TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Gmail’s API lockdown will kill some third-party app access, starting July 15

240 pointsby joeyhalmost 6 years ago

25 comments

tomswartz07almost 6 years ago
I see this as a double-edged sword.<p>1. It makes sense that Google wants to stop apps from abusing their storage platform. There are a lot of projects that abuse the data storage capacity. There was that one app that converted files to Base64 or something and was storing files that way as email text. Obviously not cool. However, Google needs to be explicitly clear on expectations and throw some people-power behind the reviews, since many are being denied by (seemingly) some automated process.<p>2. The second issue I see is that it will encourage less secure methods of using these apps. SMSBackup+ in particular is discussing the possibility of moving to &quot;App Passwords&quot; to bypass 2FA and provide the app access it needs to upload and store the data. Issue being, App Passwords are incredibly fragile, they provide near-unfettered access to IMAP and other account features with no auditing. Caveat emptor and all that.<p>I think SMSBackup+, specifically, has a bit of a gray line as SMS messages can technically be sent via email and vice versa, (among other similarities). It&#x27;s a shame that Google is becoming so draconian about their data storage uses.
评论 #20301809 未加载
评论 #20300637 未加载
评论 #20302295 未加载
评论 #20300454 未加载
评论 #20303450 未加载
SpicyLemonZestalmost 6 years ago
&gt; <i>Google&#x27;s OAuth APIs have been around for years as a way for apps to get access to and control your Google data. A third-party email app, for instance, would want access to your Gmail account and the ability to send, read, and delete emails so it could control everything remotely. An IM app might just want access to your contacts and profile picture. For years this was purely an agreement between the user and the developer—the app would say what it wanted access to, and the user could deny or allow it.</i><p>Yeah, until the Cambridge Analytica scandal revealed that agreements like this aren&#x27;t sufficient to protect user data. I think Google&#x27;s making the only acceptable tradeoff here.
评论 #20300767 未加载
评论 #20300425 未加载
akkartikalmost 6 years ago
I&#x27;ve been expecting this. Google&#x27;s attempts to get me to turn off &quot;less secure app access&quot; have grown increasingly obnoxious over the last couple of years. A few months ago they went so far as to send me a &quot;prevented login from suspicious device&quot; alert after a getmail run. Time to leave. If I can&#x27;t download it with POP or IMAP, then it&#x27;s not email.
评论 #20301749 未加载
sct202almost 6 years ago
As a former user of SMSBackup+, at a certain point it did seem like I was putting a lot of trust into a 3rd party to have full access to both my text messages and my email. So I can kind of see how it&#x27;s a risk, but it seems sad to just shut it all down.
评论 #20300283 未加载
评论 #20302840 未加载
quotemstralmost 6 years ago
I wonder how long it&#x27;ll take for scraping to make a comeback. I feel like we&#x27;ve become used to APIs being the only integration options. When API restrictions become too burdensome, however, I expect people to recall that other access options exist.
评论 #20300978 未加载
评论 #20302841 未加载
paxysalmost 6 years ago
There will always be misuse of open APIs by third parties, and the company itself will be blamed in the PR fallout. After Google and Facebook I expect more services to follow suit, which is a shame but understandable.
6cd6bebalmost 6 years ago
You shouldn&#x27;t be building anything that relies on a google service unless<p>A) Google would die without that service<p>B) You&#x27;re just fucking around and what your building could burn to the ground without consequence<p><a href="https:&#x2F;&#x2F;killedbygoogle.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;killedbygoogle.com&#x2F;</a> has 143 services listed.
评论 #20307504 未加载
dpacmittalalmost 6 years ago
Slightly off topic, but Google is also discontinuing Google photos and google drive syncing feature. This is currently the only way to access your Google photos with Rclone.
评论 #20302848 未加载
评论 #20310944 未加载
miki123211almost 6 years ago
how long until Google says &quot;hey, actually, it would be cool if users used gmail.com with all the ads instead of some stupid external email clients. Let&#x27;s disable POP3&#x2F;IMAP&#x2F;SMTP for non-business users. Oh, and let&#x27;s disallow mail redirection too, so they won&#x27;t even think about running away&quot;.
评论 #20303539 未加载
评论 #20304821 未加载
评论 #20303985 未加载
_Codemonkeyismalmost 6 years ago
The email client I use - Nine - is on the list. I can&#x27;t see how an email client is a problem except they want to push Googles client. Hope Nine gets fixed.
评论 #20303579 未加载
评论 #20304937 未加载
exabrialalmost 6 years ago
Yep, I wish I could opt out. For years, I&#x27;ve used an app to backup my sms messages to gmail, now it&#x27;s being taken away.
评论 #20303683 未加载
dazbradburyalmost 6 years ago
Does anyone know if this will have any impact on Gmail backup tools such as:<p><a href="https:&#x2F;&#x2F;github.com&#x2F;jay0lee&#x2F;got-your-back" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;jay0lee&#x2F;got-your-back</a><p>Or the long term sustainability of such projects?<p>I&#x27;ve found gmail&#x27;s own data export tools to not work <i>at all</i> for any inbox of a considerable size (100gb+) - so third party tools are the only way to actually back up &#x2F; migrate email data.<p>Without such tooling, relying on Gmail would be a huge mistake for anything remotely important.
评论 #20303622 未加载
xt508almost 6 years ago
I just noticed a new &quot;Schedule Send&quot; Gmail feature, could this be related and Google is adding in features from third-party apps?
jguimontalmost 6 years ago
They could have gone another route than imposing a bogus security audit and have the devs pay for it. I did an integration with QuickBooks a while back, and they paid&#x2F;conducted the security audit themselves.<p>Google could have added a contract that would plainly state that any data needs to be wiped out etc and enforce that contract if anything is fishy.<p>Google could have created a process to clearly inform the dev that the user wants to delete google related data and impose deadlines on it.<p>Those are simple, but I think Google was just lazy and listened to a bunch of lawyers instead of thinking out the box.<p>I have an app that allows to link your email account thru Nylas (with google), now I would have to pay the security audit? No way. I told my customers that any google account that is not a GSuite which whitelisted the app (most of my customers corporate) that they might have warning dialog when connecting their gmail account. There is a limit of 100 linked account without verification ;(
lstoddalmost 6 years ago
&gt; &quot;Don&#x27;t store Google user data on your server.&quot;<p>The, I&#x27;m sorry, WTF? This is not Google&#x27;s data.
评论 #20301047 未加载
评论 #20300738 未加载
评论 #20300482 未加载
评论 #20305063 未加载
prasanthmjalmost 6 years ago
I invested a lot of time trying to publish a Gmail add-on and failed miserably [1][4] because of this lockdown. Here are some notes that may be of interest:<p>The lock down is for the Gmail API especially for API that allows reading user’s email.<p>Any App has to get OAuth 2 token to get access to the API. The user has to explicitly provide access . The approval screen will show each type of access the app is asking. See an example here [2]<p>In addition, Google will send an email to the user immediately after the approval, with a scary warning.<p>The user can withdraw the app access anytime, from Google account page.<p>The data access concern Google is projecting is that the APP can read user’s email (Remember, the app can read only those who explicitly gave the app the permission to read their email). The “lockdown” is a direct reply to the media frenzy that “Gmail allows any app to read anyone&#x27;s email” [5]. Gmail does not allow reading email automatically. The user has to allow explicitly.<p>In order to get Gmail API access, the app has to go through a Google review process where Google will ask the developer to justify each type of API access the app is requesting in addition to explaining (with videos) what the app does and how the API is used. The first level of approval process demands you to publish a comprehensive privacy policy and in my experience, anything like “marketing” or “research” in the privacy policy will get you disapproval. [3]<p>Such a strict approval process is good and fine, and well appreciated till this point. The issue comes for the last part of the approval process.<p>Those Apps that requires read access to Gmail has to get themselves assessed, through Google appointed third party security assessors paying $75000 USD annually.<p>This is the main blocker.<p>This will kick out any app or add-on that small scale developers create. It will block new entrants. What remains will be established apps that are generating huge revenue to justify the “protection money”. They get an added advantage that there will no longer be any new competition.<p>It is not the restrictions, or the intention to protect the end user that is in question but the “first save my back” attitude in the process, and the bait and switch - that is the problem. In summary it happened like this:<p>Hey developers come, build apps using our platform, show your innovation! Developers start investing time and effort on the platform, approval process is smooth and fare Somewhere else, someone misuses someone’s system, huge media attention Sorry developers, you go to Mr X , keep paying him and we will keep you here. If not, trash your product and go away.<p>[1] <a href="https:&#x2F;&#x2F;medium.com&#x2F;@prasanthmj&#x2F;lessons-learned-developing-an-app-using-google-apis-dff3f7b91be0" rel="nofollow">https:&#x2F;&#x2F;medium.com&#x2F;@prasanthmj&#x2F;lessons-learned-developing-an...</a><p>[2] <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=GGXFQUmZTf4" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=GGXFQUmZTf4</a><p>[3] <a href="https:&#x2F;&#x2F;blog.gsmart.in&#x2F;applying-for-g-suite-api-approvals&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.gsmart.in&#x2F;applying-for-g-suite-api-approvals&#x2F;</a><p>[4] <a href="https:&#x2F;&#x2F;medium.com&#x2F;@prasanthmj&#x2F;google-restricted-api-scopes-require-75k-yearly-fees-a23cad053a4c" rel="nofollow">https:&#x2F;&#x2F;medium.com&#x2F;@prasanthmj&#x2F;google-restricted-api-scopes-...</a><p>[5] <a href="https:&#x2F;&#x2F;www.wsj.com&#x2F;articles&#x2F;techs-dirty-secret-the-app-developers-sifting-through-your-gmail-1530544442" rel="nofollow">https:&#x2F;&#x2F;www.wsj.com&#x2F;articles&#x2F;techs-dirty-secret-the-app-deve...</a>
ryanmerceralmost 6 years ago
The changes they&#x27;ve been doing is somewhat annoying. It killed probably 75% of my IFTTT and now it is going to kill my SMS backup solution (SMSBackup+) unless the developer changes a bunch of stuff. Sure I can backup other ways but I like having it in my gmail, I&#x27;ve been saving SMS backup there since the iPhone 3gs.<p>I get why they are doing it but blah, now I have to find solutions for everything again.
pmlnralmost 6 years ago
Good.<p>Maybe email clients will go back being email clients with IMAP so they can be used with _any_ provider, not just gmail.
js4everalmost 6 years ago
I&#x27;m now considering to stop using gmail and all google services in general
laurent123456almost 6 years ago
The article mentions this is going to affect Drive soon too, but couldn&#x27;t find any info about this on Google announcement. Anybody has any info on this?
评论 #20304226 未加载
jackjackk0almost 6 years ago
The only third-party app I received a warning about from Google regarding this issue was FastMail... coincidence?
Zenbit_UXalmost 6 years ago
This doesn&#x27;t bode well for companies like streak whose sole product is an add-on to Gmail...
评论 #20304577 未加载
tregoningalmost 6 years ago
Doesn&#x27;t this mean that SuperHuman is screwed?
alacombealmost 6 years ago
So... if every player (and Google in particular) start locking their platform, how could this not constitute ground for antitrust trial ?<p>Even explorer was less tightly integrated 25 years ago...
unixheroalmost 6 years ago
Christ. So much for the API economy.