16 ms·
The Sign Up with Google Mistake You Can't Fix
- Chefkoochooloo 11y agoWow, information is coming at an insane cost. Why do companies have to be so incredibly sneaky when trying to gather your digital information? There really needs to be laws put in place. Technology is growing at too fast a pace and we need laws in place to protect our privacy.
- ccvannorman 11y agoSounds like a great idea, but unfortunately technology moves 100x the speed of law, so by the time any laws are passed they won't matter. In other words, if you care, make a technological solution, not a legal one, because the right laws will be too little too late.
- chopin 11y agoThis is in Europe, where laws for this are in place. If the OP asks Fleet is required to delete the data permanently.
- calcsam 11y agoIf you realize it immediately after, you can cancel the OAuth authorization you granted, before they grab your data: https://myaccount.google.com/u/0/security#connectedapps https://myaccount.google.com/u/0/security#connectedapps
- SCdF 11y agoMaybe he can, but less tech savvy people almost certainly can't.
- mynameisvlad 11y agoSays who? If they were pissed off about this, then I'd assume they're capable of a simple search for "remove app permissions google" which brings up several help articles on how to do it. Considering that Google uses that terminology in the sign in screen anyway, it's not like the terms are incredibly unfamiliar.
- karmajunkie 11y agoI think you're overestimating by a couple orders of magnitude what the average user is capable of composing as a search.
- mynameisvlad 11y agoI think you're underestimating. An app is a common term for a mobile or web app, should be known by most people using the app in the first place. Permissions is a common term to signify what you just gave the new app you approved, also nothing really crazy. You want to remove or revoke what you just gave the app, so that term is obvious. And the service you approved it with is Google, so add that in. It's not like this is using any real technical terms that a common 21st century computer/phone user might not know, and the only real difficult one is probably "permissions" which you can probably either guess or eventually get to with synonyms; totally possible given it's a common English word.
- te0x 11y agoNo, you're drastically overestimating. Try working in a Best Buy. Everything you just put together with logic is not a safe assumption to make about the average user.
- karmajunkie 11y agoIts not whether the average user would understand it if you asked them (although even that's a stretch.) its whether its going to occur to them that they need to search for that particular string of words, or one similar enough to find the correct result. that is a fairly technical task and presumes a lot of knowledge.
- tonyarkles 11y agoHaving worked on an email client app before, that would definitely be effective. Retrieving and processing a decade worth of email is a huge pain in the ass that takes quite a long time (just retrieving the message bodies from GMail took at least an hour).
- mborch 11y agoI did after about 18 minutes which did limit the import to just the most recent emails. Phew!
- r00fus 11y agoDoesn't changing the password invalidate all OAuth tokens?
- calcsam 11y agoNo.
- boto3 11y agoThis is insane. I have Google/FB test accounts that I use to try out new products. I am now inclined to set up offline mail to make sure that my emails are not readily available to anyone but me. Of course Google still archives my removed emails but I think their policy is to remove them after a certain period. Can someone at Google confirm?
- r3bl 11y agoHow about feeling inclined to actually read the permissions that the service is requesting from you and deciding upon that? Same thing applies on smartphones too. If an app requests a lot of permissions that do not look like a legit part of the service, stay the hell away from it. A couple of examples: * Facebook Messenger does not need access to my location and call logs. * The main Facebook app does not need access to my SMS. * Signal does not need access to my calendar. Solution: I have none of these apps on my phone. Edit: a couple more examples: * WhatsApp does not need to read my Google services configurations. * Viber does not need access to my Bluetooth. * Snapchat does not need access to my audio settings. * Instagram does not need to run at startup. * Microsoft Word does not need to have the ability to set an alarm.
- fishanz 11y agoAndroid is tricky. I'm not an expert at their permissions settings but it seems that some of them are worded alarmingly for over-reaching yet justifiable permissions. I'm thinking for example (not one you listed, but..) that displaying push notifications immediatly when the phone is not in use requires a permission to "prevent the phone from sleeping"...
- xenophonf 11y agoI build federated IAM infrastructure at work, and one of the hardest problems we have is informed consent around attribute release. Users don't necessarily understand what they're releasing, developers don't necessarily understand what they're asking for, and there isn't a way to fake attribute release under the user's control (for those cases where you might still want to use a web app but not give it the carte blanche access it's asking for). It gets even more complicated when using social networks as identity providers of last resort. I---along with my employer---am very privacy conscious, so I really, really don't want to ask for any information I don't absolutely have to have. I try to mitigate this personally by creating multiple Google Accounts, but it isn't foolproof---plus, not every social network lets you do that.
- mgreg 11y agoI would tend to agree. In this whole episode I don't think either Google or the user are "at fault." I think its an unfortunate misunderstanding. A powerful tool accidentally misused. It does make me think that perhaps authentication (OAuth) would be better provided by an independent organization that didn't house so much personal data (that is, not an email provider nor a social network). An independent provider that didn't have much, if any, personal info would prevent this accidental release of information and control. That way if someone _really_ wanted to give a third party access to and control of their email at Google they would have to actually take the extra step of logging into Google and deliberately providing the access. In this case introducing friction into the process may save the user from shooting himself in the foot.
- dragonwriter 11y ago> It does make me think that perhaps authentication (OAuth) would be better provided by an independent organization that didn't house so much personal data (that is, not an email provider nor a social network). OAuth is an authorization system, not a mere authentication system, and it makes sense to have an authorization provider that is the locus of data or services for which authorization is required. Separate authentication-only systems haven't been particularly successful.
- pinkunicorn 11y agoThis is exactly why I change email addresses every 1/2 years. I've forwarding setup from 3 of my old addresses to my current address and for all financial transactions I only use my current email address.
- lern_too_spel 11y agoSo when you want to look up an old email, you have to remember which three month period it was in and which email address that corresponds to? When you have conversation that spans multiple periods, you have to do this multiple times? This cure is worse than the disease.
- dredmorbius 11y agoLocal mail archives are a hell of a drug. Using mutt or offlineimap: 1. Configure POPS/IMAPS access to the account, use Maildir format locally. 2. Download all messages. 3. Copy your saved messages to another location. 4. Delete all email on server. Local search tools can then be used to access that archive.
- pinkunicorn 11y agoI don't use email to have lengthy period conversations.. Didn't even know it was a thing until now! Almost all of my conversations are over chat and my primary usage of email is to sign up with sites or receive updates on my orders on Amazon/whatever. I haven't felt it as a curse so far. YMMV
- CrystalGamma 11y ago… only applies to GMail users. And here I thought this was relevant for me. I was almost shocked on reading the title.
- PostThisTooFast 11y agoThe title doesn't even make sense.
- fixermark 11y ago"Fleep would like to:" - View and manage your mail (click the "info" icon) More info --------- View, manage, and permanently delete your mail in Gmail Create, update, and delete labels Compose and send new email View your settings (e.g., filters and labels) - - - Okay. So the author is saying that the user cannot be trusted to read dialog boxes or click "more info" on a process they don't understand. Which, if that's the case, I guess the user can't be trusted to connect Gmail to anything. That's an unfortunately wide swath of usability that would have to be categorically disallowed if the problem is that Google allows this "At all."
- yAak 11y agoYeah, I think a more meaningful critique here would be "Google should draw more visual attention to certain dangerous permissions like these, over less impactful ones." Also, it's easy for users to click buttons and go "ohhhh, wait, no!" and there ideally should be something to account for this case too.
- pfooti 11y agoYes, absolutely. I write a lot of stuff that uses Google OAuth in order to to interact with google apps on behalf of a user (generate calendar events from forum posts, etc). I ask for the auth scopes separately and my code makes it clear what it's asking for (and the extra auths are asked for outside of the login-authenticate stuff which is always super-basic). Because of this, I'm extra attentive to what these scopes ask for and definitely don't sign up for anything that looks sketchy (especially the gmail stuff) - most recently TripIt asked for that permission (I suppose to scan my email in order to find travel documents). Even if I trust that TripIt isn't going to misuse that auth right now, there's no way I'm allowing that credential. I kind of wish I could set universal auto-reject at the google account level of some auth scopes. Like, "I will never allow https://mail.google.com/ https://mail.google.com/ scope (or any of the https://www.googleapis.com/auth/* https://www.googleapis.com/auth/* ones)".
- wodenokoto 11y agoWhich is absolutely what the author asked for.
- Johnie 11y agoOAuth (Google Sign In / Facebook Login) is a pretty good technology in order to manage and share your information. What's nice about OAuth is that it allows the end user to control access to information and revoke access as needed. What is truly scary is that the banks and financial institutions have not implemented OAuth. Currently, financial data is provided to third party apps via aggregators, like Plaid and Yodlee. Unlike OAuth, once you log into your bank with a third party app, they get an access token that allows access to your account indefinitely. There is no mechanism to monitor which apps have access to your account and ability to revoke the access to individual apps. I posted about this a while back: https://medium.com/@johnie/let-my-financial-data-free-74f3b7476bda https://medium.com/@johnie/let-my-financial-data-free-74f3b7...
- doomrobo 11y agoOnce access is established, there's nothing stopping the connected service to download all your information before you can disconnect it
- njovin 11y agoIt goes beyond access to your data. With an account and routing number and access to ACH protocols anyone has essentially unrestricted access to your money. I ran into an issue last year where I was unable to get an insurance company to stop pulling money, unauthorized and automatically, from my account. Since the amounts were different each time, my bank said I had no recourse other than to continue disputing the charges or change my account number. So in that way it's a bit like oAuth, except you only have one key and when you revoke it, everybody loses access.
- Johnie 11y agoThis is the CRAZIEST part of the banking system. The information to withdraw money from your account is on the bottom of the paper checks that you freely give out. Anyone with the routing number and account number can drain the entire account. ACH fraud in the US is in the ballpark of $100M / year. This is why I think we're only in the opening days of the FinTech shift. There's a lot to be done and a lot to fix.
- rmetzler 11y agoReading the title I thought it was about the GMail address which you can't change afterwards. I regret not getting my real name in my early twenties.
- ianamartin 11y agoOh, don't feel so bad about that. Pretty much every real name gets hit with so much spam now, it's not even funny. Or if it's not actual spam, it's people using your email for stuff they don't care about, like a throwaway account. I'm getting pretty close to just not using my gmail account any more.
- Gratsby 11y agoTaking advantage of end user provided permissions seems to be the norm instead of the exception. A few scandals have risen because of it. I remember a popular "free" calculator app that was sending GPS data. Oddly, most people don't seem to care. They'd rather give up their entire picture collection than spend $2 on a permissions restricted app. Having more fine-grained restrictions than we already do won't solve the problem. Most people will simply accept the default "give this application permissions to do everything" right out of the gate. I'd be surprised if even close to 5% of the people on facebook have reviewed the applications they've given permission to in the last 12 months.
- smarx007 11y agoFleep is a European (Estonian) company. Just mail them (https://fleep.io/privacy https://fleep.io/privacy, §9) and they should be decent enough to terminate your account altogether. I had quite a good experience with them, their CEO responded to my Fleep messages (nice example of dogfooding), though haven't used it for a while now.
- Someone1234 11y ago> the bigger problem here lies with how Google makes this possible: At all Sorry but it is MY information and I should be able to do with it as I please. If Google removes the ability to extract it all to a third party then you're locked into Google forever. Removing the ability because some people aren't responsible isn't a good argument.
- dredmorbius 11y agoFalse dichotomy. It's possible to allow for extraction of user data (Google actually support this quite well) and not for sleezy third-party services to fool ... gifted and talented developers, let alone the semi-literate, technically-phobic, Alzheimers-addled, visually disabled, or others, for whom this sort of crap is a very real and constant source of frustration. I support a group of such users. While they can frustrate me with their lack of understanding, the crap interfaces, requests, and systems they're presented with frustrate me far, far, far, far more.
- Zigurd 11y agoThe only way to really fix it is either... 1. Don't allow 3rd party mail apps 2. Encrypt mail and provide open, verifiable clients and open server protocols. Google make only a little money from my GMail account. I'd gladly pay them twice that for a strongly encrypted email system that provides infrastructure for key exchange with a web of trust.
- fixermark 11y agoIn this specific context, there was a third way to fix the issue: 3. Click "Deny" when the app explicitly has Google's OAuth flow ask if you want to give it permission to read, create, and delete all of your email.
- Zigurd 11y agoWell, of course. One could ask "What did he think was going to happen when he installed a 3rd party mail reader?" Thing is, encrypted mail and trusted clients means you could store your email at supersketchy.ru and it wouldn't matter. It's the way to make those kinds of choices safe, Or, rether, just having permissions doesn't security is adequate.
- wdr1 11y agoWhen he says Google shouldn't make this possible at all, I'm not sure what he's asking for? Isn't the alternative basically vendor lock-in? Or that this would mean disabling things like IMAP & POP? Fleep sounds like a shitty service from the description, but at some point user's need to take responsibility for their actions, no?
- BinaryIdiot 11y ago> When he says Google shouldn't make this possible at all, I'm not sure what he's asking for? I thought maybe he was asking for something like: 1. Request password before allowing access (which seems reasonable if the user hadn't entered it recently; I mean you have to do this for almost every other security setting in your account) 2. Allow finer control over the data. Say not allow it to download the entire corpus or only access to meta data, etc (though that can be probably too complicated for a regular user). Maybe this simply means different permissions when they want full access versus recent / continual access? I could see that being possible more descriptive.
- tobyjsullivan 11y agoI can't agree with this author - at least their argument that "the bigger problem here lies with how Google makes this possible: 1) At all..." If this wasn't possible at all, this product couldn't exist in it's current form. And clearly, at some point, the author saw value in this product enough to give it a shot. Do I agree Google should make it extra clear when you are signing over permission for unusually liberal access to your data? Absolutely.
- dredmorbius 11y agoIf the 1) the product couldn't exist in its (not "it's") current form, and 2) perceptions of value were based on what was a false understanding of the product and how it worked, then that perception of reality is false, and the product simply shouldn't exist.
- deleted 11y ago[deleted]
- taurath 11y agoThis is truly a big deal, and also effects Android. The system of "privacy checking" doesn't work when the consumer has almost zero information about how they will actually use the information. Its a binary "give access to everything" or "you can't use this app" which creates an arms race. App updates can then ask for more and more permissions. More importantly, even a misclick can easily give access rights away to your entire email inbox, phone contacts, call history or any other information you might consider private.
- chii 11y agoThe way to fix it is for Google to let you change what data appears to an app after the fact. The app asking for permission will never get denied. They'd get fake data if the user didn't give permission.
- mattbgates 11y agoScary.
- ishener 11y agoIt's an app to manage your emails. What did you expect for christ's sake?
- codeulike 11y agoGoogle Mistake is such a good name for a product. Not sure what it would do, but it's a good name.
- dredmorbius 11y agoIt would save time.
- dredmorbius 11y agoThe mistake was not "all yours", and Fleep (and Google) are failing to disclose how, when, where, and most importantly, why data are being used. Quite arguably, Fleep gained access to data you held which was not yours to provide -- email content and contact information for those with whom you've corresponded. This is among the reasons I'm increasingly limiting my use of electronic communications at all. The risks, reality, frequency, control, and disclosure of such cases is simply too high a negative to utilise them. Yes, this means that I not only don't carry a smartphone, but by and large don't carry a mobile phone at all -- a regression to pre-2000 states of comms. This is a case of race-to-the-bottom behavior, and bad (or simply grossly incompetent) actor behavior poisoning the well for all. It's an exceptionally strong argument to replace, as rapidly as possible, the present set of hosted online services with privately provisioned ones. Sandstorm.io, FreedomBox, and similar concepts can't hit prime time too soon. If Google knows what's good for it, it should support this as well. Its choices are having some access to user time and committment, or none. (Google's previous behaviors mean I've largely left it behind for its namesake service. I interact with it principally through pseudonymous accounts, though I'm aware these offer fairly thin protections against a determined actor.) As Cory Doctorow has said, data are the radioactive waste of the current age. My formulation is that data are liability. Overreaching privacy-invading tools are bad news waiting to happen.
- deleted 11y ago[deleted]
- PostThisTooFast 11y agoThat title makes no sense. And use a proper E-mail server, not Google apps.