Live data from Hacker News

Google’s painful Gmail OAuth verification process

aura.app

41–50 of 52 posts

Re: Google’s painful Gmail OAuth verification process

#42
post #22

This all makes sense to me. If you're not providing enough value to users to cover the >$15k fee, you're just an attack vector for user data. Consistency of the process aside, I'm really not sure what people would expect. (I work at Google, yadda yadda, but have nothing to do with this.)

Fuck this, it's EXACTLY the problem in the valley. Small players should be empowered, not stifled.

Re: Google’s painful Gmail OAuth verification process

#43

Earlier quoted context omitted.

I don't recall since the last time I set it up was a while ago, but I think just your password + an app specific code if you use 2fa normally. But yeah I'm pretty confident this doesn't apply to outlook.

So why don't we see more startups use open protocols for access to email rather than make things that are GMail specific? Why do you get voted down for just suggesting that they do so?

I'm not sure, my expectation would be because oauth is more secure and feature rich than either imap or pop. Jmap I'm less familiar with.

Re: Google’s painful Gmail OAuth verification process

#44

Someone needs to make it trivial to host your own email, and sell it as reliable. I think you could probably sell more than just techies on it, given how your email is a critical system to many people in modern times.

Host it where tho ? Wouldn't you need a 24/7 running server ?

Re: Google’s painful Gmail OAuth verification process

#45

As both a gmail user and developer interested in applications to help me manage my personal information, this is incredibly depressing to hear. The idea of a verification process itself is great, and I applaud that effort. But some of these barriers seems put in place solely to kill competition and prevent startups from filling the personal data needs before Google comes up with its own plan. These exorbitant fees of…

It's the direction that everyone seems to be moving. Wall up the gardens, remove your own access to your information, and remove the ability to share and integrate across platforms. The weird thing is how quickly the sentiment turned from my perspective. I felt like one day most technical people applauded the ability to have total real-time access to your data, to be able to write code or use open source code to plug…

The difference is that the internet happened and it became way too easy for anyone in the world to exfiltrate all your data with a simple free program. This is why we can't have nice things.

Re: Google’s painful Gmail OAuth verification process

#46
post #22

This all makes sense to me. If you're not providing enough value to users to cover the >$15k fee, you're just an attack vector for user data. Consistency of the process aside, I'm really not sure what people would expect. (I work at Google, yadda yadda, but have nothing to do with this.)

Fuck this, it's EXACTLY the problem in the valley. Small players should be empowered, not stifled.

I wouldn't want someone who won't bet $15K-$75K on their own product to have access to any of my data.

Re: Google’s painful Gmail OAuth verification process

#47

Earlier quoted context omitted.

So why don't we see more startups use open protocols for access to email rather than make things that are GMail specific? Why do you get voted down for just suggesting that they do so?

I'm not sure, my expectation would be because oauth is more secure and feature rich than either imap or pop. Jmap I'm less familiar with.

IMAP can be awkward with sync, pagination and has never played great with labels vs folders. JMAP looks promising.

Re: Google’s painful Gmail OAuth verification process

#48

Earlier quoted context omitted.

Fuck this, it's EXACTLY the problem in the valley. Small players should be empowered, not stifled.

I wouldn't want someone who won't bet $15K-$75K on their own product to have access to any of my data.

Your making a lot of assumptions. For example, who said anything about a product. Not all "players" small or large are selling something. Sometimes people just like to make stuff that works well for themselves and others.

Re: Google’s painful Gmail OAuth verification process

#49

Earlier quoted context omitted.

I wouldn't want someone who won't bet $15K-$75K on their own product to have access to any of my data.

Your making a lot of assumptions. For example, who said anything about a product. Not all "players" small or large are selling something. Sometimes people just like to make stuff that works well for themselves and others.

Things like gsyn.ch will just not be written. Google already throws scary warnings about unverified apps using OAuth tokens when you use this service, but Google's use of non-standard CSV entries rather than vCards for sharing contacts has made for a terrible user experience if you want to use your phonebook outside an Android phone/Gmail.

Re: Google’s painful Gmail OAuth verification process

#50

Earlier quoted context omitted.

It's the direction that everyone seems to be moving. Wall up the gardens, remove your own access to your information, and remove the ability to share and integrate across platforms. The weird thing is how quickly the sentiment turned from my perspective. I felt like one day most technical people applauded the ability to have total real-time access to your data, to be able to write code or use open source code to plug…

You're confusing 2 things. Facebook shared data on millions of users to Cambridge Analytica. I never gave my consent, you never did. It is a different matter than having open APIs that allow you to get your own data out of Facebook. I want to be able to get my own data on Facebook through open APIs. What I don't want is for Facebook to give away my data to other people without my consent. You can advocate for those 2…

Both cases are the same.

Alice sends Bob an email and Bob then shares it with an evil 3rd party spell check extension... Alice's privacy has now been breached without her consent.

Alice posts her contact info to her wall, and her friend Bob (who has read access) shares it with a third party (Cambridge Analytica). Alice's privacy has now been breached without her consent.

Cambridge analytica collected the bulk of their private data with the consent of a friend of the victim.

Post reply on HN