5 ms·
I’ve gone through this process for my email client Kanmail [1]. The third party audit is not required for email clients that run on end users computers and stor
by Fizzadar 4y ago
I’ve gone through this process for my email client Kanmail [1]. The third party audit is not required for email clients that run on end users computers and store credentials locally.
By the looks of it Pegasus falls into this category and should not have any issues getting approved (still need the YT video and such but the Google team are surprisingly responsive and helpful in my experience).
[1] https://kanmail.io https://kanmail.io
- undecisive 4y agoThe wording seems to imply that if, on a yearly whim, someone at Google decides to "empanel" a security assessment team, you have no choice, you will not necessarily be asked permission and you will be paying that invoice whether or not you needed that assessment. Do you have evidence - in writing - to the contrary from a Google official? Abridged wording and my non-lawyer interpretation below in case I'm not clear: > Every app that [accesses Gmail and also accesses other servers] is required to go through a security assessment from Google empanelled security assessors. [...] > In order to maintain access to restricted scopes, the app will need to undergo this security assessment on an annual basis, [... costs usually] between $10,000 - $75,000 (or more) [...] > This fee may be required whether or not your app passes the assessment and will be payable by the developer."
- dal 4y agoSo basically when your application resolves gmail.com you will access other servers. :P
- undecisive 4y agoWell, certainly they haven't ruled it out. DNS servers are third-party servers. VPNs are third-party servers. They can be as kind or as nasty about this as they like, For all my fear mongering, I should point out that the only reason Google are saying this is to cover their backs when they decide to levy the maximum fee on an unsuspecting competitor. If they don't consider you a direct competitor, you might be ok. They have no reason to use this policy to alienate the majority of desktop applications that connect to email. But they also have no repercussions if they do.
- ed 4y ago> you will be paying that invoice whether or not you needed that assessment They don't just send you a bill for $10k. You can opt-out of the yearly audit by removing your use of restricted scopes. But yes, it is a yearly required audit, and they're serious about it. This limits the kind of apps that can be built on Gmail (basically – no free apps), but it is undoubtedly better for end users. Having gone through the process, which checks among other things that data can't be resold, tokens are encrypted, user data is really deleted when you say it is, and that Gmail API access is auditable in the event of a breach; these are all good things for users. (My auditor was so thorough they actually found a high-impact XSS bug in Firefox – the bounty covered part of their fees.)
- yoaviram 4y agoIt's not necessarily better for the users. I'm one of the founders of a free and open source service which simplifies the process of sending CCPA/GDPR data deletion requests. A common request from our users is to give them good recommendation on who to opt out from. A new compatitor has implemented a feature where they use the Gmail API to analyse a user's email exchange (from their servers) in order to recommend who to opt out from. It's very effective, and even though I would never give a 3rd party access to my email account most people do. Now we thought of implementing a similar feature, but from the client side (which is a bit less effective but much more privacy respecting). Now I'm not sure from what I read if we need a security audit or not, but the risk and the extra work isn't worth it for us. We're a nonprofit. Our compatitors on the other hand are a VC backed commercial organization. They make money buy providing a service to the companies they help people opt out of. The whole opt out side is just a way of manufacturing demand, so you can guess where their loyalty lies. But because they are well funded and because sending opt out emails is basically marketing for them, it makes sense for them to pay for an audit. At the end of the day, the user suffers.
- pas 4y agothe user already suffers by "Google" cross-financing all these free things (from search itself to mail, chrome, android, and ... go, k8s, project zero, and who knows what) and I've added the quotes because of course everyone else does that, and it trains users (and now since everyone is a user it basically conditions society) to have unrealistic expectations, skews what people value, completely fuck up the market (hard to compete with free) ... that said, in the end the user gets what it wants "opt out", and it's free for them.
- onphonenow 4y agoGoogle SHOULD NOT promise anything else. This is critical for users security. Yes, developers and business claim they make user data, privacy and security a top priority. As we have seen from plenty of developers on the facebook platform, if not checked, they far to often lie, betray users trust or are just totally incompetent. At least on the business side, giving restricted scopes access (ie, enabling a third party server to read all emails in a domain) is a major permission. It needs to be treated like this. In many cases a problem here unlocks a LOT more because email is used the default password for everything (via password reset options and more). I hope google holds a firm line here and doesn't bow to hacker news type social media pressures - we have too much evidence of bad and poor behavior by developers to just trust them.
- userbinator 4y agoGoogle is also one to "betray users trust"!
- ForHackernews 4y agoYeah, imagine if users didn't have benevolent Google protecting them, some unscrupulous company full of unethical developers might scan all their personal email, or monitor what websites they visit, or even collect biometric data and then track their every waking movement in the real world.
- onphonenow 4y agoLet me repeat this very clearly here. HN folks seem to think that developers in the internet at large are "good" and google is evil. Or that things like google asking random developers from china to go through a security assessment is appalling. I can tell you that for businesses and others spending money (ie, where the business is the customer and not the product) the perspective is opposite this. A business wants google to track users so logins from unusual locations / devices go through more rigorous authentication. That is considered a benefit, not a harm. A business wants google to scan everyone's email - for everything from phising to spam to malware. This is considered a benefit not a harm. I think folks here underestimate just how trusted and core to many individuals and businesses google is. Many folks trust google MORE than they do their own goverment, including on issues of spying on emails and more. The goverment leaks everything - from photos of dead celebrities to tax returns. Many goverment are active in spying on their users as much as they are able. Around the world, brands like Apple and Google considered evil here on HN, have just insane brand value. Again, Google are idiots if they were to go the facebook route and not keep the private info they hold pretty secured. The downsides are SO much larger for them (see Cambridge Analytics) than the upsides of allowing random third party internet developers to access someone's email on an ongoing and programmatic way without these types of controls.
- Fizzadar 4y agoNot sure where this is from but there's a critical part of the quote missing here: > Every app that requests access to restricted scope Google user’s data and has the ability to access data from or through a third party server is required to go through a security assessment An email client that only transmits data to/from Google's own IMAP/SMTP servers does not have the ability to access data through any third party server, and thus does not require the audit. Source: https://support.google.com/cloud/answer/9110914?hl=en#zippy=%2Csteps-for-apps-requesting-restricted-scopes%2Csecurity-assessment https://support.google.com/cloud/answer/9110914?hl=en#zippy=...
- pferde 4y agoWhat about e-mail clients which allow you to configure multiple accounts at different e-mail providers? Those will be able to access your Gmail data, and also "data from or through third-party servers" in form of receiving or sending e-mail via different mail servers.
- tiernano 4y agoIs it not "proxy" like servers they are talking about? You login and the details are stored on a server which does push notifications and the like... instead of your phone polling or pulling email all the time, the proxy server sends a push to the app to update when new mail arrives... is this what they mean?
- undecisive 4y agoIt certainly includes that, yes. In fact, mobile push notifications is one case that I hadn't even thought of. If you use a third party to perform push notifications, you are "accessing" data through a third party application. (I'm presuming the word "accessing" is used here to mean any use of a third party server, regardless of whether read or write - because the whole idea is pointless if transmitting is not included in the definition) It also includes any email client with a built-in VPN, or potentially any client that can use a VPN (remember, it's at Google's discretion)
- 4y ago
- Alex3917 4y ago> The third party audit is not required for email clients that run on end users computers and store credentials locally. It might not be required for applications that run locally, but they don't tell you whether or not it will be required until after you've already done the work to create the app. The exact wording from the FAQ is: "Local Data Storage: Local client applications don't need to undergo a security assessment because data is run, stored, and processed only on the user's device. Local client applications that only allow user- configured transmissions of Restricted Scope data from the device may be exempt from this requirement." Keep in mind that any email client that allows you to reply to (or forward) an email would count as transmitting restricted scope data from the user's device.
- joshuamorton 4y ago> Keep in mind that any email client that allows you to reply to (or forward) an email would count as transmitting restricted scope data from the user's device. Not if it does so only via the oauth api?
- Fizzadar 4y agoThe OAuth verification FAQs state: > Ensure your app complies with the Google APIs Terms of Service, Google's API Services User Data Policy, and the Additional Requirements for Specific Scopes, which includes undergoing an annual security assessment if your app accesses restricted scope Google users data from or through a third-party server. In the case of an email client data is transmitted directly from/to Google's own IMAP/SMTP servers and not a third party, and is thus exempt from the assessment.
- antisthenes 4y agoYour client seems interesting Is there any reason it can't work on Windows 7?