Elevating user trust in our API ecosystem
cloud.google.com
cloud.google.com
We're a bootstrapped business with nowhere near this kind of cash, so this effectively means Google are shutting our service down.
What's crazy is that while this might help protect from negligent developers accidentally losing a few user keys, it doesn't really solve the real problems like it's claiming to. It in no way protects you from the worst offenders, the Cambridge Analytica's out there, the ones with plenty of cash, from still stealing or abusing your data. They can just pay to make this go away.
This is seriously bad news for any independent developers or small companies who are building apps on top of Google's API.
It seems like an attempt to address bad publicity in the articles mentioned below - which largely boiled down to misleading reporting. And the remedy doesn't accomplish much outside hurting small developers and Google's reputation in the ecosystem.
I'll never build anything on top of Google again. I might end up repurposing my work on top Outlook instead. From what I've heard, they are much more supportive of their developers.
Worst of all, this won't stop intentional bad actors from stealing user data for whatever purposes they have in mind. Big pockets are going to laugh even at a $75k fee.
Also, this isn't a bad move AFAICT (tightening policies and access to a very important API), but it's evidently a reaction to the backlash from that WSJ "exposé" about the scandalous fact that email providers allow third parties to read/manage your inbox... if you give the third parties permissions and access tokens. That was just dirty reporting and intentionally misleading average readers--the comments on that article were all akin to "I knew Google was reading my emails!". And I don't see this change mattering much to those people.
EDIT: at least I think I do. I tried to find a reference to this in my project note, to confirm the timestamp, but I failed. So it could be I've seen it in October 2018, as 'Ivoirians pointed out.
Also, this announcement says it first came out in October 2018, while the WSJ article came out in July 2018?
I tried to confirm the date I saw this in my project notes, and failed, so maybe I indeed saw it in October. If so, and if WSJ report came out months earlier, then maybe it is indeed a reaction.
A scaling system based on number of users and other factors would probably be better. Look at the list of requirements for a security audit [0]. I'd imagine many small businesses would struggle to sort out everything listed there.
I'm not a fan of removing user choice. If someone has established trust out-of-band then they should be able to opt-in after acknowledging that they accept and understand the risks. But I guess we need big daddy Google to step in and protect us, since we're too dumb to critically asses the situation.
Something that nobody seems to be mentioning is that you need to perform these security assessments on a yearly basis. Talk about drastically raising the barrier to entry...
[0] https://support.google.com/cloud/answer/9110914#assessment-i...
You can have unlimited developers using the app from accounts with your domain.
You really should get at least 250 users though, since at $10 / user / month that would be enough to cover the cost of the security assessment, and the assets under protection are going to be minimal enough so as to not attract any non-automated attacks.
Even if the answer is that Google is indeed shutting out free/not-for-profit and pre-revenue apps (collateral damage), it should at least be stated explicitly.
I'm not horribly against this policy, email is pretty central to a lot of peoples' world, and I suspect there's lots of really really scummy actors out there. In an ideal world I'd be able to say "hey this is my email and I personally wrote the code accessing it, so let it do what it wants".
It uses some of the "restricted" scopes[2].
Also, what does the verification as "non-malicious software" entail?
[0] https://github.com/gauteh/gmailieer/
[1] A cli program that downloads one's (i.e. the user's) gmail e-mails onto one's computer (without touching any third-party servers on the way) — it's effectively a better offlineimap for gmail, for use with notmuch.[3]
[2] https://support.google.com/cloud/answer/9110914#restricted-s...
"The owner and users of your apps belong to the same G Suite domain or customer."
https://support.google.com/cloud/answer/9110914?visit_id=636...
Having a whole lot of bureaucracy and cost from Google is not going to help and is going to cause us a lot of hassle.
To me this sounds very much like an anti competitive measure aimed at shutting down the vast majority of third party software currently accessing their APIs and forcing users to use their official apps to access their email.
Linkedin did a similar move a few years ago where they basically shut down their entire API ecosystem in favor of tightly controlled partnerships with selected partners. Twitter killed the market for third party UIs as well.
$15k+ barrier refers to a mandatory security assessment fee -- see "How will the security assessment work?" on the FAQ