3 ms·
> Google could be more honest and label the permission "this app will make your email public for all intents and purposes". How is offering the worst case hypo
by bdhess 8y ago
> Google could be more honest and label the permission "this app will make your email public for all intents and purposes".
How is offering the worst case hypothetical of what the 3rd party might do with your data _more honest_ than refraining from hypothesizing?
- deleted 8y ago[deleted]
- saagarjha 8y agoBecause it turns out that the hypothetical case wasn’t so hypothetical after all.
- pacala 8y agoBecause that's what's happening. Having an app with both "read email" and "network access" is basically saying "this app will siphon your email to an unvetted and likely unsecure third party location". You wouldn't want your bank account info treated the same, would you. Would it be that hard to raise the user's awareness right then and there? Bonus points for offering a sandboxing mode, where the app can only access certain network locations, like Google IMAP servers, and only Google IMAP servers. Extra bonus points for auditing traffic from sandoxed apps to catch them if they try something fishy.
- simonh 8y agoThat’s not the same as making your emails public, ie posting them in a world readable archive.