3 ms·
Do you understand what type of apps we are talking about here? It's not Chrome apps. It's not android apps either. It's apps that make use of Google's OAuth con
by tokenizerrr 9y ago
Do you understand what type of apps we are talking about here? It's not Chrome apps. It's not android apps either. It's apps that make use of Google's OAuth connection to do stuff on behalf of the user. So, don't use that if you don't want to deal with the very legitimate security checks.
Again, this is NOT about Android or Chrome apps. So yeah, go use whatever apps you want, as long as it doesn't want the users to grant the developer permission to do stuff with the user's Google account, this does not affect you in the slightest.
- bjpbakker 9y agoThis is any web app that /you/ granted access to your Google account details (or a wider scope). If you don't want a web app to access your account, then don't grant access. It really is that simple. Now there's an extra step: Google's stamp of trust. I agree that for most web app this will be an extra formality. For me personally the key point is that there will be web apps that Google does not agree with from a business POV. That is my real problem with this. If this list was curated by a community rather that Google, I would not have a problem with it.
- tokenizerrr 9y agoEveryone can make such an app. A malware site can just redirect an user to that page, and the user thinks they have to log in. They do so. Most users aren't very tech savvy. For apps that aren't vetted you have to confirm that you really intended to give them access. This is good! It protects most users who aren't a genius like yourself. Even if you're not verified, users can still grant your app access! Nothing is blocked! Google just wants to be sure the user realizes what is going on.
- vitus 9y agoI mean, I see this as a culmination of the response to the OAuth phishing attack that happened a few months ago [0]. Red flags should go up if you were accessing a site yesterday via OAuth, and all of a sudden today on the same site you get an angry full-page alert that "so-and-so wants your credentials, but they haven't been verified yet". I also noticed the presence of the domain name on the OAuth page, which certainly helps but is probably not widely noticed in practice. It's certainly worth acknowledging that even if users aren't truly blocked, they may be turned away from legitimate apps that just haven't gone through the review process yet -- too many extra clicks, concerns about the legitimacy of the app, whatever. I wonder how this in particular differs from the vetting process for any mobile app store (Apple's App Store in particular comes to mind with its reputation as a walled garden [1], but Android does also warn the user when enabling the installation of third-party apps not on the Play Store). [0] http://www.pcworld.com/article/3194816/security/google-docs-phishing-attack-underscores-oauth-security-risks.html http://www.pcworld.com/article/3194816/security/google-docs-... [1] https://en.wikipedia.org/wiki/IOS_app_approvals https://en.wikipedia.org/wiki/IOS_app_approvals Disclaimer: while I work at Google, I have nothing to do with OAuth or any other user-facing interface.
- Flenser 9y ago> It's certainly worth acknowledging that even if users aren't truly blocked, they may be turned away from legitimate apps that just haven't gone through the review process yet -- too many extra clicks, concerns about the legitimacy of the app, whatever. Perhaps it should have a "tell me when they're verified then" option.