Live data from Hacker News

Less secure apps and your Google Account

support.google.com

111–120 of 272 posts

Re: Less secure apps and your Google Account

#111
post #16

I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…

You absolutely should own your own domain and use it to email somewhere besides Google. I use Fastmail but ProtonMail is great, tutanota, mailfence, etc. Getting locked out of your email is no joke you don’t want to be in that situation. I have a paid account with Fastmail and a free account with protonmail just in case something goes wrong with Fastmail I can transition my free protonmail account to paid and use it…

If you have a domain, that's just another liability for email security. Look at what NameCheap did. Imagine losing your domain for some reason -- even forgetting to renew. All your contacts need a new address now, and until then it's dropped emails.

A custom domain is mostly a vanity measure. It does allow you to migrate to a new email service if your provider cancels your subscription, I suppose... But I'd rather only have one thing to worry about.

Re: Less secure apps and your Google Account

#112
post #47

It's interesting how words can be strung together to avert scrutiny of relevant facts pertaining to the message being communicated—and sometimes even used to mask dishonesty.* The terse form of the advisory states: > To help keep your account secure, starting May 30, 2022, Google will no longer support the use of third-party apps or devices which ask you to sign in to your Google Account using only your username and…

> Google, not the Thunderbird team, are to blame for why your Gmail password is the same as your Google Vault password, which is the same as your YouTube password, which is the same as the password you use to mark your phone as needing to be locked out of your account after it's stolen. You mean like google's "Application Specific Passwords" that have been around for a VERY long time, and are not affected by this ann…

Application specific passwords require two-factor auth being on, which means either giving google your phone number or having to pay for e.g. a yubikey.

Re: Less secure apps and your Google Account

#113

Earlier quoted context omitted.

Suggestion? Start now. I moved my primary email to a custom domain a bit over a year ago, and it takes a while to slowly migrate everything over. You don't want to be doing that while under pressure from whatever it is that forces you off.

Any suggestions for good privacy-centric email providers?

https://privacyguides.org/providers/email/

I use mailbox.org with no complaints.

Re: Less secure apps and your Google Account

#114
post #37
post #16

I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…

Your device is probably pwned. But go ahead and blame Google. I love how people just ignore these warnings.

How are we supposed to trust 'your browser might not be secure' when Google benefits directly from hobbling everything that isn't Chrome?

Re: Less secure apps and your Google Account

#115
post #16

I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…

I've got six google accounts and never seen this message while connecting from my normal IP address or a random VPN provider (so hundreds of users sharing the same IP address).

I presume something is wrong with your Firefox profile.

Re: Less secure apps and your Google Account

#116
post #16

I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…

You absolutely should own your own domain and use it to email somewhere besides Google. I use Fastmail but ProtonMail is great, tutanota, mailfence, etc. Getting locked out of your email is no joke you don’t want to be in that situation. I have a paid account with Fastmail and a free account with protonmail just in case something goes wrong with Fastmail I can transition my free protonmail account to paid and use it…

Just a reminder to everybody that Fastmail is an Australian company, and is therefore subject to Australia's TOLA / Assistance And Access.

I avoid them like the plague for this reason. Having your e-mail provider compelled to work against your interests is no joke and you may not want to be in that situation.

Re: Less secure apps and your Google Account

#117
post #37
post #16

I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…

Your device is probably pwned. But go ahead and blame Google. I love how people just ignore these warnings.

Every device in a walled garden is pwned, is it not?

Re: Less secure apps and your Google Account

#118
post #34

Google keeps making it more and more difficult for me to use their services. It's going to be painful when Google finally forces me off Gmail.

I moved away from Google services years ago, but nowadays you can't even browse Youtube without asking for age verification, I'm not going to send my ID card or credit card data to Google to prove that my 15+ years old account was not created at that time by someone who was 2 years old and is still not adult in Europe, do these people even use brain to require age verfication from 15+ years old account?

Oldest e-mail I've found in my Gmail is from 2007 from Rapidshare, but created it already way before, but there is no way to find account creation time (POP/IMAP trick doesn't work, shows 2008).

Any idea how to find how old is Gmail account and why they ask for age verification for 15+ yo accounts?

Re: Less secure apps and your Google Account

#119
The sign-in method they're removing really is less secure: you're sending your full username and password to a third-party. Application-specific passwords (https://support.google.com/accounts/answer/185833) and OAuth are much better.

Disclosure: I work for Google, speaking only for myself

Re: Less secure apps and your Google Account

#120

Earlier quoted context omitted.

> Google, not the Thunderbird team, are to blame for why your Gmail password is the same as your Google Vault password, which is the same as your YouTube password, which is the same as the password you use to mark your phone as needing to be locked out of your account after it's stolen. You mean like google's "Application Specific Passwords" that have been around for a VERY long time, and are not affected by this ann…

Application specific passwords require two-factor auth being on, which means either giving google your phone number or having to pay for e.g. a yubikey.

Or using a free authenticator app for time-based codes?
Post reply on HN