Elevating user trust in our API ecosystem
developers.googleblog.com
developers.googleblog.com
A click on that icon should display a popup which explains who it is, a link to the privacy policy, date when the Integration was enabled, count of how many emails it has seen, and provides an option to disable the integration with a single click. It would be nice to have the ability to apply filters to limit which emails are shared with that provider in the future.
It’s too easy for users to add an Integration at one point and forget months or years later that it’s active. But also mentally when people add these add-ons it often doesn’t really click exactly that you are literally Bcc’ing the add-on every message you send.
There is precedence for this kind of UX change and Google. It used to be that chrome extensions could optionally add icons to the Chrome menu (the icons to the right of the address bar). Now all Chrome extensions appear in the Chrome menu, both reminding the user that it is there and also giving an easy way to remove the extension should they no longer need it.
> Your app will have the remainder of 2019 to complete the assessment.
> The assessment fee is paid by the developer and may range from $15,000 to $75,000 (or more) depending on the size and complexity of the application.
> This fee is due whether or not your app passes the assessment; the fee includes a remediation assessment if needed.
Personally, I feel like people in general are too quick to hand apps access to their machines. For example, I know a bunch of people who used grammarly, and I said to them at the time - wait, you're basically installing a key-logger that sends your data to a 3rd party - what happens when they lose it?
And then, there’s is often nothing I can tell people to make them afraid. Sure, I’d never do such a thing. But because I don’t trust the corps, not because I could really articulate what bad could possibly happen in the worst case.
I imagine most people wouldn't really want to do that, even if they believed they had nothing to hide and use apps like kayak.
Might be a good way to make a point (or maybe not, but it's interesting to think about).
I guess maybe it's like how you're comfortable talking about a medical issue with a doctor you've never met before, but you wouldn't necessarily want to discuss it with friends.
They're making a choice to sacrifice privacy for convenience but in your example it's sacrificing privacy for no benefit.
You need only to send your friend an email:
"Steve,
Please remember to bring the poison and knife tonight when you meet me under the bridge at 12am at 1st and Congress. I will meet you there with the cocaine and unmarked bills. I appreciate your help in this matter, and suspect Bob will not see it coming."
Owning a keyboard is potentially "giving everything you type to a company". Connecting to the internet at all is possibly giving the whole world access to your machine. Using ANY service is giving them information about you that could be used against you.
Why are those tradeoffs okay, but giving a company access to your email not (access, which is already given to Google as the one actually running the email service)?
Nobody is saying they want it to be a free-for-all where anyone that gets access to your information can use it any way they want with no security or tools in place to manage it. But I feel I should be allowed to decide who I'm able to give my information to, especially when I get something in return. And I want there to be controls in place to prevent abuse, I want to be able to revoke that access at any time, and I want the legal system to be on my side if things go wrong, but I don't want someone condescendingly trying to make me "afraid" of a conscientious decision I made that is making my life better and all parties involved are happy with.
Just like how you shouldn't be lambasted for using a keyboard which could possibly contain a keylogger embedded in the device, I shouldn't be insulted for wanting to use tools and services on my information that benefit me.
But I really appreciate the response! It's a nice breath of fresh air when someone responds like you did, especially when my comment was a lot more aggressive.
There's not going to be an easy solution for this kind of stuff, but at the end of the day I feel it's a necessary evil, very similar to how many countries deal with freedoms or natural rights.
If we err on the side of giving people choice, that means that more bad actors will be able to hurt than if we didn't. But I feel that freedom is something to be protected, and it is worth the added work and risk of allowing bad actors to get a foothold.
Not clear what "verified as non-malicious" means in this case, w.r.t. cost.