4 ms·
Not sure where this is from but there's a critical part of the quote missing here: > Every app that requests access to restricted scope Google user’s data and
by Fizzadar 4y ago
Not sure where this is from but there's a critical part of the quote missing here:
> Every app that requests access to restricted scope Google user’s data and has the ability to access data from or through a third party server is required to go through a security assessment
An email client that only transmits data to/from Google's own IMAP/SMTP servers does not have the ability to access data through any third party server, and thus does not require the audit.
Source: https://support.google.com/cloud/answer/9110914?hl=en#zippy=%2Csteps-for-apps-requesting-restricted-scopes%2Csecurity-assessment https://support.google.com/cloud/answer/9110914?hl=en#zippy=...
- pferde 4y agoWhat about e-mail clients which allow you to configure multiple accounts at different e-mail providers? Those will be able to access your Gmail data, and also "data from or through third-party servers" in form of receiving or sending e-mail via different mail servers.
- tiernano 4y agoIs it not "proxy" like servers they are talking about? You login and the details are stored on a server which does push notifications and the like... instead of your phone polling or pulling email all the time, the proxy server sends a push to the app to update when new mail arrives... is this what they mean?
- undecisive 4y agoIt certainly includes that, yes. In fact, mobile push notifications is one case that I hadn't even thought of. If you use a third party to perform push notifications, you are "accessing" data through a third party application. (I'm presuming the word "accessing" is used here to mean any use of a third party server, regardless of whether read or write - because the whole idea is pointless if transmitting is not included in the definition) It also includes any email client with a built-in VPN, or potentially any client that can use a VPN (remember, it's at Google's discretion)
- undecisive 4y agoI intentionally simplified that language to > [accesses Gmail and also accesses other servers] ... because that's all that convoluted line means. Break it down: - Access to "restricted scope Google user's data" (in this case, all we care about is Gmail) - AND ability to access data from or through a third party server. It's that last bit that people seem to be getting confused about. For example: - if your app accesses Gmail and Hotmail accounts, then your app is doing both - if your app accesses Gmail and also checks today's weather, you're doing both - if your app accesses Gmail and sends basic usage telemetry. Or checks for updates. Or has plugins that provide spam checking or virus scanning... you're probably doing both - if your app has ANY plugin system, it could be argued that your app is doing both. While the language may be unclear, "third party server" is probably intended to reference any non-google service. And my overall point still stands: YOU do not get to decide what triggers their security review. All you have the right to do is pay the bill.