Live data from Hacker News

Less secure apps and your Google Account

support.google.com

171–180 of 272 posts

Re: Less secure apps and your Google Account

#171
post #47

It's interesting how words can be strung together to avert scrutiny of relevant facts pertaining to the message being communicated—and sometimes even used to mask dishonesty.* The terse form of the advisory states: > To help keep your account secure, starting May 30, 2022, Google will no longer support the use of third-party apps or devices which ask you to sign in to your Google Account using only your username and…

> Google, not the Thunderbird team, are to blame for why your Gmail password is the same as your Google Vault password, which is the same as your YouTube password, which is the same as the password you use to mark your phone as needing to be locked out of your account after it's stolen. You mean like google's "Application Specific Passwords" that have been around for a VERY long time, and are not affected by this ann…

I am familiar with that page. (Although I'm not sure how to interpret your "You mean like[...]" phrasing. It doesn't make sense in response to what I wrote.) There's good reason not to go along with the security theater it describes.

App Passwords are not really passwords in the conventional sense. The format makes it difficult to actually use them like a password. They're 16-digit sequences that Google generates for you (you have more control over your child's SSN than you do over these non-passwords)—hard to remember, and that's because you're pretty much not expected to. You're expected to key it in approximately once and configure the relevant app to save it in perpetuity, rather than typing it in. What these things actually are should be familiar to the people here. They're API tokens (and pretty weak ones at that, relatively speaking)—just billed under a different, more familiar name, for a non-technical audience who wouldn't understand that term.

If you are currently using a strong but nonetheless memorable password for Gmail and have your mail client set up to always prompt you for it rather than storing its own copy, then switching to one of these app-specific tokens will actually make your email less secure.

Furthermore, in comparison, a 16-digit sequence has less entropy than a passphrase comprising 6 words chosen from even a very small 1000-word dictionary.

In summary:

- worse experience than an actual password

- less secure

A less cumbersome approach to address the threat Google is pretends to be concerned about here? Allow people to deconsolidate their accounts. This would actually have other happy knock-on effects, such as mitigating the impact of the now-familiar phenomenon where people get locked out of significant parts of their online and offline lives when something goes wrong with their account. Also wouldn't hurt their image in the current conversations about legally imposed breakup.

Re: Less secure apps and your Google Account

#172
post #16

I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…

>I dislike being held to increasingly arbitrary and opaque metrics of what Google defines as "safe"... because that is anxiety inducing, what will it be next week?

Unfortunately, that's the nature of computing in the era of the Internet; being connected online exposes one's accounts to every bad actor on the planet. Google has to keep adapting to the attacks that are successful against their most vulnerable users, and since attackers keep getting more savvy, countermeasures increase in complexity. I won't be surprised when Google mandates 2FA for everyone.

But you're right that it puts a burden on the end user, and increases the odds of false-positive attack prevention kicking in. There really isn't a way off that anxiety-train I'm aware of that isn't "migrate to a different, far less popular service provider that won't be as large an attack target for bad actors," with all the negative consequences such a migration entails.

Re: Less secure apps and your Google Account

#173
post #90

Earlier quoted context omitted.

I ran my own mail for a couple decades, until it got too time consuming. Now I primarily use Fastmail and I prefer it to Gmail, but still sometimes there are issues of third parties not liking my TLD (rare but happens with certain TLD's), but the biggest issue is when people just assume Gmail even though I've given them and sent them mail from other addresses and done everything I can to have them not send to my Gmai…

Yeah, I should note that choice of TLD is important for your primary email. In my experience so far, no one blocks .com/.org/.net. Other TLDs may be trickier.

Yep. Try to stick to 2/3 letter TLDs, some sites check that length is within that range. I have a "fun" tld (in the same vein as myfullna.me) but keep a .net handy that's aliased to it in case it gets rejected.

Re: Less secure apps and your Google Account

#174
post #170

Earlier quoted context omitted.

I sincerely doubt it has anything to do with a whitelist of user agents. It is probably triggered by a failure to evaluate the botguard program, which indicates that your browser may be under the control of malware.

No, Google are pretty specific that they have a whitelist of user agents for their properties. [0] [0] https://support.google.com/mail/answer/6557?hl=en&co=GENIE.P...

There's a huge difference between "supported" and "whitelisted".

Re: Less secure apps and your Google Account

#176
post #16

I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…

You absolutely should own your own domain and use it to email somewhere besides Google. I use Fastmail but ProtonMail is great, tutanota, mailfence, etc. Getting locked out of your email is no joke you don’t want to be in that situation. I have a paid account with Fastmail and a free account with protonmail just in case something goes wrong with Fastmail I can transition my free protonmail account to paid and use it…

I personally am fine sticking with Gmail as I really enjoy the interface/features. One of the things I really like is the scripting I can do with Google Sheets, Gmail, and my Google Calendar. I have some pretty nice automations setup that do things like automatically adding details to my calendar based on emails. Parsing emails to put data into a spreadsheet, automatically adding details to calendar entries for certain things, etc...

What I do to avoid too big of a headache with a lockout is using my own domain name. I essentially just forward my emails to my Gmail account. And then I set it up so I can reply with my own domains address in emails. So if I want to switch to a different provider it's just a matter of switching where I forward to or switching mx records. I also use Google takeout to take frequent full backups of all my data.

Re: Less secure apps and your Google Account

#177
post #141

Earlier quoted context omitted.

Seconding this. I'm running Firefox on mac, with the built-in "Enhanced Tracking Protection" enabled, and uBlock Origin with the default settings. I've never seen that error. I don't use a VPN and I'm in the United States.

I only use uBlock Origin and the built in tracking protection. However I do not use Firefox defaults: I block all third party cookies and don't save cache/history on exit.. I guess it could well be the latter that Google finds "unusual" and frankly, this is what is pushing me away... I don't care what the metric is, I want to be in control, i'm not an idiot who tries to log in from ancient browsers or not understand…

It is unusual. Google uses some of those cookies to determine whether it can lower the "threat signal" on your user agent (a UA carrying tokens that only Google could have issued to it is a huge indicator that Google has a pre-existing trust relationship with that UA).

By throwing away those cookies, your browser is doing the equivalent of showing up to the Google DMV wearing a different hat / sunglasses / beard pattern every time; the agent behind the counter can't say "Oh, that's just tomxor, I know them at a glance already so I by default trust they aren't an active threat to me" and has to do the equivalent of going through the process of doing a background check on you every time.

> But Google is optimising for the 99% at the risk of locking out 1%, that seems careless to me.

It's not careless; it's extremely intentional. Google has a responsibility to protect the 99% and assumes that those who are Internet-savvy enough to do the work to wonk up their UA's thumbprinting are Internet-savvy enough to do the additional work to make that process smooth for their fancy non-defaults configuration.

At the scale they operate, you can expect Google to make the decision that benefits the 99% over the 1% most of the time (particularly when it comes to account security). They'll assuredly risk losing business by making the 1%'s auth story more inconvenient if it makes it 1% more likely that the 99% don't lose the whole farm to a hacker.

Re: Less secure apps and your Google Account

#178
post #16

I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…

You absolutely should own your own domain and use it to email somewhere besides Google. I use Fastmail but ProtonMail is great, tutanota, mailfence, etc. Getting locked out of your email is no joke you don’t want to be in that situation. I have a paid account with Fastmail and a free account with protonmail just in case something goes wrong with Fastmail I can transition my free protonmail account to paid and use it…

I'll add a thumbs up for Migadu! Great service, great principles, I'm a happy customer. It's also pretty cheap (specially if you're a student).

https://migadu.com

Re: Less secure apps and your Google Account

#179
post #52

I suggest all HN readers use this opportunity to stop using Google accounts, if they haven't done so already. Potential benefits: * Better privacy (on many/most alternatives); Google will no longer read your email, store it for use by themselves and their partners, and perhaps pass a copy along to the NSA as Edward Snowden has revealed happens. * Less exposure to manipulative ads, and lower finesse of manipulation du…

You are missing key benefit: when Google locks you out of your account, you don't lose access to significant part of your digital life (your email, all these sign with google ect). Google is using law of algorithm, not a rule of law. Trying to get to a person is nearly impossible.

> when Google locks you out of your account

Is lock-out on Google a thing? I mean, does it happen often other than, when, your account has been maliciously hacked? I didn't know that.

Re: Less secure apps and your Google Account

#180
post #87
post #66

Earlier quoted context omitted.

Does that handle the huge torrent of ads well? Seemingly every website and brick and mortar I've shopped at ever sends me at least one email per day.

The unsubscribe buttons on those emails mostly work, by law. My life improved a lot when I started taking the ten seconds to unsubscribe from everything, vs. just deleting.

I often find myself constantly deleting/ignoring these emails instead of just hitting "unsubscribe". It's so weird how our human laziness works because I swear not many people unsubscribe from emails even though it is typically very easy. It is satisfying when I go in and unsubscribe to a bunch of junk.
Post reply on HN