ or anyone else raised in the postmodern era, where 'content' just lives 'in' an 'app' and can be searched for (and if you're lucky, found). But I don't think people of that minimum level of sophistication are in the market for products like Backblaze or S3 - they're just out there paying for more iCloud storage (or new laptops) because Apple said they are out of space.

Re: End of the road for Google Drive in Transmit

#105

I wrote this response to another front page HN article on a similar topic: https://news.ycombinator.com/item?id=41664753 I know everyone loves to dunk on Google, and I definitely agree their communication and customer service to app developers is shite, but this change to permissions scope is a good thing. If you have full, unfettered access to large number of people's Google Drive data, you're a huge target for male…

This assumes that Google can be trusted with my data and other apps can't, and that I'm ok with Google assessing the safety of other apps. It's something that is automatic, and right now it needs to be explained.

Yes, assessing the trustability of apps is important. No, I don't trust Google to do it properly. Maybe I didn't choose Google because I find them the best, but because I have to (because Google, surprise surprise, forces itself down the throat of everyone, so the people I want to collaborate with use it).

Did my apps certify Google as a trustable provider ?

Re: End of the road for Google Drive in Transmit

#106
post #70
post #51

As per mentioned Ghisler page: "The security assessment would have to be performed by a specialized company, and costs up to $75'000 per year and program (so $150'000 for 32bit+64-bit). This is not sustainable even with a subscription." [0] This is death kiss to indie developement. But paradoxically it is great. Killing interoperability is nail to coffin. This brings more and more focus to alternative solutions out o…

Yep. I use drive but keep waiting for some clear alternative to arrive. My biggest use is just keeping D&D campaign-related materials there. Google is a drag.

WebDAV is pretty easy to configure on all operating systems I'm aware of. You wouldn't even need a third party client.

You can do that self hosted or via fastmail or similar

Re: End of the road for Google Drive in Transmit

#107
post #97

Earlier quoted context omitted.

This is what everyone said they wanted after Cambridge Analytica! For platforms to exercise due diligence before allowing users to delegate their access to third parties.

Wasn't a significant part of the Cambridge Analytica scandal that Facebook gave them access to user data _without_ the user's consent?

IIRC the way Facebook's "platform" stuff worked was that when one user authorized an application, it got to see all their friends' data. Farmville had to be able to access your friends list to see who you could send a sheep to, you see.

Nowerdays this seems like an incredibly dumb idea, sure, and personally I disabled it entirely the moment it came out. But we can cut them some slack, because back in ~2006 facebook was a new thing, for young people - and nobody was sure where this new "social media" thing was going to go.

On top of that I believe Cambridge Analytica did the usual "personality test" trickery where you fill out a survey, then it won't show your result until you hand over your details and accept some legal mumbo-jumbo.

So your Great Uncle wanted to know what harry potter character he was, clicked a consent button, and Cambridge Analytica got your PII.

Re: End of the road for Google Drive in Transmit

#108
post #97

Earlier quoted context omitted.

This is what everyone said they wanted after Cambridge Analytica! For platforms to exercise due diligence before allowing users to delegate their access to third parties.

Wasn't a significant part of the Cambridge Analytica scandal that Facebook gave them access to user data _without_ the user's consent?

Not as far as I know.

Facebook provided a general API for apps, not some kind of data feed. The API required user consent from the app user, though almost certainly not informed consent.

The API also provided too much data, in particular on the user's social graph, which is why a single user giving uninformed consent would lead to data being extracted for multiple others. But even if the app had informed users about intending to steal the social graph, most users would still have consented. They would not have read the text, or not cared. Just click ok until the computer lets you do what you wanted.

So we really do know that the only way to safeguard the data is to design safe scoped APIs for the typical use cases, and keep dangerous unscoped APIs around only as an escape hatch with much stricter security and safety requirements.

Re: End of the road for Google Drive in Transmit

#109
post #51

As per mentioned Ghisler page: "The security assessment would have to be performed by a specialized company, and costs up to $75'000 per year and program (so $150'000 for 32bit+64-bit). This is not sustainable even with a subscription." [0] This is death kiss to indie developement. But paradoxically it is great. Killing interoperability is nail to coffin. This brings more and more focus to alternative solutions out o…

This is what everyone said they wanted after Cambridge Analytica! For platforms to exercise due diligence before allowing users to delegate their access to third parties.

Yes, the situation superficially resembles Cambridge Analytica, but there's a few differences here. People aren't building detailed dossiers of themselves on Google Drive like they were on Facebook, and Transmit is a client app that is honest, open and up-front about how it uses your data - to move it in and out of Google Drive.

To be clear, the problem with Cambridge Analytica was not Cambridge Analytica. The problem was - and still is - Facebook's habit of getting everyone to overshare and self-surveil. There needs to be some control and vetting over the apps that have access to your data but not so much that actually honest developers are quitting the game.

My guess is that Google just doesn't want third-party clients (you can't shove "AI" or "Investor Advertising" into it), so they're slowly turning up the heat by abusing the data scare.

Re: End of the road for Google Drive in Transmit

#110

I wrote this response to another front page HN article on a similar topic: https://news.ycombinator.com/item?id=41664753 I know everyone loves to dunk on Google, and I definitely agree their communication and customer service to app developers is shite, but this change to permissions scope is a good thing. If you have full, unfettered access to large number of people's Google Drive data, you're a huge target for male…

> if you want complete, unfettered access to my entire Drive account,

Panic never got complete or unfettered (or any) access to my Google Drive. I got access. I used their application, which can easily be supervised with Little Snitch or other software to prove that is not sending a copy of my credentials or my files to Panic. If it were OSS it would be even more categorically provable that it's not giving access to anyone but the end user, but these draconian requirements would still apply.

The point is, Google is telling THEIR users, not Panic, that they aren't qualified to use their own judgment to select a client. It woudl be just as bad as Microsoft saying that if you want to check your email or access SharePoint you can't use anything but Edge (insert jokes about how they basically did do that 20 years ago with MSIE, but let's be serious, that sort of thing would be rightfully mocked today).

> I don't think it's a bad thing that Google is enforcing some minimal security standards.

These certification programs are 100% a moneymaking program to engage in a lot of box-checking, which I'd wager has zero correlation with a positive outcome for anyone other than the shareholders of the "labs" that do these audits.

Post reply on HN