8 ms·
Context: In ~July 2018 there was some outcry because Google was "letting third parties read your emails" (e.g. https://www.cbsnews.com/news/google-reportedly-a
by joefkelley 8y ago
Context:
In ~July 2018 there was some outcry because Google was "letting third parties read your emails" (e.g. https://www.cbsnews.com/news/google-reportedly-allows-third-party-apps-to-scan-gmail-emails/ https://www.cbsnews.com/news/google-reportedly-allows-third-...). Of course, these were all explicitly installed by users who gave these apps access. But somehow people were mad anyway - maybe users shouldn't be given the option to make choices they don't understand?
Anyway, as the message mentions, Google announced new requirements for these apps on October 8: https://cloud.google.com/blog/products/g-suite/elevating-user-trust-in-our-api-ecosystems https://cloud.google.com/blog/products/g-suite/elevating-use...
Apparently, IFTTT (which does personal automation, integrating with many third parties), does not comply with the new policy.
- deleted 8y ago[deleted]
- chii 8y ago> maybe users shouldn't be given the option to make choices they don't understand? ala brexit!
- mappu 8y agoIf your addon works entirely locally, you only need to be "verified as non-malicious software", but if there is any network component then you need the "full assessment" from an independent 3rd-party auditor: > The assessment fee is paid by the developer and may range from $15,000 to $75,000 (or more) depending on the size and complexity of the application. This fee is due whether or not your app passes the assessment
- abraae 8y agoGood news for IFTT, who presumably can afford to pay this (and could use the results elsewhere). Bad news for smaller players.
- tptacek 8y agoThe low-end of that range is the ballpark for the low-end of the range of security assessments; the $75,000 high-end is very high; a more realistic range would be $15,000-$30,000 for typical SAAS-type functionality. This is simply what professional security assessment costs. There's a lot of competition and a diversity of firms, and this is the range the rates float in. It doesn't make sense that small companies should be allowed to circumvent the requirement when what they're doing is just as sensitive as apps from large companies.
- jdp23 8y agoBoth are true simultaneously: * professional security is needed, and this is what it costs * the cost is more of a barrier to smaller companies (and hence provides an advantage to larger companies) It seems like an inherent tension; I'm not sure how to get around it.
- QuercusMax 8y agoSeems like a business opportunity for somebody to create a compliant API that allows other people to write software that accesses gmail data in a limited fashion.
- J-Kuhn 8y agoI'd say that this is nearly impossible. We talk about two different data sets here: * The actual User data. * Data from third persons, including, but not limited to their e-mail address. While a user can agree that their own data should be processed by a third party, the problem is that he cannot consent for other people. And in my understanding (INAL), every part of the software where those third person information is transferred or processed needs to be part of that full assessment. A limited API that does not give out any third persons data would have to somehow filter out all the information of all third partys.
- Alex3917 8y agoTheir TOS explicitly forbids doing that.
- canada_dry 8y ago> ...explicitly installed by users who gave these apps access. But somehow people were mad anyway... Yah, and we know that 99% of folks just next - next - next when installing everything on their phone, laptop, console. So many apps want access to stuff that isn't obvious (e.g. games that want to access your photos, emails, and msgs) though most people skip the alerts when installing.
- TeMPOraL 8y agoThis case is different. IFFT is entirely about you explicitly giving it access to individual services of your choosing, in order to make them interoperable via the scripts you explicitly create there. It's kind of obvious IFFT can see your e-mails if you connect it to add a script triggered on "When new mail matching XYZ arrives".
- jakelazaroff 8y ago> maybe users shouldn't be given the option to make choices they don't understand? Not sure if this is meant ironically… but no, they definitely should not.
- scarejunba 8y agoBeware of he who would deny you access to information^W control over your own tools, for in his heart he dreams himself your master
- jakelazaroff 8y agoDo you really have control if you're making a choice you don't understand?
- lukevdp 8y agoYes, having a choice gives you more control than having that choice made for you.
- o10449366 8y ago> Of course, these were all explicitly installed by users who gave these apps access. But somehow people were mad anyway - maybe users shouldn't be given the option to make choices they don't understand? It's interesting to see the difference in attitude on HN towards Google and Facebook. Many readers on HN shared the media's outcry when it was "revealed" that Netflix and Spotify were given read/write access to users' messages if they had authorized those Messenger plugins/platforms. I'm not attacking your position--I wholeheartedly agree with it--it just seems like there's a double standard on HN when it comes to certain tech companies.
- RhodesianHunter 8y agoIf I connect IFTTT to my Gmail to automate some aspect thereof I can reasonably expect it to have access to my emails. If I connect my Facebook to my Spotify so that I can log in with one account and maybe share music with friends, I don't expect Spotify to have access to my private messages. Obviously context is important, but I'm not seeing the double standard.
- o10449366 8y agoCorrect me if I'm wrong, but I believe the circumstances under which Spotify would have permission to read your messages are 1) if you use their Messenger app plugin 2) if you had connected to Messenger through Spotify's desktop app. I believe this feature has been deprecated for a few years now, though. Even if you sign up for Spotify using your Facebook account or connect your Facebook account to Spotify that does not give them access to your Messenger messages. It is my understanding that it required the user to opt into specifically connecting Messenger for that circumstance to occur.
- nindalf 8y agoThe Facebook integration with Spotify allowed you to send messages and receive from within Spotify. Could you think of a way to implement this without giving the Spotify client access to those messages? What’s more, users explicitly opted in, giving Spotify permission to do so. [1] No reasonable person would use Spotify to send and receive messages after explicitly granting the client permissions and then claim “but I don’t expect Spotify to have access to my private messages” [1] - https://stackoverflow.com/questions/17561784/django-social-auth-extended-facebook-permissions-like-spotify https://stackoverflow.com/questions/17561784/django-social-a...
- londons_explore 8y agoThe missing detail here is the policy requires a third party audit which is expected to cost ~$100k. Most small startups won't think that's worth it.