Live data from Hacker News

Less secure apps and your Google Account

support.google.com

181–190 of 272 posts

Re: Less secure apps and your Google Account

#181
post #28

Earlier quoted context omitted.

What about clients which don't support that, like Google's "send mail as" feature? I suppose that won't be supported anymore?

Indeed: this is a hard compatibility break, without a simple workaround. The thing is, this is nowhere near new: it's been announced years ago, and slowly rolled out since 2019. Actually, IIRC, the rollout has been postponed at least once in 2020, due to covid (in order to not cut people off). I recall implementing Xoauth for IMAP, specifically for this.

If you have two factor auth on and generate an "app-specific password" doesn't this allow you to do the same thing still? You just use your email and app-specific password to login and it should work still shouldn't it?

Re: Less secure apps and your Google Account

#183
post #43

Earlier quoted context omitted.

Check the URL and check the lock icon. If you're feeling extra paranoid, you can also click the log to get more information on the security certificate to confirm it's the certificate belonging to the provider.

If it's in an app you don't necessarily get full browser functionality. You just have to trust the app.

Google does not allow oauth from embedded webviews:

https://developers.googleblog.com/2021/06/upcoming-security-...

So you should never need to trust the app.

Re: Less secure apps and your Google Account

#184

I suggest all HN readers use this opportunity to stop using Google accounts, if they haven't done so already. Potential benefits: * Better privacy (on many/most alternatives); Google will no longer read your email, store it for use by themselves and their partners, and perhaps pass a copy along to the NSA as Edward Snowden has revealed happens. * Less exposure to manipulative ads, and lower finesse of manipulation du…

Cons: * While you can Takeout your data, enjoy the process of reshuffling gigabytes of Drive contents, calendar entries, YouTube videos, etc. Into other application systems. * Disconnection from the Cloud makes everything strictly less convenient. "Oh, I'll just throw you a Drive link... Oh wait, I guess I'm going to have to upload it to something else that you may or may not have access to, or email it to you and ho…

> enjoy the process of reshuffling

If you've uploaded it, there's no sense in taking it down. Google already has it. Just don't log-in to Google accounts and don't take their cookies.

> I guess I'm going to have to upload it to something else that you may or may not have access to,

If you looked into alternatives, you would find many don't require any account or login by the receiving party. Example: box.com links . Actually, I'm pretty sure that's the norm.

> I'll upload it to a web server and toss you a password

Look, you've been stuck in the Google bubble for too long. The weather is just fine outside.

Re: Less secure apps and your Google Account

#185
post #119

The sign-in method they're removing really is less secure: you're sending your full username and password to a third-party. Application-specific passwords ( https://support.google.com/accounts/answer/185833 ) and OAuth are much better. Disclosure: I work for Google, speaking only for myself

An email client running on my own machine is not a third party. But regardless, this is why the feature is called "enable access for less secure apps". It's disabled by default, and it re-disables itself automatically unless you're actively using it to sign in.

My Google account does not contain nuclear launch codes, and my threat model is not the same as Google's. I am far more worried about getting locked out of my own account due to some mishap than I am someone else getting in, and I think I should be able to assess my own risk. Google can set defaults, but I know my own life.

(I will say that I wouldn't mind switching to app-specific passwords, but Google won't let me because I have 2FA turned off. I don't want 2FA because I don't want to get locked out of my account, I don't need 2FA because I use a password manager, and I don't understand how 2FA and app-specific passwords are related.)

Re: Less secure apps and your Google Account

#186
post #145

Earlier quoted context omitted.

Just a reminder to everybody that Fastmail is an Australian company, and is therefore subject to Australia's TOLA / Assistance And Access. I avoid them like the plague for this reason. Having your e-mail provider compelled to work against your interests is no joke and you may not want to be in that situation.

Maybe it's just me but I don't have "Australia going to force my email provider to hand over my data" in my threat model. It's probably worth thinking about that too before hastily switching email providers. Fastmail is a solid provider, with great support and I never had a real issue with them. I give them money, they provide me a good and stable email service.

You should have "my mail data should not be shared with third parties" as a general rule for mail providers. If that's not you, cool - but I'd wager most folks don't want their mail read :)

Re: Less secure apps and your Google Account

#187

Earlier quoted context omitted.

Cons: * While you can Takeout your data, enjoy the process of reshuffling gigabytes of Drive contents, calendar entries, YouTube videos, etc. Into other application systems. * Disconnection from the Cloud makes everything strictly less convenient. "Oh, I'll just throw you a Drive link... Oh wait, I guess I'm going to have to upload it to something else that you may or may not have access to, or email it to you and ho…

> enjoy the process of reshuffling If you've uploaded it, there's no sense in taking it down. Google already has it. Just don't log-in to Google accounts and don't take their cookies. > I guess I'm going to have to upload it to something else that you may or may not have access to, If you looked into alternatives, you would find many don't require any account or login by the receiving party. Example: box.com links .…

> If you've uploaded it, there's no sense in taking it down. Google already has it. Just don't log-in to Google accounts and don't take their cookies.

I meant in terms of making it convenient to use that data in some other environment when one moves away from Google.

My Drive contents, for example, will come down in doc formats that may or may not be immediately compatible with whatever I want to move to (be it someone else's cloud or locally-running desktop editors). And it'll all have to be re-indexed for search purposes (unless I just decide "being able to search all my documents regardless of their format" is one of those Drive features I no longer care about).

Photos as well... I can pull my photos down, but I'm going to leave behind those "Find all pictures of a cat" or "Find all pictures of my mom" features that Google Photos provide.

Re: Less secure apps and your Google Account

#188
This is going to be a big impact for a lot of our customers. The app we use only supports user/pass auth and lots of people set up special sending only gmail accounts to just get it out and not impact security of their orgs commercial gsuite stuff. Fun times ahead.

Re: Less secure apps and your Google Account

#189
post #148
post #54

Earlier quoted context omitted.

“Your browser might not be secure” is a worthless error message. If you have a strong reason to believe this is the case, you should tell me. If you don’t tell me, I’m going to assume you don’t have a good reason, and you’re just scaremongering.

They are telling you.

They're not telling you what's wrong, just that you're bad for arbitrary reasons that ultimately will end up boiling down to "we don't trust that you try to preserve your own privacy".

Re: Less secure apps and your Google Account

#190
post #87
post #66

Earlier quoted context omitted.

Does that handle the huge torrent of ads well? Seemingly every website and brick and mortar I've shopped at ever sends me at least one email per day.

The unsubscribe buttons on those emails mostly work, by law. My life improved a lot when I started taking the ten seconds to unsubscribe from everything, vs. just deleting.

> The unsubscribe buttons on those emails mostly work, by law

They won't for some arbitrary percentage of emails. And even then, they will keep coming from new places.

Post reply on HN