5 ms·
> you will be paying that invoice whether or not you needed that assessment They don't just send you a bill for $10k. You can opt-out of the yearly audit by re
by ed 4y ago
> you will be paying that invoice whether or not you needed that assessment
They don't just send you a bill for $10k. You can opt-out of the yearly audit by removing your use of restricted scopes.
But yes, it is a yearly required audit, and they're serious about it. This limits the kind of apps that can be built on Gmail (basically – no free apps), but it is undoubtedly better for end users.
Having gone through the process, which checks among other things that data can't be resold, tokens are encrypted, user data is really deleted when you say it is, and that Gmail API access is auditable in the event of a breach; these are all good things for users.
(My auditor was so thorough they actually found a high-impact XSS bug in Firefox – the bounty covered part of their fees.)
- yoaviram 4y agoIt's not necessarily better for the users. I'm one of the founders of a free and open source service which simplifies the process of sending CCPA/GDPR data deletion requests. A common request from our users is to give them good recommendation on who to opt out from. A new compatitor has implemented a feature where they use the Gmail API to analyse a user's email exchange (from their servers) in order to recommend who to opt out from. It's very effective, and even though I would never give a 3rd party access to my email account most people do. Now we thought of implementing a similar feature, but from the client side (which is a bit less effective but much more privacy respecting). Now I'm not sure from what I read if we need a security audit or not, but the risk and the extra work isn't worth it for us. We're a nonprofit. Our compatitors on the other hand are a VC backed commercial organization. They make money buy providing a service to the companies they help people opt out of. The whole opt out side is just a way of manufacturing demand, so you can guess where their loyalty lies. But because they are well funded and because sending opt out emails is basically marketing for them, it makes sense for them to pay for an audit. At the end of the day, the user suffers.
- pas 4y agothe user already suffers by "Google" cross-financing all these free things (from search itself to mail, chrome, android, and ... go, k8s, project zero, and who knows what) and I've added the quotes because of course everyone else does that, and it trains users (and now since everyone is a user it basically conditions society) to have unrealistic expectations, skews what people value, completely fuck up the market (hard to compete with free) ... that said, in the end the user gets what it wants "opt out", and it's free for them.
- ed 4y agoWhy not run the tool clientside? You don’t need an audit unless you’re doing something with the data on your end.
- yoaviram 4y agoAre you sure about this?
- ed 4y agoYeah, it’s what I was told by a member of the verification team last year (as long as everything is clientside, you can bypass the audit). Before you build anything you should request the restricted scopes in Google’s Cloud Console as if the feature is already built, to kick off the verification process. Then you can ask a human for clarification (IIRC the exemption isn’t mentioned in the FAQ). Assuming it’s okay, you can then build the feature and resubmit your request. Best of luck!
- undecisive 4y agoThe context here is Free and Open Source Software that accesses email. Software that, for now, under Google's current interpretation of the rules, is allowed to use their OAuth without paying these fees. The question I'm asking is, what happens next year when Google decides to silently change their interpretation of the rules? Do you, as a FOSS email client writer working on JohnnyMail, risk a massive yearly bill of 1/6th or more of your salary that you are contractually obliged to pay - or just say "Sorry Google, you've outpriced me" while their interpretations are still favourable? It's not "undoubtedly better for end users" that free email apps be excluded from Gmail. It's not better for end users that open source software developers are given a sword of Damocles hovering above their heads. Sure, it's undoubtedly better if these free apps can be guaranteed to be secure, it would be even better if Google could do that in a way that didn't cost a massive amount or a surprise bill. I'm glad you had the resources to be able to go through the process, and that you found it a useful process to go through. But it doesn't justify the uncertainty.
- ed 4y agoThis isn’t about profit. Google doesn’t want to pay for security audits. You pay the auditor directly. I suppose Google could charge for future access. Any platform could. But not retroactively. That would need to be in a contract and it’s not.