Live data from Hacker News

End of the road for Google Drive in Transmit

blog.panic.com

51–60 of 196 posts

Re: End of the road for Google Drive in Transmit

#51
As per mentioned Ghisler page: "The security assessment would have to be performed by a specialized company, and costs up to $75'000 per year and program (so $150'000 for 32bit+64-bit). This is not sustainable even with a subscription." [0]

This is death kiss to indie developement.

But paradoxically it is great. Killing interoperability is nail to coffin. This brings more and more focus to alternative solutions out of Google market, especially in independent software area. Like yt-dlp, FreeTube, F-Droid - actually all my family uses them and I recommend it to everyone. I can't wait to get some alternative GDrive client lib which simulates browser to throw data over that garden wall, and I don't care if it nags with captcha. The more hassle the more people are going to hate that ivory tower.

[0] https://www.ghisler.com/googledrivehelp.htm

Re: End of the road for Google Drive in Transmit

#52
Raising the barrier for access like Google has done feels very anti-small company. Sure, it's more secure, but I have to wonder if they could improve security without excluding smaller companies like this. Seeing as it's Google, they probably could and specifically choose not to.

Re: End of the road for Google Drive in Transmit

#53
post #36

Earlier quoted context omitted.

> Sometimes companies have even been destroyed, notably by Amazon, for having the wrong political viewpoints. Ok, I'll ask: what company did Amazon destroy for having the wrong political viewpoint? AWS hosts some pretty vile stuff without blinking. The last time a company made a big "woe is me, my ideas are being suppressed" claim against Amazon, it was Parler, and they weren't kicked off for their viewpoints. They w…

Look, they were kicked off for their content. I hesitate to call their content "viewpoints" but it's become roughly synonymous with speech so I guess it kinda fits. Regardless, I'm happy they did it. I think there is room for "exception that proves the rule" type behavior. When the bridge too far is literal Nazis I'm okay with considering AWS to still be politically neutral. No ToS violation (which was flimsy at best…

I didn't realize that death threats were a viewpoint.[1]

> People on Parler used the social network to stoke fear, spread hate, and allegedly coordinate the insurrection at the Capitol building on Wednesday. The app has recently been overrun with death threats, celebrations of violence, and posts encouraging “Patriots” to march on Washington, DC, with weapons on Jan. 19, the day before the inauguration of President-elect Joe Biden.

> In an email obtained by BuzzFeed News, an AWS Trust and Safety team told Parler Chief Policy Officer Amy Peikoff that the calls for violence propagating across the social network violated its terms of service. Amazon said it was unconvinced that the service’s plan to use volunteers to moderate calls for violence and hate speech would be effective.

Parler was used to coordinate the Jan 6 attacks, and when they were caught with their pants down they promised some half baked scheme to have unpaid volunteers do moderation. It was demonstrably a joke and they were caught failing to moderate more attack planning that was happening out in the open on their app. I think Parler leadership got off easy on this, they frankly should've been in jail on January 7th for being accomplices and not merely getting kicked off AWS.

[1] https://www.buzzfeednews.com/article/johnpaczkowski/amazon-p...

Re: End of the road for Google Drive in Transmit

#54

I wrote this response to another front page HN article on a similar topic: https://news.ycombinator.com/item?id=41664753 I know everyone loves to dunk on Google, and I definitely agree their communication and customer service to app developers is shite, but this change to permissions scope is a good thing. If you have full, unfettered access to large number of people's Google Drive data, you're a huge target for male…

I think it's relevant that Transmit is a local native app . There's no hosted app exposed to the internet to hack here. Google made one lengthy process that doesn't fit this use case.

Panic runs a cloud-hosted sync service that syncs your credentials and connection info between different instances of Transmit you may have.

No idea if that's what google is targeting here, but that is a cloud service, that presumably gets a copy of people's Google Drive OAuth keys if they use Google Drive with Transmit and the sync service.

Re: End of the road for Google Drive in Transmit

#55

I wrote this response to another front page HN article on a similar topic: https://news.ycombinator.com/item?id=41664753 I know everyone loves to dunk on Google, and I definitely agree their communication and customer service to app developers is shite, but this change to permissions scope is a good thing. If you have full, unfettered access to large number of people's Google Drive data, you're a huge target for male…

That seems like a poor argument for an app which doesn’t mirror data or accept commands remotely (if I can control your app on your device, I can control the official Google Drive app) but there is a general point about full drive access. However, I think the answer there is for Google to improve the security model for Drive - for example, allow the user to select a non-root folder which Transmit or iA Writer can use and have some UI indicating that it’s shared. Instead, this process serves as a competitive moat and isn’t very effective – all of the large companies that we’ve seen getting breached are going to pay KPMG to spend time on performative box checking, and your data will still be exfiltrated but they’ll at least say they’re very sorry.

Re: End of the road for Google Drive in Transmit

#56
post #3
post #2

Google really is wrecking hell on third party integrations.

"The fastest path to wealth is the construction of these digital platforms, where other people depend on you." - Eric Schmidt. Many products leads at Google seem to disagree!

Depends.

Build it, get dependent developers, start charging dependent developers, ????, profit.

Re: End of the road for Google Drive in Transmit

#57
I think its totally reasonable. If google wants to make drive functionality expensive and annoying for devs to include, then devs are going to drop support.

I appreciate that this seems to be some additional security for drive access which is ostensibly a good thing but it doesn't seem like the review is very useful or catches any bad actors or errors.

Re: End of the road for Google Drive in Transmit

#58
post #51

As per mentioned Ghisler page: "The security assessment would have to be performed by a specialized company, and costs up to $75'000 per year and program (so $150'000 for 32bit+64-bit). This is not sustainable even with a subscription." [0] This is death kiss to indie developement. But paradoxically it is great. Killing interoperability is nail to coffin. This brings more and more focus to alternative solutions out o…

Its the kiss of death for google drive support, and eventually when many apps don't support using google drive people who are on it will switch to other cloud storage providers.

Re: End of the road for Google Drive in Transmit

#59
post #33
post #26

Earlier quoted context omitted.

> which I've done and are quite easy - if anything Did you read the part where it took multiple months to continue because of slow replies and non-working tooling from Google's side? It's also pretty expensive for a relatively niche app, it might be fine if you are Dropbox or a big VC funded Mail app but for smaller companies it's not "easy". > I don't think it's a bad thing that Google is enforcing some minimal secu…

We've done it too, first time it was hard but it's required and recommended. It raises the bar for low effort hackers and improves security. I disagree with the op. Sorry mate go through the casa audit and get the access .

If you read the article, they went through the casa audit, found that it did not improve the security of their app, and came to the conclusion it wasn't worth the time and now money to do it a second time.

Re: End of the road for Google Drive in Transmit

#60

Earlier quoted context omitted.

> If you can't afford the new audit requirements ... then I'd really question your ability to appropriately safeguard so much critically private data. Because large companies that can afford it have proven to be exemplars at safeguarding private data?

Like google? Yes, I think so. Probably one of the best track records among big tech, so maybe their security practices should carry more weight?

Lets just say this: the US Federal Government, several large health care and health insurance organizations, several large financial institutions, a major university, and several others have all had to send me "We take security seriously" letters. They could all afford to undergo (and had passed) various security audits. But in the real world they failed.
Post reply on HN