Live data from Hacker News

Less secure apps and your Google Account

support.google.com

41–50 of 272 posts

Re: Less secure apps and your Google Account

#43

Earlier quoted context omitted.

I've got great distrust for these pop-up "sign in with Google" or whichever SSO provider you have you find in a lot of apps (or even Apple's accounts thing on macos); how can I verify it is in fact Google and not a 3rd party lookalike?

Check the URL and check the lock icon. If you're feeling extra paranoid, you can also click the log to get more information on the security certificate to confirm it's the certificate belonging to the provider.

If it's in an app you don't necessarily get full browser functionality. You just have to trust the app.

Re: Less secure apps and your Google Account

#44

Great. There's nothing I hate more than an app or game asking to login with Google and redirecting me to a non Google domain. Of course I have a separate email for those cases

I've got great distrust for these pop-up "sign in with Google" or whichever SSO provider you have you find in a lot of apps (or even Apple's accounts thing on macos); how can I verify it is in fact Google and not a 3rd party lookalike?

On iOS, you get a system-level modal promopt that confirms what domain you're going to, and the domain should be in the title bar of the web view.

It's not totally foolproof, of course, an app could bundle its own HTML engine or fake the UI some other way.

Re: Less secure apps and your Google Account

#45
post #16

I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…

This is often the result of browser extensions. Specifically, CDN replacement extensions like Decentraleyes or LocalCDN.

Re: Less secure apps and your Google Account

#46

I suggest all HN readers use this opportunity to stop using Google accounts, if they haven't done so already. Potential benefits: * Better privacy (on many/most alternatives); Google will no longer read your email, store it for use by themselves and their partners, and perhaps pass a copy along to the NSA as Edward Snowden has revealed happens. * Less exposure to manipulative ads, and lower finesse of manipulation du…

self host your email. mailinabox makes it less than half an hour job. plus occasional updates every few months, nothing big. the upside is, you get to control your emails, your server. the bad thing is, if you get a bad IP (which you can have replaced for example at the start from vps provider) or you do something fishy with your email like spam gmail/yahoo/outlook users, you would be banned but other than that it really isn't all that bad.

sure i have to "sometimes" ask people to check spam and set it as not spam but that is becoming more and more remote.

i do understand the appeal of protonmail and other privacy centric emails but you can do that yourself if you put in the elbow grease. plus you get to learn about a lot of stuff and its a fun exercise.

you also do not have to pay through your nose if you want more features/more storage and stuff (well the storage/server depends on your vps in toto but still)

Re: Less secure apps and your Google Account

#47
It's interesting how words can be strung together to avert scrutiny of relevant facts pertaining to the message being communicated—and sometimes even used to mask dishonesty.*

The terse form of the advisory states:

> To help keep your account secure, starting May 30, 2022, Google will no longer support the use of third-party apps or devices which ask you to sign in to your Google Account using only your username and password.

It's the innuendo that's interesting. The message in the subtext of this statement is, Look at these apps! They want you to use them for e.g. checking your email, but look at what they do! Isn't it awful? In order to let you check your email, they make you give them the password for your _whole_ Google account!

Of course, the only one who's responsible for the current arrangement is Google. Google, not third-party developers, are to blame (and _solely_ to blame) for why access to the various Google services is consolidated into a single account. Google, not the Thunderbird team, are to blame for why your Gmail password is the same as your Google Vault password, which is the same as your YouTube password, which is the same as the password you use to mark your phone as needing to be locked out of your account after it's stolen.

* This is why I'm skeptical of the whole "writing forces you to be honest because it means you have to actually think things through well enough to put them into words that can be put into coherent sentences" meme. Nobody seems to talk about how writing and the revision process that's inherent to it also provides the opportunity to finesse words. Some idea can be made to appear as if it's sound and backed by solid reasoning even when the truth is actually much less straightforward—or even contradictory.

Re: Less secure apps and your Google Account

#48
post #34

Google keeps making it more and more difficult for me to use their services. It's going to be painful when Google finally forces me off Gmail.

Suggestion? Start now. I moved my primary email to a custom domain a bit over a year ago, and it takes a while to slowly migrate everything over. You don't want to be doing that while under pressure from whatever it is that forces you off.

Re: Less secure apps and your Google Account

#49
post #10
post #5

Does this mean no more app tokens, e.g. to retrieve IMAP mail?

No, you can still use IMAP with Thunderbird for example but you login to google account and Thunderbird get a token similar to how all OAuth works, what is blocked is using email/passowrd directly with your IMAP client.

In other words, Gmail is no longer compliant with Internet email standards like POP3/IMAP.

Re: Less secure apps and your Google Account

#50
post #28
post #10

Earlier quoted context omitted.

No, you can still use IMAP with Thunderbird for example but you login to google account and Thunderbird get a token similar to how all OAuth works, what is blocked is using email/passowrd directly with your IMAP client.

What about clients which don't support that, like Google's "send mail as" feature? I suppose that won't be supported anymore?

From the client's point of view, it's like a password. Just not your password. (edit: talking about app passwords, unrelated to oauth or stuff like that)
Post reply on HN