11 ms·
DO NOT GIVE THIS ACCESS TO YOUR WORK EMAIL! DO YOU NOT GIVE THIS ACCESS TO YOUR WORK EMAIL! There is no source code, and it gets READ access to your meetings!
by animal-hash 3y ago
DO NOT GIVE THIS ACCESS TO YOUR WORK EMAIL! DO YOU NOT GIVE THIS ACCESS TO YOUR WORK EMAIL!
There is no source code, and it gets READ access to your meetings!
Please do not make the error and give a non-vetted source access to your PRIVATE data!
- pkiv 3y agoThis is no different than using Reclaim.ai or Calendly with your work calendar. Obviously you should do your diligence with what software you give access to your calendar, but this likely isn't the first SaaS that has access these days...
- animal-hash 3y agoThe app wants you to mindlessly click through Google's access permissions without a second thought as to the impact of your actions. Flashy application with no contact information or legitimacy trying to access data. Your alarm bells should be going off at that point.
- klyrs 3y ago> Your alarm bells should be going off at that point. Whenever the erosion of privacy comes up, folks here point to regular folk being ambivalent until their identity is stolen. But even among the tech literate? Chill, don't worry, everybody is reading your work email!
- gumby 3y agoWith valuations down these days there's a great opportunity to do a rollup of spyware SaaS like these. It's the modern day equivalent of tossing USB sticks in the parking lot.
- SturgeonsLaw 3y agoFWIW Calendly claims that they do not collect appointment contents, only the time and duration. They could, from a technical perspective, but their privacy policy states that they don't.
- paulddraper 3y agoSoooooo.....like Calendly?
- animal-hash 3y agoCompare Calendly's website filled with contact information, social media links, or pricing data to this skeleton site.
- carlosdp 3y agoNone of those things actually make any impact into how secure or privacy-preserving an app is...
- TylerE 3y agoWhy does stuff that's very easily "faked" (e.g. mail address at a UPS Store, etc) actually mean anything? This seems like paranoia theater.
- dao- 3y ago> © copyright 2023 > Meeting Swipe > Worldwide Corporation Here's me wondering what that's even supposed to mean.
- Waterluvian 3y agoGood point. Shouldn’t be using that either.
- acheron 3y agoI guess. Do people really connect work accounts to shit like that? Where on earth do you work?
- paulddraper 3y agoHow do clients/candidates/vendors schedule time with you?
- 3y ago
- paulcole 3y agoHow else would you use this to manage work meetings without giving it access to your meetings?
- altairprime 3y agoHow else would you gain access to tens of thousands of work calendars for espionage? It only takes one day to write an app like this, and endless waves of tech people will give up their data for the chance to downvote a meeting.
- paulcole 3y agoIf you like the idea of swiping left on meetings to cancel them then you're going to have to either pray someone makes a privacy respecting version of this that meets your standards (or make it yourself) or give up some level of privacy to use someone else's app and take the good with the bad.
- 0xbadcafebee 3y agoDude. Do you realize how many companies (of all sizes) use things like Trello, putting proprietary information into a free website that can do anything it wants with the data? Meetings are barely the tip of the iceberg.
- faitswulff 3y agoIn the same vein, it's very funny to me how many people are feeding proprietary information to LLMs without giving a damn about their employer's stance on data privacy.
- hamandcheese 3y agoAt least with LLMs I get something useful in return.
- graphe 3y agoAnd that's why I send it info. I used to send Google feedback until I realized it did nothing and stopped being not not evil.
- 8n4vidtmkvmk 3y agoMy employer is explicitly against us putting stuff into chat gpt. Which is fair. But sad.
- reitanqild 3y agoI'm lucky because at the moment I work at a public project that is meant to be public and there is no issue at all with checking an LLM. That said, lately I have favored Kagi FastGPT for two (three) reasons: - I trust Kagi a magnitude more (or even more) than I trust any FAANG company except Apple [1][2]. - It seems to be way more up to date. - (It seems a bit less shy.) [1]: Why? Sound business plan, incentives align. [2]: Does it mean I trust them? No, that would have meant I hadn't learned a thing from WhatsApp. And no, after the photo snooping stunt from Apple a couple of years ago I don't trust them either, I only consider them my best option at the moment.
- carlosdp 3y agoUm, yea, I would expect an app that is meant to help manage your meetings needs access to your calendar invites... that's the whole point. If you used this logic, you couldn't use any non-open-source calendar tool, or apps like Superhuman.
- josephcsible 3y agoYou connect non-open-source third-party tools to your work calendar? I certainly don't.
- derefr 3y agoDo you give hire an accountant to do your company's taxes? If so, what's the difference?
- Veserv 3y agoAccountants are hired under confidentiality agreements. Connecting random third parties to your systems that have "we are allowed to do anything we want at any time" agreements is kind of the exact opposite of that.
- PoignardAzur 3y agoConfidentiality agreements aside, the scale isn't the same. Accountants have tens of clients, online apps have thousands or millions. For an app, the relative benefit from skimming a bit off every client is higher, the relative cost of losing one client who notices is lower.
- TeMPOraL 3y agoAs others said, accountants are hired under confidentiality agreements. What that means is, should said accountant breach my trust, they're an easy target to hit with a lawsuit. The possibility discourages scammy behavior and establishes some baseline trust. Big corporations are also good targets for lawsuits - they may not be easy, but they are stationary, and if you have a good case, chances are many other people have one too. This is, again, establishing some baseline of trust, even in absence of a proper business contact. Random SaaS / fresh startups? They're a highly-mobile targets. There's a good chance they may close shop and disappear overnight. There is no baseline of trust there, and much more thorough due diligence is required.
- aaron695 3y ago[dead]
- w-ll 3y agoim with ya. im surprised there is not a flag meeting creates to limit scope and api info.
- TobyTheDog123 3y agoDefinitely totally 100% unrelated, but do people notice that their security teams often focus on minuscule unlikely scenarios instead of potentially-company-ending bugs and exploits? Things like your MacOS install being on 12.3.1 instead of 12.3.2, blindly listing off AWS/GCP recommendations without any consideration to how the service is implemented and/or how the infrastructure is used, or making engineering teams jump through seventeen hoops to deprecate an endpoint..... all while there's like a SQL injection in the primary public-facing customer API or something.
- klooney 3y agoWell, comparing version numbers is easy, and analyzing code is hard, so...
- deely3 3y agoWe have to have some level of trust. Otherwise we will need to manually and personally verify each line of each software that we use. And unfortunately this is impossible.
- staunton 3y agoSecurity teams focus on requirements and objectives which are set by far removed entities and at vastly different generality and abstraction levels, often with objectives other than "make sure we and our customers don't get hacked", such as limiting legal liability and navigating a complex landscape of regulation and best-practice recommendations, ignoring which can also lead to legal liability. It should be no surprise that these have little overlap with actual security problems arising in their particular context. A good security team will manage to find the time to also identify and address the actual concrete security issues.
- vasco 3y agoYes same issue in all my jobs. I've found that security and compliance standards for technology companies are created and maintained by accountants, not engineers. In a way this is good because if the engineers fix "the real issues" and the accountants focus on the "generic list that doesn't matter", you still end up catching some different things. Problem is the amount of fake work, as well as slowdowns created in exchange for no extra security.
- henriquez 3y agoNo Privacy Policy => hard pass.
- iakov 3y agoDoes Privacy Policy even matter? It feels like those walls of texts are a kind of "privacy theater" to show users that the company has their shit together. I'm wondering how many Privacy Policies are read by at least on employee of the company, and how many are copy-pasted from the competitor's web.
- henriquez 3y agoIn the U.S. anyway privacy policies identify the company doing business, provide contact information and are legally enforceable by the FTC and states.
- pembrook 3y agoWhile your point is extremely valid, I think it's interesting how different the reaction would have been to a fun tool like this 15 years ago. I doubt this would be the top comment, which makes me wonder how many startups that grew from fly-by-night experiments into giant companies then would no longer be possible now due to everyone's hyper-sensitivity and risk aversion around anything tech-related (which again, is certainly valid). Makes me wonder if this cycle of internet innovation is over, and whether we're now going to be subject to 50+ years of stagnation and increasing regulation while the more risk-averse personality types start dominating. Similar to what happened in the automative industry -- think of the insanity and lack of concern for safety that went on at auto companies in 1920s Detroit that also simultaneously allowed for the core innovation and fast iteration in automotive to happen.
- deleted 3y ago[deleted]
- userbinator 3y agoI think it's interesting how different the reaction would have been to a fun tool like this 15 years ago. My guess would be, even more "do not want". 15 years ago, "cloud" was not even really a thing, and many were understandably very averse to it when it was introduced. If anything, the megacorps have only convinced us to give up more of our privacy since then.
- raxxorraxor 3y agoI have the complete opposite impression. Sure, Facebook an co. do partially depend on people oversharing. But people being careful about their data have seriously turned down their expectations. 10-15 years ago it would be a huge scandal if some software phoned home your software configuration. Today people are ok with unique advertising IDs. Some say data protection today inhibits development. I do not think there is much merit to arguments of this kind. I don't even believe the most important innovations wouldn't have been possible with more data protection at all and that includes huge datasets to feed AI. Maybe the market for data being sold would be smaller. But that isn't innovation really.
- ltbarcly3 3y agoNot my precious meetings!
- moosedev 3y agoI get it - you’re mocking the parent’s framing of this as a security issue. Perhaps it isn’t an issue for you, but in case it’s not obvious, calendar entry titles and descriptions can (and have) contained confidential information that would present various forms of business risk if leaked. BigCo corporate IT policy often forbids placing such information on untrusted third-party hardware/software/services.
- ltbarcly3 3y agoOf course this is a security issue, I was just making a joke about how I hate meetings. If this is confusing see: "Meetings are like lasagna without the cheese—dull, bland, and ultimately unsatisfying." - Garfield "Garfield." Cartoon. Created by Jim Davis. Published May 5th, 1987. Garfield.com, https://www.garfield.com/comic/1987/05/05 https://www.garfield.com/comic/1987/05/05. Accessed 15 May 2023. "Meetings: The art of keeping the people who need to work in a room too long so they can't get any work done." - Dilbert "Dilbert." Cartoon. By Scott Adams. Published October 7th, 2003. Dilbert.com, https://dilbert.com/strip/2003-10-07 https://dilbert.com/strip/2003-10-07. Accessed 15 May 2023. (and yes both references and quotes are fake)
- ilyt 3y ago>There is no source code, and it gets READ access to your meetings! sooo like whatever cloud thing you'd give it access to ?