Perpetual Window into Gmail
wired.com
wired.com
Again - even if "fortunately, Unroll.me is a totally legit NYC-based startup providing a useful service", that says nothing about their security practices. For all we know, someone already has access to their servers and they will never detect the breakin.
Being paranoid can be useful. :)
My colleagues and I developed this idea in a paper (see: http://ieeexplore.ieee.org/xpl/freeabs_all.jsp?arnumber=5421...). Back then we also had proof of concept running on our server.
Is that even true? The advantage of Oauth over the "password anti-pattern" is that you can grant limited rights. i.e. sharing my address book with Facebook. That's personal information, but it's not my entire email archive.
I believe this list is the scope of possible Oauth permissions: http://code.google.com/apis/gdata/faq.html#AuthScopes
It looks like granting access the Gmail Atom feed allows access to new Inbox emails (but not the entire email body, I think.) But if you haven't granted that permission, your emails should be safe. (I think. Any expert opinions?)
There are two reasons they built this system: (1) So apps won't have to ask for your Google password. This password would give them access to much more than just Gmail. And if you wanted to revoke their access, you'd have to change your password, whereas with OAuth you can just flip a switch in your Google settings. (2) So apps won't have to do hacky stuff with curl to interact with Gmail. It's much easier to use an official API.
That said, if it's possible for an application to read/act on your email, it's possible for them to store your email. And if it's possible for them to store your email, it's possible for a hacker to hack it. So if you're going to use something based on Gmail OAuth, make sure you trust them and that they aren't actually storing your data.
This highlights a growing problem I see with newly launched consumer oriented sites (many posted here on HN). Startups are ignoring legal and regulatory requirements around privacy and seem completely insensitive to customer's feelings in this area.
That is going to hurt them in the long run. They'll lose customers like this author. Things are moving fast with regard to privacy around the world. The FTC tagged both Google[1] and Facebook[2] last year for privacy violations. The EU is pushing forward with new, much tougher, regulations[3] and still week after week I see sites come out that don't even have a privacy policy[4].
[1]http://www.informationweek.com/news/security/privacy/2282000...
[2]http://www.washingtonpost.com/business/technology/facebook-s...
[3]http://ec.europa.eu/justice/newsroom/data-protection/news/12...
So there's more than just privacy at stake here. I go to almost paranoid lengths to protect it from attacks known and unknown because once someone takes it, they can take over almost everything else.
Just something to think about.
(i know what localhost means, in that it is the name associated with 127.0.0.1, but how is it a "connected site, app or service"?)
No, that's patently false.
While it may be in response to a compromise, it's generally good security practice to change your password periodically.
I've read that it's better to use 2-step in conjunction with a strong password that you'll remember, versus regularly migrating from one weak or medium strength password to another.
You could always create a special GMail account that you use to sign up for spam generating offers or deals and use that to authenticate logins you're not sure about.
That's the link to list the apps that have access to your account, but for the life of me, I can't work out how to get there from any of the other settings pages...
EDIT it's second from the bottom, in the "Accounts and Import" (3rd across) https://mail.google.com/mail/#settings/accounts
It's a little scary that the authorization is all-or-nothing. Many sites use OAuth just for sign-in (like Stackoverflow), so surely it makes sense to have different levels of access (I was under the impression that fine-grained access control was the whole point of token-based OAuth).
24 hours, 7 days, 1 month, 1 year, indefinitely