By the looks of it Pegasus falls into this category and should not have any issues getting approved (still need the YT video and such but the Google team are surprisingly responsive and helpful in my experience).
By the looks of it Pegasus falls into this category and should not have any issues getting approved (still need the YT video and such but the Google team are surprisingly responsive and helpful in my experience).
Do you have evidence - in writing - to the contrary from a Google official?
Abridged wording and my non-lawyer interpretation below in case I'm not clear:
> Every app that [accesses Gmail and also accesses other servers] is required to go through a security assessment from Google empanelled security assessors. [...]
> In order to maintain access to restricted scopes, the app will need to undergo this security assessment on an annual basis, [... costs usually] between $10,000 - $75,000 (or more) [...]
> This fee may be required whether or not your app passes the assessment and will be payable by the developer."
For all my fear mongering, I should point out that the only reason Google are saying this is to cover their backs when they decide to levy the maximum fee on an unsuspecting competitor. If they don't consider you a direct competitor, you might be ok. They have no reason to use this policy to alienate the majority of desktop applications that connect to email.
But they also have no repercussions if they do.
They don't just send you a bill for $10k. You can opt-out of the yearly audit by removing your use of restricted scopes.
But yes, it is a yearly required audit, and they're serious about it. This limits the kind of apps that can be built on Gmail (basically – no free apps), but it is undoubtedly better for end users.
Having gone through the process, which checks among other things that data can't be resold, tokens are encrypted, user data is really deleted when you say it is, and that Gmail API access is auditable in the event of a breach; these are all good things for users.
(My auditor was so thorough they actually found a high-impact XSS bug in Firefox – the bounty covered part of their fees.)
A new compatitor has implemented a feature where they use the Gmail API to analyse a user's email exchange (from their servers) in order to recommend who to opt out from. It's very effective, and even though I would never give a 3rd party access to my email account most people do.
Now we thought of implementing a similar feature, but from the client side (which is a bit less effective but much more privacy respecting). Now I'm not sure from what I read if we need a security audit or not, but the risk and the extra work isn't worth it for us. We're a nonprofit.
Our compatitors on the other hand are a VC backed commercial organization. They make money buy providing a service to the companies they help people opt out of. The whole opt out side is just a way of manufacturing demand, so you can guess where their loyalty lies. But because they are well funded and because sending opt out emails is basically marketing for them, it makes sense for them to pay for an audit.
At the end of the day, the user suffers.
and I've added the quotes because of course everyone else does that, and it trains users (and now since everyone is a user it basically conditions society) to have unrealistic expectations, skews what people value, completely fuck up the market (hard to compete with free)
...
that said, in the end the user gets what it wants "opt out", and it's free for them.
Software that, for now, under Google's current interpretation of the rules, is allowed to use their OAuth without paying these fees.
The question I'm asking is, what happens next year when Google decides to silently change their interpretation of the rules? Do you, as a FOSS email client writer working on JohnnyMail, risk a massive yearly bill of 1/6th or more of your salary that you are contractually obliged to pay - or just say "Sorry Google, you've outpriced me" while their interpretations are still favourable?
It's not "undoubtedly better for end users" that free email apps be excluded from Gmail. It's not better for end users that open source software developers are given a sword of Damocles hovering above their heads. Sure, it's undoubtedly better if these free apps can be guaranteed to be secure, it would be even better if Google could do that in a way that didn't cost a massive amount or a surprise bill.
I'm glad you had the resources to be able to go through the process, and that you found it a useful process to go through. But it doesn't justify the uncertainty.
I suppose Google could charge for future access. Any platform could. But not retroactively. That would need to be in a contract and it’s not.
Yes, developers and business claim they make user data, privacy and security a top priority. As we have seen from plenty of developers on the facebook platform, if not checked, they far to often lie, betray users trust or are just totally incompetent.
At least on the business side, giving restricted scopes access (ie, enabling a third party server to read all emails in a domain) is a major permission. It needs to be treated like this. In many cases a problem here unlocks a LOT more because email is used the default password for everything (via password reset options and more).
I hope google holds a firm line here and doesn't bow to hacker news type social media pressures - we have too much evidence of bad and poor behavior by developers to just trust them.
I can tell you that for businesses and others spending money (ie, where the business is the customer and not the product) the perspective is opposite this.
A business wants google to track users so logins from unusual locations / devices go through more rigorous authentication. That is considered a benefit, not a harm.
A business wants google to scan everyone's email - for everything from phising to spam to malware. This is considered a benefit not a harm.
I think folks here underestimate just how trusted and core to many individuals and businesses google is. Many folks trust google MORE than they do their own goverment, including on issues of spying on emails and more.
The goverment leaks everything - from photos of dead celebrities to tax returns. Many goverment are active in spying on their users as much as they are able. Around the world, brands like Apple and Google considered evil here on HN, have just insane brand value.
Again, Google are idiots if they were to go the facebook route and not keep the private info they hold pretty secured. The downsides are SO much larger for them (see Cambridge Analytics) than the upsides of allowing random third party internet developers to access someone's email on an ongoing and programmatic way without these types of controls.
The point isn't that Google is evil and random devs are good. The point is that Google is amoral and harmful - and also enormous and powerful. Random small developers may be good, bad, whatever, but they are diverse and individually powerless. Should you be more afraid of the Stasi or of a neighborhood burglar?
> Every app that requests access to restricted scope Google user’s data and has the ability to access data from or through a third party server is required to go through a security assessment
An email client that only transmits data to/from Google's own IMAP/SMTP servers does not have the ability to access data through any third party server, and thus does not require the audit.
Source: https://support.google.com/cloud/answer/9110914?hl=en#zippy=...
(I'm presuming the word "accessing" is used here to mean any use of a third party server, regardless of whether read or write - because the whole idea is pointless if transmitting is not included in the definition)
It also includes any email client with a built-in VPN, or potentially any client that can use a VPN (remember, it's at Google's discretion)
> [accesses Gmail and also accesses other servers]
... because that's all that convoluted line means. Break it down:
- Access to "restricted scope Google user's data" (in this case, all we care about is Gmail)
- AND ability to access data from or through a third party server.
It's that last bit that people seem to be getting confused about. For example:
- if your app accesses Gmail and Hotmail accounts, then your app is doing both
- if your app accesses Gmail and also checks today's weather, you're doing both
- if your app accesses Gmail and sends basic usage telemetry. Or checks for updates. Or has plugins that provide spam checking or virus scanning... you're probably doing both
- if your app has ANY plugin system, it could be argued that your app is doing both.
While the language may be unclear, "third party server" is probably intended to reference any non-google service.
And my overall point still stands: YOU do not get to decide what triggers their security review. All you have the right to do is pay the bill.
It might not be required for applications that run locally, but they don't tell you whether or not it will be required until after you've already done the work to create the app.
The exact wording from the FAQ is:
"Local Data Storage: Local client applications don't need to undergo a security assessment because data is run, stored, and processed only on the user's device. Local client applications that only allow user- configured transmissions of Restricted Scope data from the device may be exempt from this requirement."
Keep in mind that any email client that allows you to reply to (or forward) an email would count as transmitting restricted scope data from the user's device.
Not if it does so only via the oauth api?
> Ensure your app complies with the Google APIs Terms of Service, Google's API Services User Data Policy, and the Additional Requirements for Specific Scopes, which includes undergoing an annual security assessment if your app accesses restricted scope Google users data from or through a third-party server.
In the case of an email client data is transmitted directly from/to Google's own IMAP/SMTP servers and not a third party, and is thus exempt from the assessment.
Is there any reason it can't work on Windows 7?