Live data from Hacker News

Less secure apps and your Google Account

support.google.com

101–110 of 272 posts

Re: Less secure apps and your Google Account

#101
post #90

Earlier quoted context omitted.

I ran my own mail for a couple decades, until it got too time consuming. Now I primarily use Fastmail and I prefer it to Gmail, but still sometimes there are issues of third parties not liking my TLD (rare but happens with certain TLD's), but the biggest issue is when people just assume Gmail even though I've given them and sent them mail from other addresses and done everything I can to have them not send to my Gmai…

Yeah, I should note that choice of TLD is important for your primary email. In my experience so far, no one blocks .com/.org/.net. Other TLDs may be trickier.

Indeed, and now that I've been using it for years and many people also use it to contact me, it will be as painful to change it as it would be to drop Gmail.

Re: Less secure apps and your Google Account

#102
post #26

I suggest all HN readers use this opportunity to stop using Google accounts, if they haven't done so already. Potential benefits: * Better privacy (on many/most alternatives); Google will no longer read your email, store it for use by themselves and their partners, and perhaps pass a copy along to the NSA as Edward Snowden has revealed happens. * Less exposure to manipulative ads, and lower finesse of manipulation du…

What are the leading recommendations these days? is it still mainly protonmail? I think the features I value most are U2F support and a usable but simple web interface (Gmail's web interface has actually gotten consistency worse over the last decade so I guess that sets a low bar).

I use protonmail as a second account. It works fine, but there are a few quality of life differences compared to gmail.

1. ProtonMail can not search the contents of messages in the web client, unless you enable local indexing. This downloads all of your messages to the client, and performs the search locally. This, of course, must be done from every web client. It makes sense, given that PM can't see the contents of your messages. The Android app can not search the contents of messages.

2. The Android app does not clear notifications if the message is read elsewhere. This can be annoying when you look at your phone and see notifications for 7 unread messages after they've all been read.

Proton supports TOTP only, and not U2F/WebAuthn.

Re: Less secure apps and your Google Account

#103
post #66

Earlier quoted context omitted.

Suggestion? Start now. I moved my primary email to a custom domain a bit over a year ago, and it takes a while to slowly migrate everything over. You don't want to be doing that while under pressure from whatever it is that forces you off.

Does that handle the huge torrent of ads well? Seemingly every website and brick and mortar I've shopped at ever sends me at least one email per day.

Use a unique email address for every service you have to sign up for. Optionally combined with sieve filter to sort them accordingly.

Re: Less secure apps and your Google Account

#104
post #47

It's interesting how words can be strung together to avert scrutiny of relevant facts pertaining to the message being communicated—and sometimes even used to mask dishonesty.* The terse form of the advisory states: > To help keep your account secure, starting May 30, 2022, Google will no longer support the use of third-party apps or devices which ask you to sign in to your Google Account using only your username and…

> Google, not the Thunderbird team, are to blame for why your Gmail password is the same as your Google Vault password, which is the same as your YouTube password, which is the same as the password you use to mark your phone as needing to be locked out of your account after it's stolen.

You mean like google's "Application Specific Passwords" that have been around for a VERY long time, and are not affected by this announcement?

https://support.google.com/accounts/answer/185833?hl=en

Re: Less secure apps and your Google Account

#107
Just wanting to point out that as an alternative to ProtonMail, FastMail, etc. you can simply buy your own domain, and point your DNS MX record to a traditional mail service with POP and IMAP access. All DNS registrars I know do offer that, plus RoundCube as web mail service if you want to access it from browsers.

Re: Less secure apps and your Google Account

#108
post #16

I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…

I have been having lockout anxiety lately as well. I actually took the time to look up proton mail and gave been waiting for and day to add it to any accounts I need access to such as amazon, eBay, Facebook, etc. There are just too many stories of people losing their gmail and no recourse as you will never get a human on their part to fix the issue unless you are some high profile client who can rock the boar.

Re: Less secure apps and your Google Account

#109
post #91
post #37

Earlier quoted context omitted.

Your device is probably pwned. But go ahead and blame Google. I love how people just ignore these warnings.

That message is generally when your user agent doesn't match Google's list of allowed browsers. It has nothing at all to do with how secure the browser on the end user's computer actually is.

I sincerely doubt it has anything to do with a whitelist of user agents. It is probably triggered by a failure to evaluate the botguard program, which indicates that your browser may be under the control of malware.
Post reply on HN