Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Kind of confused by this heroku error message I received? Are you storing my gmail credentials on heroku? When I tried again I have a google /looking/ login screen?

http://cl.ly/1p0M0o2t0H1E3Z1h3i0n



I haven't used this so I'm not sure what's going on, but I believe OAuth involves a redirect back to servers controlled by the third party to actually do something with the authentication token. This doesn't strike me as necessarily fishy.


I guess I don't understand why they even need to store anything on their servers?


Hi bdittmer, we don't store any of your content, nor any of your passwords. We only store meta data that describes the organization of your documents and do so server-side so that we can add features in an upcoming release that we otherwise wouldn't be unable to add.


Storing stuff? Isn't that what my hard disk is for? If I wanted a cloud solution, I'd just log into Google Docs directly.

I would have thought the whole point of an app like this is to take advantage of the benefits of native UI, not to add yet another point of failure.


Got it. You guys should read up on iCloud :)


You need to be way more transparent about what you're storing and why - a native client app implies nothing in the middle.


I think they are mimicking the Google Login page and just saving your username/password. Seems damn fishy to me.


no. these guys are legit. they work in our sandhill office. They're not out to steal your login credentials.


If they're legit, why are they not using oAuth?


We are using Google's oauth2 protocol. No user password is stored or even ever transmitted to our server.


Well I'm not at a Mac so I can't confirm but it's unfortunate to see such misinformation in this thread. I apologize for repeating it, I was too trusting of other comments.


Since you are framing in the login with webkit, why not show the URL as well? User's need to see htts://google.com or they'll assume it's a phishing attack.


How is this actually any more secure? It's pretty easy to display a legit (but "fake") URL while your phishing form is displayed in the webview.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: