Hacker News new | ask | show | jobs
by Arathorn 2084 days ago
Absolutely - at Element we categorically have zero desire to have access to anything in your GL accounts. On the other hand, for the same reason, we’re not going to exploit that :/
1 comments

But the responsible thing to do here is to _throw all that data away_, and force everyone to explicitly grant gitter access to their account again.

With only as many rights as necessary, of course. No app needs full account access, all the time. Make the various parts differently authenticated layers.