Live data from Hacker News

Less secure apps and your Google Account

support.google.com

191–200 of 272 posts

Re: Less secure apps and your Google Account

#191

Earlier quoted context omitted.

So without a domain whoever owns the domain you're using can deplatform you. The result is dropped emails at that address forever. With your own domain, the registrar can pull a namecheap and cancel your country. The result is temporarily dropped emails while you transfer to another domain registrar. You can set the registrar to autorenew.

I de-googled last year but still use google domains as my registrar. It's just so darn cheap and includes DDNS. I've looked at alternatives and I haven't been able to strongly identify one I trust more than google (as strange as that sounds). How do other people pick a registrar that they trust?

gandi.net

There are DDNS scripts on github to update the DNS record. Picked gandi a very long time ago and have no complaints.

Re: Less secure apps and your Google Account

#192

I suggest all HN readers use this opportunity to stop using Google accounts, if they haven't done so already. Potential benefits: * Better privacy (on many/most alternatives); Google will no longer read your email, store it for use by themselves and their partners, and perhaps pass a copy along to the NSA as Edward Snowden has revealed happens. * Less exposure to manipulative ads, and lower finesse of manipulation du…

What are some alternatives?

Here's one survey of alternatives:

https://restoreprivacy.com/google-alternatives/

Personally, I use:

* DDG for search.

* gmx.com as my main email server (not sure it's that great for privacy, ProtonMail is probably better).

* OpenStreetMap for maps (caveat: Some info is on Google Maps and not on there)

* HereWeGo for car navigation

* Thunderbird as my mail client + calendar

* I don't publish videos, but otherwise probably PeerTube

* IRC and Matrix for group chatting

* F-Droid for FOSS mobile apps, Aurora for anonymous access to Google Play Store

Not yet de-googlified:

* I use an Android phone (albeit Chinese)

* Still need a good alternative for Google Translate.

Re: Less secure apps and your Google Account

#193
post #119

The sign-in method they're removing really is less secure: you're sending your full username and password to a third-party. Application-specific passwords ( https://support.google.com/accounts/answer/185833 ) and OAuth are much better. Disclosure: I work for Google, speaking only for myself

Sweet, I was about to look into whether I'd need to make changes to my OAuth integration. Makes sense that it's fine since the username/password (or however they wish to authenticate) is sent to Google themselves.

Re: Less secure apps and your Google Account

#194
post #16

I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…

[deleted]

Re: Less secure apps and your Google Account

#195
post #194
post #16

I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…

[deleted]

[deleted]

Re: Less secure apps and your Google Account

#196
post #47

It's interesting how words can be strung together to avert scrutiny of relevant facts pertaining to the message being communicated—and sometimes even used to mask dishonesty.* The terse form of the advisory states: > To help keep your account secure, starting May 30, 2022, Google will no longer support the use of third-party apps or devices which ask you to sign in to your Google Account using only your username and…

[deleted]

Re: Less secure apps and your Google Account

#198
post #94

Earlier quoted context omitted.

If an email provider does not offer standard pop3 or imap it is not an email provider. It's just some web shit.

IMAP with OAuth is standard. What am I missing?

It is not, in fact, a standard. It's a proprietary complicating thing that megacorps do and everyone else assumes is standard.

https://datatracker.ietf.org/doc/html/rfc6749 "The OAuth 2.0 Authorization Framework"

>This specification is designed for use with HTTP ([RFC2616]). The use of OAuth over any protocol other than HTTP is out of scope.

So now you have HTTP protocol being used for IMAP, or worse and more common, not-OAuth over IMAP and you call that standard? These are Microsoft, Google, etc announcements of proprietary things. Not standards. And every single megacorp requires a different custom solution to interact with.

Re: Less secure apps and your Google Account

#199
Annoyingly, Google doesn't actually support app-specific passwords for accounts that don't have two-factor authentication enabled. So for use cases that require a password (eg SMTP), there's literally no other option available.

(Yes, 2FA increases security, but if someone doesn't or can't have it enabled, for whatever reason, that's no reason to prevent them from using app-specific passwords)

Re: Less secure apps and your Google Account

#200
post #47

It's interesting how words can be strung together to avert scrutiny of relevant facts pertaining to the message being communicated—and sometimes even used to mask dishonesty.* The terse form of the advisory states: > To help keep your account secure, starting May 30, 2022, Google will no longer support the use of third-party apps or devices which ask you to sign in to your Google Account using only your username and…

> Google, not the Thunderbird team, are to blame for why your Gmail password is the same as your Google Vault password, which is the same as your YouTube password, which is the same as the password you use to mark your phone as needing to be locked out of your account after it's stolen. You mean like google's "Application Specific Passwords" that have been around for a VERY long time, and are not affected by this ann…

> You mean like google's "Application Specific Passwords" that have been around for a VERY long time, and are not affected by this announcement?

It's not actually documented anywhere, but app-specific passwords cannot be used with non-commercial Google accounts that do not have two-factor authentication enabled.

Post reply on HN