Because for a lot of people that contains a ton of "password reset" emails with new passwords in plain text.
Because for a lot of people that contains a ton of "password reset" emails with new passwords in plain text.
dons flame suit
We used OAuth to gain access to users' email. We were exceptionally explicit about this—it was the entire point of the service! We only looked at header data but technically we had access to the full text of the email—Google's permissions weren't granular enough for our users to only grant us access to headers.
That was one of our requests to the Gmail team when they announced the Gmail API. I wrote a blog post about its deficiencies from our perspective and one of the engineers on the Gmail team reached out. Mostly, it was just way too slow so we stuck with IMAP.
I was more-or-less running the ingest and storage systems at the time. We were pretty careful and data wasn't shared with any other companies.
IIRC we could access any mailbox/folder in the account.
edit: To be clear, the OAuth prompt clearly says you are granting access to read emails. Yeah, people don't read, but I don't believe we were doing anything wrong.
edit2: Our media coverage (Techcrunch etc) touted the fact we had access to your email—that was the selling point of the entire service! Amazing to me that OAuth has suddenly become evil.
- Tokens can only be used from servers that have been registered with Google, so even if a startup has their OAuth tokens stolen the attacks can't really make requests on their behalf.
- Tokens access has per user and per app rate limits that are configurable in the Google console.
- With read-only OAuth access, there isn't really any value to attackers. E.g. if anyone tried to reset your bank passwords, it would be immediately obvious because they wouldn't be able to delete the password reset emails.
I'm currently (i.e. today) writing a Gmail Add-on that only requires read-only access to the currently open thread rather than requiring it for your entire inbox. (Basically read-only access is granted when you click the icon to activate the add-on within the currently open thread.)
This is something that's become possible in the last six months and is probably a slight improvement from a security perspective, but even the baseline level is pretty solid. The tech industry has yet to see any large OAuth-related security breaches, and frankly we may just never see that given the combination of the good security story and the limited value to attackers.
This seems pretty obvious to me. There are many useful services that do this (SaneBox for example) but DUH how do you expect them to do anything intelligent with your email if they can't read it?
This is all predicated upon the user granting access to their email account though, so this is roughly equivalent to saying "People you sent a letter to can read your letter" ... duh that's why you did it.
The article isn't about some automated service looking at your e-mail. It's about actual humans reading it. Big difference.
Electronic-Mail. That comes with a plurality of baggage associated with the voncept due to the societal concept of Mail.
In the U.S. at least, one's mail IS sacrosanct. The Postal Service, being the message handlers that "set the standard" as it were for other logistics and postage businesses to be measured against DO NOT MESS WITH THE MESSAGE, beyond setting limits on transiting parcels to facilitate smooth operation of the system.
Emphasis mine.
They do not "maintain state" about message history either. They do not scan to detect trends. They do not try to "sanitize" that data to sell to marketers.
Just because there ISN'T a codified rule, DOESN'T mean it's a good idea to go around playing with expectations literally over a century old. If you call yourself a Mail provider of any sort, don't be surprised when people find you looking at correspondences that you end up getting blowback.
Stories (entertainment, not journalism) are filled with people eavesdropping on messages BECAUSE it is exceptional behavior. It wouldn't be worth writing about otherwise.
The type of behavior seems to be especially problematic in the tech world because there is seemingly no cost, or visibility to the non-tech-savvy user that it's happening.
Stop treating the user's data like it's yours. The system is yours. It would have no worth if they weren't using it.
Playing word games and hiding behind the legalese has worked thus far, but the tech literacy of the general populace IS increasing. And if the general populace likes anything, it's common sense and cognitive resonance. Tech will be beaten with the stick once the tech literacy is there.
The privacy reckoning will come if tech doesn't get its act together and GET WITH THE LAST TWO CENTURIES.
I feel like everybody has been brainwashed into thinking Google is awesome and I'm looking at it from a distance, thinking how did they do this.... Tech conferences? Yearly Google io PR?
Somehow people is treating this ad company like they are good guys.
That has obviously changed over the past couple years, in a slow creeping way.
Not really sure that was ever the case?
I remember when they originally launched - with the "Do No Evil" motto - thinking it was PR bullshit.
If they were "pretty not-evil" at some point, from my PoV it'd have to be before that as I was clearly cynical of them already by then.
In fact they are probably worse, given how much personal information they hold on people and how willing they are to ignore local laws and regulations.
It was magnitudes more effective than any marketing I've ever seen Google do. Ethics aside, you could argue that Lifehacker writers should have gotten Google CMO level stock grants.