Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> We moved everything we could to our Google SSO.

I realize this is for employees and it is hard to escape their gravitational pull, but I hope no customer data is going to Google unless asked for.



This is for employees only. We don't collect more than necessary for customers, and if we did we sure as hell wouldn't be sending it to Google.


Thanks, and right... I don't expect maliciousness on fly's part. But you'd be surprised (or not) how many goog products phone home with anything they can find. In fact it might be called a "business model" of some sort.


Google's SSO can't really phone home. You're either using SAML or OAuth; in either scenario, the information flow is Google --> the app you're SSOing into; name, email, and user group information.

If you're SSOing into, say, AWS, Google doesn't get any access or private info out of AWS in the flow.


You get that the norm in hosting providers is hosting applications themselves on Google and Amazon, right?


I don’t trust anything with google on it, is that clear enough?


Accidentally hit enter the moment before HN went down and didn't get to edit it. :-D

But yes, reading google on your network gave me the heeby-jeebies. That the 'normal' thing is to host them on google is not really pertinent. If I was interested in that, I'd have done it. But I'm looking at other parties on purpose.

ceejayoz seems to think it is not technically an issue, google is not on your network. That sounds plausible to me, assuming it is accurate.


Well, our root of authentication trust is Google, so if "no Google involved" is a criteria for you, we're not a good place to host stuff for you.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: