TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Tell HN: Google halts Gmail and Drive apps and forces them to do security audits

7 pointsby redmover 5 years ago
I found our Google App&#x27;s OAuth permissions were decertified today after seeing some users receiving permissions errors. Google did this without so much as an email to us. Upon digging in further, I discovered that they changed their policy on February 7th, effectively revoking our existing app permissions, and requiring anyone requesting those permissions go through a 3rd party security audit (3P) at the cost of (in their estimation) $15,000 to $75,000 before getting permissions back. They also state this process will take 4-6 weeks. This is not specific to us, as noted in the post below:<p>https:&#x2F;&#x2F;support.google.com&#x2F;cloud&#x2F;answer&#x2F;9110914?authuser=2<p>As of now, we are limited to 100 users connecting accounts before we will no longer be able to accept additional users. Maybe we&#x27;ll get a helpful response from Google, but considering the lack of notice, I doubt it.<p>This is why you can&#x27;t build on a platform like Google; you never know when they will suddenly change policy (or shutdown) without notice and shut you down. No company can stop accepting users for 4-6 weeks while a security audit goes on and stay in business.

3 comments

epcover 5 years ago
This was announced last year: <a href="https:&#x2F;&#x2F;www.theregister.co.uk&#x2F;2019&#x2F;02&#x2F;11&#x2F;google_gmail_developer&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.theregister.co.uk&#x2F;2019&#x2F;02&#x2F;11&#x2F;google_gmail_develo...</a><p>It was a reaction to apps &amp; extensions abusing access to users’ email.
评论 #22314002 未加载
评论 #22314026 未加载
leshokuninover 5 years ago
Has anyone got recommendations on completing this while being an early stage startup? Besides lowering the API scope.
Reggi55over 5 years ago
Maybe you sent their emails to spam it was planned ages ago
评论 #22314305 未加载