Live data from Hacker News

End of the road for Google Drive in Transmit

blog.panic.com

171–180 of 196 posts

Re: End of the road for Google Drive in Transmit

#171
post #105

Earlier quoted context omitted.

This assumes that Google can be trusted with my data and other apps can't, and that I'm ok with Google assessing the safety of other apps. It's something that is automatic, and right now it needs to be explained. Yes, assessing the trustability of apps is important. No, I don't trust Google to do it properly. Maybe I didn't choose Google because I find them the best, but because I have to (because Google, surprise su…

If you don't trust Google, why are you using Drive in the first place?

Quoting the message you replied to:

> the people I want to collaborate with use it

If I were an independent individual who didn't need any others, then it might be a decision I can make. That's the neo-liberal lie you are driven to believe. But we're always part of a society and can't exist without society. Some of the information I want to read has been elaborated and written for years in Google Drive. Some of the people who want to share stuff with me will only use Google Drive. Of course I do all my best to migrate them away, but it only works that much.

Re: End of the road for Google Drive in Transmit

#172
post #55

I wrote this response to another front page HN article on a similar topic: https://news.ycombinator.com/item?id=41664753 I know everyone loves to dunk on Google, and I definitely agree their communication and customer service to app developers is shite, but this change to permissions scope is a good thing. If you have full, unfettered access to large number of people's Google Drive data, you're a huge target for male…

That seems like a poor argument for an app which doesn’t mirror data or accept commands remotely (if I can control your app on your device, I can control the official Google Drive app) but there is a general point about full drive access. However, I think the answer there is for Google to improve the security model for Drive - for example, allow the user to select a non-root folder which Transmit or iA Writer can use…

How do you know it doesn't mirror data or accept commands remotely, or that it has no vulnerabilities/backdoors which can make it do so? Perhaps you could do an audit of it or something...

Re: End of the road for Google Drive in Transmit

#173
post #160
post #105

Earlier quoted context omitted.

This assumes that Google can be trusted with my data and other apps can't, and that I'm ok with Google assessing the safety of other apps. It's something that is automatic, and right now it needs to be explained. Yes, assessing the trustability of apps is important. No, I don't trust Google to do it properly. Maybe I didn't choose Google because I find them the best, but because I have to (because Google, surprise su…

That makes no sense - if you don't trust Google Drive, don't use it. Google is not "forcing itself down the throat" with Google Drive, and even my Android phone comes with 3 cloud providers. And yes, your apps certified Google as a trustable provider when they added support for it. Such support is not automatic, it requires non-trivial effort, and presumable no one would do it for services they do not trust.

> And yes, your apps certified Google as a trustable provider when they added support for it. Such support is not automatic, it requires non-trivial effort

Are you talking about the technical support (ie implementing APIs) or the bureaucratic support (ie going through Google's process) ? Because the first one is a result of Google going its own way with its own protocol, and the second is entirely a decision of Google.

> and presumable no one would do it for services they do not trust.

No, they would not do it for a service that is vital for the sustainability of their app. When Google is so hegemonic it's sometimes impossible to avoid, app developers must consider whether Google's ways are worth implementing not just based on Google but on the users' willing to make do with an app that doesn't work with Google. Not being compatible with Google is more often than not seen as a problem with the app, not with Google.

Re: End of the road for Google Drive in Transmit

#174

Earlier quoted context omitted.

If they are connecting to Google Drive, is that not connected to the internet?

Everything's connected to the internet, what the OP was talking about was attack vectors and since Transmit is a local app it really isn't one unless your whole machine is compromised, which in that case you're screwed.

There are lots of ways a local app can be compromised. It can read a local config value unsafely which can be influenced by some other app that does talk to the Internet, for example.

There's a reason why airgapping is the only way to secure important systems (and of course that can also have a number of vulnerabilities).

And besides, how do you know it's a local only app if you haven't audited it?

"Just trust me bro" -- some dev

Re: End of the road for Google Drive in Transmit

#175
post #55

Earlier quoted context omitted.

That seems like a poor argument for an app which doesn’t mirror data or accept commands remotely (if I can control your app on your device, I can control the official Google Drive app) but there is a general point about full drive access. However, I think the answer there is for Google to improve the security model for Drive - for example, allow the user to select a non-root folder which Transmit or iA Writer can use…

How do you know it doesn't mirror data or accept commands remotely, or that it has no vulnerabilities/backdoors which can make it do so? Perhaps you could do an audit of it or something...

Are you under the misimpression that KPMG or PwC to fill out a checklist will catch a back door? They’re looking for things like whether your servers have an old OpenSSL library or your code doesn’t escape values in SQL, which is pretty low-hanging fruit even on hosted apps and much less valuable for local apps.

Re: End of the road for Google Drive in Transmit

#176
post #42
post #5

> But then… a couple of months later, Google completely removed the option for us to scan our own code. Instead, to keep access to Google Drive, we would now have to pay one of Google’s business partners to conduct the review. What a racket. Smells downright anti-competitive The EU will have fun with this when it catches up.

It wasn't even that expensive. Ada security audit from tekta in Spain was under 4k. There's nothing like a racket here. The list of certification agencies goes from KPMG at top end to smaller companies.

They're partners, not just agencies you independently get to choose, right? That's what I'm getting at with the racket part.

You don't get to interop with one of the biggest cloud providers in the world unless you complete commercial audits with one of their partners.

Given the kind of collusion Google's shown itself capable of [1] do you really think this is all fair?

[1] https://en.wikipedia.org/wiki/High-Tech_Employee_Antitrust_L...

Re: End of the road for Google Drive in Transmit

#177
post #5

> But then… a couple of months later, Google completely removed the option for us to scan our own code. Instead, to keep access to Google Drive, we would now have to pay one of Google’s business partners to conduct the review. What a racket. Smells downright anti-competitive The EU will have fun with this when it catches up.

The EU absolutely loves adding requirements for certifications, so no I don't think they would get involved here. In fact, it's something they are pushing for in general.

Can you expand on what you mean? Which commercial certifications has the EU pushed?

Re: End of the road for Google Drive in Transmit

#178
post #5

> But then… a couple of months later, Google completely removed the option for us to scan our own code. Instead, to keep access to Google Drive, we would now have to pay one of Google’s business partners to conduct the review. What a racket. Smells downright anti-competitive The EU will have fun with this when it catches up.

> The EU will have fun with this when it catches up. I don't think you know how the EU works.

I live here, I have a fairly good idea. The EU has quite aggressively pursued different big tech companies over the last few years. The fines have become quite material.

Re: End of the road for Google Drive in Transmit

#179
post #88
post #5

> But then… a couple of months later, Google completely removed the option for us to scan our own code. Instead, to keep access to Google Drive, we would now have to pay one of Google’s business partners to conduct the review. What a racket. Smells downright anti-competitive The EU will have fun with this when it catches up.

> Smells downright anti-competitive The EU will have fun with this when it catches up What? The EU wants to introduce certifications for all products and services, further kneecapping local innovation through regulation and costly certifications. https://digital-strategy.ec.europa.eu/en/policies/cybersecur...

Seems more like a harmonization effort than what Google is proposing here? Or maybe I'm reading it wrong.

If I don't get one of these mandarin-approved certifications, will I no longer be able to do business? [The Google audits are a hard barrier to connecting to their cloud platform]

It's perhaps a difference between prescriptive and descriptive.

Post reply on HN