3 ms·
Most mail clients can connect to both a google email account and a "third party server" email account. It's easier to rule out undetectable-by-google data exfi
by snthd 4y ago
Most mail clients can connect to both a google email account and a "third party server" email account.
It's easier to rule out undetectable-by-google data exfilteration if the app can only connect to Google.
The obvious way around this is to make a Google-only edition.
Yuck.
- solar-ice 4y agoI don't think that's what Google are saying here. I think the sentence is referring to Google user data; as long as the Google user data or credentials to access it does not touch another server, the entire thing does not apply. In fact, in Google's guidance on this subject, they say: > Local client applications that only allow user-configured transmissions of Restricted Scope data from the device may be exempt from this requirement [to get a Letter of Assessment]. And in another FAQ: > Local Data Storage: Local client applications don't need to undergo a security assessment because data is run, stored, and processed only on the user's device. Local client applications that only allow user-configured transmissions of Restricted Scope data from the device may be exempt from this requirement. My feeling is that the author of Pegasus Mail has checked a checkbox incorrectly somewhere, or alternatively has not implemented the desktop oauth2 flow correctly.
- oefrha 4y agoThis is about the OAuth server-side flow vs client-side flow. Nothing to do with third party email accounts whatsoever. My unfounded guess is that just like the parent here, OP isn’t very knowledgeable about OAuth and chose the wrong flow.