Live data from Hacker News

End of the road for Google Drive in Transmit

blog.panic.com

151–160 of 196 posts

Re: End of the road for Google Drive in Transmit

#151

Earlier quoted context omitted.

None of that is evidence conservatives aren't under attack, it's evidence that we're winning the culture war. About Musk, once he took over Twitter, that mostly solved the Social Media "Free Speech" problem, because as long as the most popular gathering place in the world is free we're [mostly] all free. So you're right, there's lots of reasons for Conservative optimism.

> None of that is evidence conservatives aren't under attack, it's evidence that we're winning the culture war. None of those businesses are part of the culture war, or if anything they're 'woke' businesses. Thiel doesn't make money being conservative, he makes money on venture capital and running a big government surveillance business. Larry Ellison makes money price gouging on licensing. Elon Musk's main source of…

I wasn't classifying those businesses as "part of culture war" or not. I'm just saying it's a fact that conservatives have been, and still are, under attack, and are nonetheless "winning".

Insofar as Musk not being a Free Speech Absolutist (which I'm not either), that's not news to me or anyone else who knows and respects him like I do. Musk is doing everything he can to keep legal speech from being censored, whereas the prior owners would cancel people permanently for trite trivial things like a mis-gendering (that wasn't even done out of malice), or simply claiming there's two genders.

Regarding Democrats getting censored themselves: While I'm a strong advocate of Free Speech as a general rule, I think after what the Democrats did for a decade (on censorship) they SHOULD be forced to reap what they sowed. So for example, I would've been perfectly in favor of Musk, as a one time act, permanently cancelling everyone who had in the past called for censorship of others. Those people didn't want Free Speech when they held power, and thus they are the ones who don't deserve to have Free Speech after they've lost their power.

Re: End of the road for Google Drive in Transmit

#152
post #5

> But then… a couple of months later, Google completely removed the option for us to scan our own code. Instead, to keep access to Google Drive, we would now have to pay one of Google’s business partners to conduct the review. What a racket. Smells downright anti-competitive The EU will have fun with this when it catches up.

> The EU will have fun with this when it catches up.

I don't think you know how the EU works.

Re: End of the road for Google Drive in Transmit

#153
post #10

Even the "audit" they require for increasing something simple as your YouTube API quota is already annoying and a massive waste of time, and this is not even close to the one they are requiring from Panic. The quota increase process is roughly: 1) Fill out the same form every year from scratch 2) Send it into the black hole that's Google "support" 3) A few weeks later receive a reply from someone asking a irrelevant…

Any tier of Google Support is 100% a black hole. I had an extremely unusual issue with a service in Google Cloud, tried to debug it and failed. I filed a ticket and waited because P1 was only for “production” issues, but our issue was for development.

A few days later, the Google engineer assigned notes to us that we can escalate to P1 if this is blocking our workflow, even when not in production. I take this to my manager and they agree that it’s time to move it to P1.

We move it to P1 and immediately get traction, only to be stonewalled by a support engineer confidently asserting that the code throwing the error, which only existed in a private Google-maintained container, which only interfaced with our app through launching a cloud job through their platform, was actually our responsibility.

No joke, they actually said “As stated in my prior message, this issue is due to your code”, despite our code being a thin wrapper around their demonstration code to run it from the command line.

In my most business professional tone, I tell them off for lying to us about them debugging on their end and inform them that I will be immediately escalating because of this dissatisfactory response. This finally gets the ticket moving and a few weeks later, a bug fixed version of the entire platform is deployed.

Total time from start to finish:

- P2: 2.5 weeks of daily updates - P1, until we’re told that it’s our fault: 8 hours - P1 escalated until issue was completely fixed: 5 weeks

We paid for premium support. I cannot imagine how bad free support is.

Re: End of the road for Google Drive in Transmit

#154

Earlier quoted context omitted.

>It’s clear that WikiLeaks doesn’t own or otherwise control all the rights to this classified content. Further, it is not credible that the extraordinary volume of 250,000 classified documents that WikiLeaks is publishing could have been carefully redacted in such a way as to ensure that they weren’t putting innocent people in jeopardy. You can be obtuse about it if you want, but this is basically what it means. The…

“Human rights groups have asked Wikileaks many times to do more to censor information found in documents. They fear reprisals against aid workers, activists and civilians named in the leaked data.” https://www.bbc.com/news/technology-37165230.amp

Okay? They didn't ask AWS to pull down the entire website though

And again, AWS cited the fact that the documents were classified as being one of the reasons for the termination. You can't get more political than that. Especially when AWS does not care about it when it happens in other countries.

Re: End of the road for Google Drive in Transmit

#155

Earlier quoted context omitted.

“Human rights groups have asked Wikileaks many times to do more to censor information found in documents. They fear reprisals against aid workers, activists and civilians named in the leaked data.” https://www.bbc.com/news/technology-37165230.amp

Okay? They didn't ask AWS to pull down the entire website though And again, AWS cited the fact that the documents were classified as being one of the reasons for the termination. You can't get more political than that. Especially when AWS does not care about it when it happens in other countries.

I’m coming to the conclusion that you and I have fundamentally different definitions of the word “political.” That’s fine.

Re: End of the road for Google Drive in Transmit

#156
post #51

As per mentioned Ghisler page: "The security assessment would have to be performed by a specialized company, and costs up to $75'000 per year and program (so $150'000 for 32bit+64-bit). This is not sustainable even with a subscription." [0] This is death kiss to indie developement. But paradoxically it is great. Killing interoperability is nail to coffin. This brings more and more focus to alternative solutions out o…

There is some massive confusion around the types and costs of audits required for full Drive permissions scope (and I definitely blame Google for the lack of communication/direction on this). I had to get this audit for an app and it was nowhere near 75k - I believe it was well under 10k. Another commenter said they had it done for $4k: https://news.ycombinator.com/item?id=41781325

That still sucks and is prohibitive for indie developers. As the post mentions, in reality this program adds very little value for any of the involved parties.

Re: End of the road for Google Drive in Transmit

#157
post #93

Earlier quoted context omitted.

The problem with Google’s security certifications, especially when compared to competitors like Salesforce and Microsoft, is how disorganized the process is. While these companies all require security reviews, Google’s approach seems particularly disorganized: if something goes wrong, there’s almost no one to contact for help. The certifications themselves are valuable, but Google’s main issue lies in its poor commun…

100% agree. Again, my position is that Google rightfully deserves all the criticism they get around communication and customer support. I just think it's a mistake to confuse that criticism with Google's change to enforce better security for highly sensitive permission scopes.

Probably not news to you, but those are completely different departments within the company with opposing goals.

Re: End of the road for Google Drive in Transmit

#158
post #87

Earlier quoted context omitted.

Google's not my dad. It's not their responsibility (or their place) to audit every piece of software I use to interact with their services. I'm tired of being treated like a child who needs every sharp corner ground down for my safety. Edit: Next logical step is auditing every IMAP client before you can connect it to Gmail. Ridiculous.

They're the ones who will take the blame when a third-party app gets compromised and is used to siphon off people's data. This isn't a theoretical concern. It's pretty much exactly what happened with Cambridge Analytica. Facebook didn't really do anything wrong; they provided an API for data access, people explicitly authorized an app with broad access their data, and it turned out that the app was basically a trojan…

You're leaving out a very important part of the Cambridge Analytica story, which is "transitive permissions". "Normal" people think of transitive permissions very different from computer science folks.

That is, the vast majority of people whose data was sucked up by Cambridge Analytica did not explicitly authorize the app. Instead, their friends did, and at the time authorizing a third party app meant the app got to see everything you did, including all of the data about your friends. Now, you may argue that if you share your data with your friends that you're then at the mercy of whoever they give this data to, but I guarantee very few people at the time understood this - saying "I authorize Bob to see my FB data" is different, in most people's minds, to saying "I authorize Bob to see my data, and also any random app that can convince Bob into giving them access." Facebook was rightly pilloried for this permissions model.

Re: End of the road for Google Drive in Transmit

#159

Earlier quoted context omitted.

Okay? They didn't ask AWS to pull down the entire website though And again, AWS cited the fact that the documents were classified as being one of the reasons for the termination. You can't get more political than that. Especially when AWS does not care about it when it happens in other countries.

I’m coming to the conclusion that you and I have fundamentally different definitions of the word “political.” That’s fine.

I think so too, though I usually don't have a broad "everything is political" position so I'm usually on the opposite end of this type of conversation haha. But I see what you mean, it wasn't anything related to partisan politics or culture wars.

Re: End of the road for Google Drive in Transmit

#160
post #105

I wrote this response to another front page HN article on a similar topic: https://news.ycombinator.com/item?id=41664753 I know everyone loves to dunk on Google, and I definitely agree their communication and customer service to app developers is shite, but this change to permissions scope is a good thing. If you have full, unfettered access to large number of people's Google Drive data, you're a huge target for male…

This assumes that Google can be trusted with my data and other apps can't, and that I'm ok with Google assessing the safety of other apps. It's something that is automatic, and right now it needs to be explained. Yes, assessing the trustability of apps is important. No, I don't trust Google to do it properly. Maybe I didn't choose Google because I find them the best, but because I have to (because Google, surprise su…

That makes no sense - if you don't trust Google Drive, don't use it.

Google is not "forcing itself down the throat" with Google Drive, and even my Android phone comes with 3 cloud providers.

And yes, your apps certified Google as a trustable provider when they added support for it. Such support is not automatic, it requires non-trivial effort, and presumable no one would do it for services they do not trust.

Post reply on HN