Live data from Hacker News

Less secure apps and your Google Account

support.google.com

211–220 of 272 posts

Re: Less secure apps and your Google Account

#211

Great. There's nothing I hate more than an app or game asking to login with Google and redirecting me to a non Google domain. Of course I have a separate email for those cases

I wrote a small python script that uses the smtp lib. I don’t want to screw around with Google’s python library for a small script that will surely break every 3 months because google changes something about their auth.

So I have a dedicated email and explicitly toggle a switch and they’ll still toggle it back forcibly over time, and now are getting rid of it?

Re: Less secure apps and your Google Account

#212
post #145

Earlier quoted context omitted.

Maybe it's just me but I don't have "Australia going to force my email provider to hand over my data" in my threat model. It's probably worth thinking about that too before hastily switching email providers. Fastmail is a solid provider, with great support and I never had a real issue with them. I give them money, they provide me a good and stable email service.

And then some version of Russia-Ukraine happens with Australia where you are locked out of your email accounts and all bets are off

This could happen to any country and is also precisely the reason why you use your own domain. You'd just point it to a new mail provider and you'll be up and running in an hour.

If you use a local mail client that stores your email locally you'll also have access to all these.

Re: Less secure apps and your Google Account

#213
post #94

Earlier quoted context omitted.

IMAP with OAuth is standard. What am I missing?

It is not, in fact, a standard. It's a proprietary complicating thing that megacorps do and everyone else assumes is standard. https://datatracker.ietf.org/doc/html/rfc6749 "The OAuth 2.0 Authorization Framework" >This specification is designed for use with HTTP ([RFC2616]). The use of OAuth over any protocol other than HTTP is out of scope. So now you have HTTP protocol being used for IMAP, or worse and more common,…

> It is not, in fact, a standard. It's a proprietary complicating thing

Nope, it's a standard. Standards you don't like aren't proprietary, they're just standards which superkuh doesn't like.

Re: Less secure apps and your Google Account

#214
post #145

Earlier quoted context omitted.

Maybe it's just me but I don't have "Australia going to force my email provider to hand over my data" in my threat model. It's probably worth thinking about that too before hastily switching email providers. Fastmail is a solid provider, with great support and I never had a real issue with them. I give them money, they provide me a good and stable email service.

You should have "my mail data should not be shared with third parties" as a general rule for mail providers. If that's not you, cool - but I'd wager most folks don't want their mail read :)

If you don't want your mail shared with third parties you just have to encrypt your email and then it doesn't matter who your provider is.

There's a difference between "don't want their mail read" and "someone will be able to read my emails if there's a court order and they are interested in the content of my specific inbox".

Re: Less secure apps and your Google Account

#215
post #119

The sign-in method they're removing really is less secure: you're sending your full username and password to a third-party. Application-specific passwords ( https://support.google.com/accounts/answer/185833 ) and OAuth are much better. Disclosure: I work for Google, speaking only for myself

There are still non-web applications, so no, that's not a third party.

If I save my credentials in Mutt/Pine it's more secure than entering them in the browser - much less attack surface, and not more third party than a browser. There are some benefits to having a token like in oauth, for example simple way to revoke some sessions access, but it's a tradeoff, not black and white.

Re: Less secure apps and your Google Account

#216
post #183

Earlier quoted context omitted.

Google does not allow oauth from embedded webviews: https://developers.googleblog.com/2021/06/upcoming-security-... So you should never need to trust the app.

Ironically this is more of a problem now on desktop, where eg a website (such as eBay) in Firefox pops up a PayPal login window without an address bar and there is no way to verify the domain without using developer tools

Really PayPal should get with the times and offer WebAuthn, where upon it isn't a problem (WebAuthn credentials are domain bound, so, if that window isn't PayPal then it can't have PayPal credentials)

Asking humans, who often don't even notice when they wrote an entire word twice in a sentence, to "verify the domain" is nonsense, machines are good at this problem, let the machines do it.

Re: Less secure apps and your Google Account

#217
post #119

The sign-in method they're removing really is less secure: you're sending your full username and password to a third-party. Application-specific passwords ( https://support.google.com/accounts/answer/185833 ) and OAuth are much better. Disclosure: I work for Google, speaking only for myself

An email client running on my own machine is not a third party. But regardless, this is why the feature is called "enable access for less secure apps". It's disabled by default, and it re-disables itself automatically unless you're actively using it to sign in. My Google account does not contain nuclear launch codes, and my threat model is not the same as Google's. I am far more worried about getting locked out of my…

I do think you're right about 2FA, and there should be an option to use an application specific password without 2FA.

Re: Less secure apps and your Google Account

#218
post #69

Earlier quoted context omitted.

Office 365.

their web email client continues to be ocular cancer for anyone who isn't already a daily Outlook user.

I can't stand it nor GMail so I always use a good old local client (Mac Mail or Evolution).

Re: Less secure apps and your Google Account

#219
post #119

The sign-in method they're removing really is less secure: you're sending your full username and password to a third-party. Application-specific passwords ( https://support.google.com/accounts/answer/185833 ) and OAuth are much better. Disclosure: I work for Google, speaking only for myself

An email client running on my own machine is not a third party. But regardless, this is why the feature is called "enable access for less secure apps". It's disabled by default, and it re-disables itself automatically unless you're actively using it to sign in. My Google account does not contain nuclear launch codes, and my threat model is not the same as Google's. I am far more worried about getting locked out of my…

FWIW, 2FA is very low friction. You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. If it wasn't you, then someone else besides you knows your credentials and you need to change them ASAP. If it was you, you have another 2FA point.

Also, I enabled 2FA a couple of years ago, and have been happily using app-specific passwords ("app passwords" now) since they were implemented. Tying them to 2FA activation doesn't look like an engineering limitation.

Re: Less secure apps and your Google Account

#220
post #119

The sign-in method they're removing really is less secure: you're sending your full username and password to a third-party. Application-specific passwords ( https://support.google.com/accounts/answer/185833 ) and OAuth are much better. Disclosure: I work for Google, speaking only for myself

You aren't necessarily actually sending it to a third party per se though. Less secure access also enables using software running on your own computer to access your email easily. For example offlineimap and imapfilter. In theory it ought to work with OAuth but damned if I can get it to work and any instructions a few years old are useless because something has changed in the interim.

It's actually less hassle to migrate off Gmail. Quite frankly there are few Google things that at this point aren't a hassle to work with. Google is poised to ruin adblocking in chrome with manifest v3, search is increasingly polluted by junk, gmail is now a pain to work with outside of a web browser and awful to use in a web browser, the play store is so bad as far as finding non junk non malware that its necessary to use an outside web page like say bing/duck duck go to find apps to install with play store which serves at best as an updater interface, workspace is a pain. Various actually useful services like reader picasa google+ are dead.

The only remaining useful end user services are youtube, maps, and android.

As someone who used to be excited about Google stuff its kind of disappointing.

Gmail user from June 2004-2022 but soon no longer. Thanks for 18 years of good service for the absolutely ridiculously low price of I think $80 to date.

Post reply on HN