Live data from Hacker News

End of the road for Google Drive in Transmit

blog.panic.com

81–90 of 196 posts

Re: End of the road for Google Drive in Transmit

#81
post #33
post #26

Earlier quoted context omitted.

> which I've done and are quite easy - if anything Did you read the part where it took multiple months to continue because of slow replies and non-working tooling from Google's side? It's also pretty expensive for a relatively niche app, it might be fine if you are Dropbox or a big VC funded Mail app but for smaller companies it's not "easy". > I don't think it's a bad thing that Google is enforcing some minimal secu…

We've done it too, first time it was hard but it's required and recommended. It raises the bar for low effort hackers and improves security. I disagree with the op. Sorry mate go through the casa audit and get the access .

> It raises the bar for low effort hackers and improves security.

There are meaningful ways you can improve the security of your app. There are ways to make sure your app passes CASA. I found very little if any overlap between those two when going through the process.

Re: End of the road for Google Drive in Transmit

#82
post #51

As per mentioned Ghisler page: "The security assessment would have to be performed by a specialized company, and costs up to $75'000 per year and program (so $150'000 for 32bit+64-bit). This is not sustainable even with a subscription." [0] This is death kiss to indie developement. But paradoxically it is great. Killing interoperability is nail to coffin. This brings more and more focus to alternative solutions out o…

I'm surprised that there isn't more support for just using object storage via a GUI.

I would love for as user friendly way to just use Backblaze or some other S3 compatible provider as my drive.

Edit: I guess that's sort of exactly what Transmit does, but I want something that is simple enough that anyone can use it.

Re: End of the road for Google Drive in Transmit

#83

I wrote this response to another front page HN article on a similar topic: https://news.ycombinator.com/item?id=41664753 I know everyone loves to dunk on Google, and I definitely agree their communication and customer service to app developers is shite, but this change to permissions scope is a good thing. If you have full, unfettered access to large number of people's Google Drive data, you're a huge target for male…

Google's not my dad. It's not their responsibility (or their place) to audit every piece of software I use to interact with their services. I'm tired of being treated like a child who needs every sharp corner ground down for my safety. Edit: Next logical step is auditing every IMAP client before you can connect it to Gmail. Ridiculous.

> Edit: Next logical step is auditing every IMAP client before you can connect it to Gmail. Ridiculous.

Actually .... They're not that far away from that, if they're not already implementing it. Office365, and Google, if they haven't already have disabled basic Auth for IMAP/SMTP, and only supporting oauth2. Which requires a AppId/ClientSecret handed out out by registering your app with Microsoft/Google.

It seems that you can still steal thunderbirds appid/clientsecret from their open source code, for now ( https://simondobson.org/2024/02/03/getting-email/ ) , but ......

Re: End of the road for Google Drive in Transmit

#85
post #33

Earlier quoted context omitted.

We've done it too, first time it was hard but it's required and recommended. It raises the bar for low effort hackers and improves security. I disagree with the op. Sorry mate go through the casa audit and get the access .

If you read the article, they went through the casa audit, found that it did not improve the security of their app, and came to the conclusion it wasn't worth the time and now money to do it a second time.

> and came to the conclusion it wasn't worth the time and now money to do it a second time.

Especially because they'd now have to go through an other third-party to perform the audit process (not just the security lab, the entire thing), according to the total commander folks[1] that's 75k/year/program.

[1] https://www.ghisler.com/googledrivehelp.htm

Re: End of the road for Google Drive in Transmit

#86
post #42

Earlier quoted context omitted.

It wasn't even that expensive. Ada security audit from tekta in Spain was under 4k. There's nothing like a racket here. The list of certification agencies goes from KPMG at top end to smaller companies.

4k is not expensive in enterprise terms, but in small bootstrapped startup terms it is absolutely expensive.

And the issue is the other corporations may likely follow, so you have to stack hefty audit sum every year for multiple monopolistic cloud vendors because you made some cheap documents scanner app with convenient storage options for your user.

Re: End of the road for Google Drive in Transmit

#87

I wrote this response to another front page HN article on a similar topic: https://news.ycombinator.com/item?id=41664753 I know everyone loves to dunk on Google, and I definitely agree their communication and customer service to app developers is shite, but this change to permissions scope is a good thing. If you have full, unfettered access to large number of people's Google Drive data, you're a huge target for male…

Google's not my dad. It's not their responsibility (or their place) to audit every piece of software I use to interact with their services. I'm tired of being treated like a child who needs every sharp corner ground down for my safety. Edit: Next logical step is auditing every IMAP client before you can connect it to Gmail. Ridiculous.

They're the ones who will take the blame when a third-party app gets compromised and is used to siphon off people's data.

This isn't a theoretical concern. It's pretty much exactly what happened with Cambridge Analytica. Facebook didn't really do anything wrong; they provided an API for data access, people explicitly authorized an app with broad access their data, and it turned out that the app was basically a trojan horse for data collection. And politicians, the media, the general public, and even the technologically savvier people who should know better all blamed Facebook for this.

Re: End of the road for Google Drive in Transmit

#88
post #5

> But then… a couple of months later, Google completely removed the option for us to scan our own code. Instead, to keep access to Google Drive, we would now have to pay one of Google’s business partners to conduct the review. What a racket. Smells downright anti-competitive The EU will have fun with this when it catches up.

> Smells downright anti-competitive The EU will have fun with this when it catches up

What? The EU wants to introduce certifications for all products and services, further kneecapping local innovation through regulation and costly certifications.

https://digital-strategy.ec.europa.eu/en/policies/cybersecur...

Re: End of the road for Google Drive in Transmit

#89
post #51

As per mentioned Ghisler page: "The security assessment would have to be performed by a specialized company, and costs up to $75'000 per year and program (so $150'000 for 32bit+64-bit). This is not sustainable even with a subscription." [0] This is death kiss to indie developement. But paradoxically it is great. Killing interoperability is nail to coffin. This brings more and more focus to alternative solutions out o…

This is what everyone said they wanted after Cambridge Analytica! For platforms to exercise due diligence before allowing users to delegate their access to third parties.
Post reply on HN