Live data from Hacker News

Less secure apps and your Google Account

support.google.com

161–170 of 272 posts

Re: Less secure apps and your Google Account

#161
Can some please ELIF about how this affects Thunderbird. I currently (and for years) have used POP3 to download my gmail mailbox (and SMTP to send outgoing). My Thunderbird account setting for gmail currently shows "normal password". Will I have to change it to OAuth or one of the others? Or will I need a special "password" just for use with Thunderbird (this is something my Yahoo/AT&T email started requiring last year).

Maybe related, I have seen for years that whenever I try to download gmail into Thunderbird and I am not at my normal office location, Google requires me to first log in to my account via a browser, then it allows the Thunderbird login.

Re: Less secure apps and your Google Account

#162

Earlier quoted context omitted.

Suggestion? Start now. I moved my primary email to a custom domain a bit over a year ago, and it takes a while to slowly migrate everything over. You don't want to be doing that while under pressure from whatever it is that forces you off.

Would like to do the same myself.. sadly my domain regsitrar is Google, not too sure if I'll need to register another name (a .dev tld) or if there's an easy route of changing registrars.

If you have a .dev TLD domain, Google technically has a lot of control over it no matter what you do, because they own the TLD. If you want to be truly Google-free you'd need a new domain.

Re: Less secure apps and your Google Account

#164
Honestly this seems like a good thing. Using app passwords to sign in to insecure apps instead of your actual password is much more secure, I already use that for Google and my Nextcloud instance and it makes it easier to keep track of where you're signed in. You Google account holds so much information about you nowadays that securing it is tantamount.

Re: Less secure apps and your Google Account

#165
post #83
post #47

It's interesting how words can be strung together to avert scrutiny of relevant facts pertaining to the message being communicated—and sometimes even used to mask dishonesty.* The terse form of the advisory states: > To help keep your account secure, starting May 30, 2022, Google will no longer support the use of third-party apps or devices which ask you to sign in to your Google Account using only your username and…

Conveniently Google also controls the allowed usages for “proper” OAuth access to Gmail. If your client is performing a function they don’t like then you’re screwed. I would expect that to be fair Google would have to also allow arbitrary access to the Gmail API to these now untouchable clients, but snowballs chance in hell Google will be so rational.

I am willing to think that Google performs fingerprinting on the OAUTH login dialog window, which if prevented, similar to the comment above regarding Firefox being unsafe, it would block login through OAUTH as it pleases.

Re: Less secure apps and your Google Account

#167

Earlier quoted context omitted.

This has happened to me, briefly. I once forgot to renew and lost access to email. Luckily I was able to fix the issue quickly. I do kind of wish I had never gone down the route of using my own domain for email. I use gmail with it, and will now have to bear a recurring payment of $6 monthly (IIRC). I could move hosts but none of them are free to my knowledge, and a free service comes with its own risks anyway. Plus…

> It would be a royal pain to switch now. I know it's tough (migrated off G Suite Legacy myself) but it's probably best for the long run since G Suite accounts have less consumer features (in my case, lack of play store reviews and free Google Voice) and it's unlikely to change. There are many submissions on HN discussing alternatives. Fastmail, Protonmail, iCloud+ (I switched to this), Microsoft 365 are frequently m…

Not being able to review things in the Play Store was a blocker for your free G Suite account?

Also I still have a legacy G Suite with Google Voice attached to it which works fine -- and will add additional cost when/if I switch away.

Re: Less secure apps and your Google Account

#168
post #43

Earlier quoted context omitted.

Check the URL and check the lock icon. If you're feeling extra paranoid, you can also click the log to get more information on the security certificate to confirm it's the certificate belonging to the provider.

If it's in an app you don't necessarily get full browser functionality. You just have to trust the app.

Good point. Although in general, if it's an app, it's gone through the vetting process to arrive on its app store and such password-thieving shenanigans would have been caught during that process.

(Ensuring the integrity of that process is one of the reasons the app stores constrain so heavily apps that allow for some flavor of self-modification, via embedding a programming language, running downloaded code, etc.).

Re: Less secure apps and your Google Account

#170
post #91

Earlier quoted context omitted.

That message is generally when your user agent doesn't match Google's list of allowed browsers. It has nothing at all to do with how secure the browser on the end user's computer actually is.

I sincerely doubt it has anything to do with a whitelist of user agents. It is probably triggered by a failure to evaluate the botguard program, which indicates that your browser may be under the control of malware.

No, Google are pretty specific that they have a whitelist of user agents for their properties. [0]

[0] https://support.google.com/mail/answer/6557?hl=en&co=GENIE.P...

Post reply on HN