githubkusi / googlecl

Automatically exported from code.google.com/p/googlecl
0 stars 0 forks source link

Trust #429

Open GoogleCodeExporter opened 8 years ago

GoogleCodeExporter commented 8 years ago
GoogleCL application has to have privileges to access to my account, for 
example using the OAuth mechanism ( 
https://www.google.com/accounts/OAuthAuthorizeToken?oauth_token= ). That's 
fine, but how can I trust the application? The web page tells me "The 
application that directed you here claims to be 'GoogleCL xxx@yyy'. We are 
unable to verify this claim as the application runs on your computer, as 
opposed to a website. We recommend you deny access unless you trust the 
application.".

"We are unable to verify this claim" is what makes me worry! You HAVE to be 
able to verify the claim, for example, GoogleCL could provide a digital 
signature that google.com/OAuth verifies.

Since I don't have time to check the code for 
trojans/backdoor/security-serious-issues and none is taking any liability for 
it, I am afraid but I will not use GoogleCL.

Please, fix this serious problem, and keep up the great work.

Bests

Original issue reported on code.google.com by alop...@gmail.com on 5 Oct 2011 at 12:33