Live data from Hacker News

Less secure apps and your Google Account

support.google.com

91–100 of 272 posts

Re: Less secure apps and your Google Account

#91
post #37
post #16

I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…

Your device is probably pwned. But go ahead and blame Google. I love how people just ignore these warnings.

That message is generally when your user agent doesn't match Google's list of allowed browsers.

It has nothing at all to do with how secure the browser on the end user's computer actually is.

Re: Less secure apps and your Google Account

#92
post #72
post #61

Earlier quoted context omitted.

> Google, not the Thunderbird team, are to blame for why your Gmail password is the same as your Google Vault password… Hmm, but couldn’t third party developers just use OAuth instead? Thunderbird works with Google’s standard XOATH Oauth IMAP implementation, last I checked.

In some cases yeah but not for mail. The GMail API is great but to use it you have to spend like $75k on a security review that Google has to approve.

You can use XOAUTH with IMAP just like any other IMAP client (including Thunderbird, as I noted above).

Re: Less secure apps and your Google Account

#93
post #77
post #61

Earlier quoted context omitted.

> Google, not the Thunderbird team, are to blame for why your Gmail password is the same as your Google Vault password… Hmm, but couldn’t third party developers just use OAuth instead? Thunderbird works with Google’s standard XOATH Oauth IMAP implementation, last I checked.

e: fyi the ringfence bit in this post is incorrect. Leaving for posterity but don't believe this comment, see replies :) -- Could just set up an app password limited to accessing gmail, been able to do that for like 10 years now and it's not going away with this change different password: check ringfenced access: check

App passwords are not limited in scope, AFAIK.

Re: Less secure apps and your Google Account

#94
post #61

Earlier quoted context omitted.

> Google, not the Thunderbird team, are to blame for why your Gmail password is the same as your Google Vault password… Hmm, but couldn’t third party developers just use OAuth instead? Thunderbird works with Google’s standard XOATH Oauth IMAP implementation, last I checked.

If an email provider does not offer standard pop3 or imap it is not an email provider. It's just some web shit.

IMAP with OAuth is standard. What am I missing?

Re: Less secure apps and your Google Account

#95
post #93
post #77

Earlier quoted context omitted.

e: fyi the ringfence bit in this post is incorrect. Leaving for posterity but don't believe this comment, see replies :) -- Could just set up an app password limited to accessing gmail, been able to do that for like 10 years now and it's not going away with this change different password: check ringfenced access: check

App passwords are not limited in scope, AFAIK.

It said it was when I created one before posting to make sure I was thinking of Gmail and not Fastmail.

Not sure why there'd be a dropdown to select the service if not, maybe I misunderstood

E: I misunderstood, you're correct. The dropdown is for your reference (e.g. "Mail [on] iPhone") and if you select "Other" it's the same as selecting the other dropdown's "Other", it lets you type a custom name. Guess that was never as secure as I'd thought!

I've long since moved to Fastmail which does do the limiting by service, thank you for correcting!

Re: Less secure apps and your Google Account

#96
post #90

Earlier quoted context omitted.

Suggestion? Start now. I moved my primary email to a custom domain a bit over a year ago, and it takes a while to slowly migrate everything over. You don't want to be doing that while under pressure from whatever it is that forces you off.

I ran my own mail for a couple decades, until it got too time consuming. Now I primarily use Fastmail and I prefer it to Gmail, but still sometimes there are issues of third parties not liking my TLD (rare but happens with certain TLD's), but the biggest issue is when people just assume Gmail even though I've given them and sent them mail from other addresses and done everything I can to have them not send to my Gmai…

Yeah, I should note that choice of TLD is important for your primary email. In my experience so far, no one blocks .com/.org/.net. Other TLDs may be trickier.

Re: Less secure apps and your Google Account

#97
post #61
post #47

It's interesting how words can be strung together to avert scrutiny of relevant facts pertaining to the message being communicated—and sometimes even used to mask dishonesty.* The terse form of the advisory states: > To help keep your account secure, starting May 30, 2022, Google will no longer support the use of third-party apps or devices which ask you to sign in to your Google Account using only your username and…

> Google, not the Thunderbird team, are to blame for why your Gmail password is the same as your Google Vault password… Hmm, but couldn’t third party developers just use OAuth instead? Thunderbird works with Google’s standard XOATH Oauth IMAP implementation, last I checked.

Google provides the App passwords feature:

> An App password is a 16-digit passcode that gives a non-Google app or device permission to access your Google Account. Learn more about how to sign in using App Passwords.

Maybe I misunderstand the announcement, but it looks to me that this feature will still be a valid alternative when Oauth can't be used.

Re: Less secure apps and your Google Account

#98
post #81

Isn't this going to break their own "send mail as" feature in Gmail to send as another Gmail address you own? Which I basically use constantly.

One thing you can generally be sure about, no matter what changes they go through: They won't ruin their own services and income-streams. Removing cookies? They have replacement for that in their browser that no extensions will be able to help with. Removing sign-in methods? Within their ecosystem they pass whatever token they want, wherever they want.

Re: Less secure apps and your Google Account

#99
post #16

I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…

You absolutely should own your own domain and use it to email somewhere besides Google. I use Fastmail but ProtonMail is great, tutanota, mailfence, etc. Getting locked out of your email is no joke you don’t want to be in that situation.

I have a paid account with Fastmail and a free account with protonmail just in case something goes wrong with Fastmail I can transition my free protonmail account to paid and use it with very minimal downtime

Edit: adding my fastmail referral link just in case https://ref.fm/u26310488

Re: Less secure apps and your Google Account

#100
post #16

I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…

I've been using Firefox for years, never faced this issue before... have you tried updating your browser?

> have you tried being a botnet enabler?

Heh.

Post reply on HN