Google launches new security features to protect users from unverified apps
techcrunch.com
techcrunch.com
But I guess that is a bit too much typing for most people.
I would have thought by now it would be pretty easy for algorithms or AI to pick up on these kinds of tricks, whether by a similarity score or an image processing approach.
On the other hand, this warning will probably happen a lot! Is Google going to be able to "validate" apps fast enough?
If an app takes days to make, requiring 5 minutes extra review effort to get it whitelisted seems fine.
A non-prohibitive barrier to entry wouldn't be a big issue, as users in general want stricter filters that mean less shitty apps instead of looser filters that mean simply more apps.
Human reviewers today, but once the training set is large enough you can start to let computers take over with human reviewers reviewing the lower certainty cases until the certainties rise further.
Start all-manual. Perhaps you only do it with a subsection of applications. Pay an extra fee and you get "certified" with special app placement. Then you start all-manual. You look for the people who are the best at finding issues, and pair them with programmers, and make the tools for the things that are gruntwork for them.
Build more and more tools, and you pull more and more people into the program as you build more and more intelligence into the machine.
Let the humans do the NP-hard portions. I'm sure this is what Apple has to be doing behind the scenes.
Manual prompts to users are a great way to develop training data and being able to distribute them at scale to millions of users means you can develop training data in very short order.
Automated tasks are not good at outsmarting humans. When you want to review a human's work for security, you need humans somewhere along the process.
Automation can help those humans do their jobs, but it's simply not a solution here.
AI and machine learning are most effective these days when they help assist people (flagging potentially malicious code, bubbling up anomalies, etc.), and it isn't that expensive to get a pair of eyeballs to double check conclusions!
User types "continue"
https://www.theverge.com/2017/5/3/15534768/google-docs-phish...
It allows an attack to present a user with a real Google 'account select' page with their account listed, but if they click that link it actually redirects them to another site (which you can dress up to look like the password page the user is expecting).
It is arguably worse than the previous issue, as I don't need a hoax extension, I can just manipulate the link to inject the malicious redirect behaviour.
They have triaged it and I'll probably write up a report once they are happy for me to do so.
I highly recommend protonemail.com. Has all the bells and whistles and its major feature is user privacy and security.
Both statements are true: It's a good thing. It's not right to have one company with so much power
No evil Google required.
"Доверяй, но проверяй" (trust, but verify)
It's very important to always question decisions made from a position of power; vigilance is the price of freedom. Questioning does not necessarily mean disapproval. Everyone concerned about the future of the internet should be questioning Google's motives and intentions every time they unilaterally exercise their power to judge which apps are "acceptable".
In this case, it shouldn't take long to find the answers to that question: Google should have implemented this kind of dismissible warning a long time ago. Hiding the "continue" option behind the possibly-misleading "Advanced" link is a minor problem, but some sort of warning is obviously necessary. (I'm actually impressed they used a type-this-word check instead of yet another ignorable "go away" button.)
Yes, some people will rag on Google for anything, but there are valid concerns when such changes are made without warning that breaks current functionality. Per the article, this time Google just enabled it for new apps with plans to roll it out to existing apps, but in the past Google as not been as courteous.
It's the classic xkcd situation that every change breaks someone's workflow; the difference being that when you're Google's size and have Google's reach of influence, you end up breaking a lot of someones workflows.
Where does this attitude stem from anyway?
I have a theory that popular opinions within social groups can reach a sort of tipping point.On one side of the tipping point, the company is seen as basically a bunch of good guys who may make occasional mistakes - but who doesn't? And they're always quick to correct them, or they're out of understandable commercial necessity.
On the other side of the tipping point, the company is seen as basically a detrimental force, hungry to gather and abuse monopoly power, responsive and accountable to no-one, and motivated only by things that will let them take more money and power from the likes of us.
Of course, for any company the size of Google / Microsoft / Apple / Facebook the answer is a little of column A, a little of column B.
But how people will see a given action depends on what side of the tipping point a company is on. When a company does something like buying another company's patent portfolio (for "defensive purposes"), or buying a startup and making their paid offering free, it'll confirm your existing beliefs - whichever side you were on.
If you went to Slashdot in the 90s, Microsoft could do no right - they could give free PCs to orphanages, and there'd be people saying they only did it to cement the dominance of Office.
I'd say Google is just kinda hovering around that tipping point right now, in HN's median opinion. Some people think it's on one side, some on the other.
Of course, us online-forum-readers and designers have to take some of the blame for this sort of reductionism - it's easy to comment without reading the article, or to design a system where parroting the collective opinion is rewarded with upvotes.
In a fairly short period of time, people started seeing the same kind of "We're in charge and you're going to use _____ and like it!" attitude that Microsoft was once famous for. People wanted Plus about as much as they wanted Vista, but it got shoved on them anyway.
In more recent years—with AMP pages (and authors on Plus) getting an edge in search, google.com badgering users to install Chrome, a successful embrace->extend->extinguish strategy being executed against open source Android, etc—moves like this one don't look so innocent as they would have coming from the smaller, goofier and cheerier Google of 2005.
1: http://www.businessinsider.com/larry-page-just-tied-employee...
No it's not. It's Google telling it's users which apps to use and not to use. For regular users Google presents itself (just like Apple does) as an authority of what's a good app. Any other apps automatically are not good in the mind of regular users.
Sorry but that's a bit of an ignorant non-argument. Given the size of Google, I believe that it is important that users can use the apps they want, not the apps that Google wants them to use.
Protectionism does not make using Google's services more secure. It serves Google, not its users.
Again, this is NOT about Android or Chrome apps. So yeah, go use whatever apps you want, as long as it doesn't want the users to grant the developer permission to do stuff with the user's Google account, this does not affect you in the slightest.
I agree that for most web app this will be an extra formality. For me personally the key point is that there will be web apps that Google does not agree with from a business POV. That is my real problem with this.
If this list was curated by a community rather that Google, I would not have a problem with it.
For apps that aren't vetted you have to confirm that you really intended to give them access. This is good! It protects most users who aren't a genius like yourself.
Even if you're not verified, users can still grant your app access! Nothing is blocked! Google just wants to be sure the user realizes what is going on.
It's certainly worth acknowledging that even if users aren't truly blocked, they may be turned away from legitimate apps that just haven't gone through the review process yet -- too many extra clicks, concerns about the legitimacy of the app, whatever.
I wonder how this in particular differs from the vetting process for any mobile app store (Apple's App Store in particular comes to mind with its reputation as a walled garden [1], but Android does also warn the user when enabling the installation of third-party apps not on the Play Store).
[0] http://www.pcworld.com/article/3194816/security/google-docs-...
[1] https://en.wikipedia.org/wiki/IOS_app_approvals
Disclaimer: while I work at Google, I have nothing to do with OAuth or any other user-facing interface.
Perhaps it should have a "tell me when they're verified then" option.
> No it's not. It's Google telling it's users which apps to use and
> not to use. For regular users Google presents itself (just like Apple does)
> as an authority of what's a good app.
It's not a good app/bad app question. It's a "can I trust the person who built this app with access to my private data" question that this is attempting to help with. It's not about good apps/bad apps - it's about access to your data. Including data that could be very sensitive.The validation process does not look onerous:
https://support.google.com/code/contact/oauth_app_verificati...
It's an extra step, and therefore probably frustrating to a number of people - but I have a hard time seeing how taking a few minutes to declare your intentions around private data usage with the entity supplying that data for your use is a bad thing. I hope other OAuth providers go in a similar direction - that way developers don't just go with "easier" paths that are less secure for their users.