why should pre-2016 cloudflare be the only company with a commitment to free speech and platforming?
I read up on that situation, and it sounded like the three letter agencies were working with Cloudflare all along. They never even asked them nicely to stop hosting lulzsec. To top it off, Sabu from lulzsec was an informer[1].
So Cloudflare wasn't bravely standing on principle, they were just doing garden variety collaboration with the feds.
I am not sure smaller devs were given the option of self-scanning code. I always wondered what the point of that was, given that there is no way for Google to ensure that the scanned code was the version distributed, and even then, as soon as a minor update was released it would have been out of date.
Because they don't care about security, it's compliance-checkbox-driven policies.
Bingo! The whole thing is for butt-covering purposes. It's just so that when something happens, Google can then say "We followed $STANDARDS_BODY Policy #420.69, so we can't be held responsible!" Theoretically even Panic would gain a little butt-covering from it too. "Look, this vulnerability was so hard to spot that even these very professional security auditors missed it 8 years in a row!"
If you read the article, they went through the casa audit, found that it did not improve the security of their app, and came to the conclusion it wasn't worth the time and now money to do it a second time.
> and came to the conclusion it wasn't worth the time and now money to do it a second time. Especially because they'd now have to go through an other third-party to perform the audit process (not just the security lab, the entire thing), according to the total commander folks[1] that's 75k/year/program. [1] https://www.ghisler.com/googledrivehelp.htm
They say it's "up to 75,000" per program, looking at the actual assessor websites, most require quotes, but tier 2 assessments start at $500 and tier 3 start at $5-6000, and you're in the land of asking for quotes from companies, so "hey we compile the same code into 32 and 64 bit versions" probably does not actually require a 2x cost increase.
I don't use Google Drive and probably never will but FWIW Transmit is still one of the best all-around data transfer apps that exist. I always miss it when I am on my Linux workstation. Being able to quickly connect to an S3 bucket and dump files and edit their permissions is a huge plus. Not to mention basic SFTP access like Cyberduck or Filezilla would do. I have never regretted my purchase of Transmit, it's great!
Same. I used to pirate it back when Serial Box was a thing and I was a broke college kid, and I've been licensed since growing up. An essential tool. I would say it should be built into the OS, but that's a joke since modern-day Microsoft and Apple could never provide such a useful tool without sanding everything down to a smooth minimalist surface with no discoverability.
This is what everyone said they wanted after Cambridge Analytica! For platforms to exercise due diligence before allowing users to delegate their access to third parties.
Wasn't a significant part of the Cambridge Analytica scandal that Facebook gave them access to user data _without_ the user's consent?
Facebook users shared data with their friends. Those friends gave access to the data to CA. So like if you share a document with me and I then give CA access to my GDrive.
> But then… a couple of months later, Google completely removed the option for us to scan our own code. Instead, to keep access to Google Drive, we would now have to pay one of Google’s business partners to conduct the review. What a racket. Smells downright anti-competitive The EU will have fun with this when it catches up.
The EU absolutely loves adding requirements for certifications, so no I don't think they would get involved here. In fact, it's something they are pushing for in general.
Never hitch your wagon to somebody else's horse. Entire companies have been destroyed because they rely on Amazon, Google, or some other service, and then have the rug pulled. Sometimes companies have even been destroyed, notably by Amazon, for having the wrong political viewpoints. My rule of thumb is: Only use open source components, and only run my stuff on Linux. So that way I maintain full control over my stack,…
> Sometimes companies have even been destroyed, notably by Amazon, for having the wrong political viewpoints. Ok, I'll ask: what company did Amazon destroy for having the wrong political viewpoint? AWS hosts some pretty vile stuff without blinking. The last time a company made a big "woe is me, my ideas are being suppressed" claim against Amazon, it was Parler, and they weren't kicked off for their viewpoints. They w…
Not too long after Parler was kicked off AWS, I was on a call with hundreds of representatives from power utilities about a modeling tool we were transitioning to. It was mentioned that the tool was hosted on AWS and someone suggested they have a fallback plan in case they got kicked off like "other companies".
This is what everyone said they wanted after Cambridge Analytica! For platforms to exercise due diligence before allowing users to delegate their access to third parties.
Yes, the situation superficially resembles Cambridge Analytica, but there's a few differences here. People aren't building detailed dossiers of themselves on Google Drive like they were on Facebook, and Transmit is a client app that is honest, open and up-front about how it uses your data - to move it in and out of Google Drive. To be clear, the problem with Cambridge Analytica was not Cambridge Analytica. The proble…
A lot of people will have substantially more sensitive data in their chosen cloud storage system (whether Drive, DropBox, OneDrive, iCloud) than on Facebook or any other social network. For example documents like ID scans, financial records, and medical records are going to be commonplace.
Having recently had an infuriating experience with an Android app submission, it seems there's a horde of people in a similar jam, running the senseless bureaucratic review process gauntlet: https://www.reddit.com/r/androiddev/comments/1ck1wyp/did_goo...
They quickly kicked off WikiLeaks under political pressure.
AWS’s stated reasons seem pretty sound to me: https://aws.amazon.com/message/65348/
Okay, so what? That you agree with the political motivation behind the decision does not make the decision any less politically motivated, proving that AWS does in fact kick out consumers based on politics.