Live data from Hacker News

Less secure apps and your Google Account

support.google.com

221–230 of 272 posts

Re: Less secure apps and your Google Account

#221

Earlier quoted context omitted.

An email client running on my own machine is not a third party. But regardless, this is why the feature is called "enable access for less secure apps". It's disabled by default, and it re-disables itself automatically unless you're actively using it to sign in. My Google account does not contain nuclear launch codes, and my threat model is not the same as Google's. I am far more worried about getting locked out of my…

FWIW, 2FA is very low friction. You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. If it wasn't you, then someone else besides you knows your credentials and you need to change them ASAP. If it was you, you have another 2FA point. Also, I enabled 2FA a couple of years ago, and have been happily using app-specific passwords ("…

> You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application.

I have two different concerns.

The first is that I frequently end up having to clear my browser cookies, for a variety of reasons. Every time I do, I have to redo the 2FA dance, on every single website that requires 2FA. I suppose I could find a different cookie management strategy, but I think it's good for both privacy and security to treat cookies as semi-ephemeral.

Secondly, I’m concerned that I'll either loose or replace my 2FA device and forget about the account until it's too late—again, I’m much more concerned about losing access to my account than someone else getting in. I would almost certainly loose any physical backup codes.

I also have a fantasy that I'll give up my smartphone one of these days, or at least not bring it everywhere I go. I’ll probably never do it, but the idea is such that I don't want to depend on an app for access to my account. I do think I’ve successfully made myself less dependent on my smartphone than a lot of people, and I’m proud of that accomplishment.

Re: Less secure apps and your Google Account

#222

Earlier quoted context omitted.

An email client running on my own machine is not a third party. But regardless, this is why the feature is called "enable access for less secure apps". It's disabled by default, and it re-disables itself automatically unless you're actively using it to sign in. My Google account does not contain nuclear launch codes, and my threat model is not the same as Google's. I am far more worried about getting locked out of my…

FWIW, 2FA is very low friction. You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. If it wasn't you, then someone else besides you knows your credentials and you need to change them ASAP. If it was you, you have another 2FA point. Also, I enabled 2FA a couple of years ago, and have been happily using app-specific passwords ("…

That's more friction than I'm willing to tolerate. If they force me to use 2FA, I'm done with Gmail for good (it's already no longer my primary email).

And I'm not against 2FA in general, I just don't want to use it in this case.

Re: Less secure apps and your Google Account

#223
post #119

The sign-in method they're removing really is less secure: you're sending your full username and password to a third-party. Application-specific passwords ( https://support.google.com/accounts/answer/185833 ) and OAuth are much better. Disclosure: I work for Google, speaking only for myself

You aren't necessarily actually sending it to a third party per se though. Less secure access also enables using software running on your own computer to access your email easily. For example offlineimap and imapfilter. In theory it ought to work with OAuth but damned if I can get it to work and any instructions a few years old are useless because something has changed in the interim. It's actually less hassle to mig…

> Less secure access also enables using software running on your own computer to access your email easily. For example offlineimap and imapfilter. In theory it ought to work with OAuth but damned if I can get it to work and any instructions a few years old are useless because something has changed in the interim.

You shouldn't need OAuth; have you tried application-specific passwords (https://support.google.com/accounts/answer/185833)?

Re: Less secure apps and your Google Account

#225

Earlier quoted context omitted.

Ironically this is more of a problem now on desktop, where eg a website (such as eBay) in Firefox pops up a PayPal login window without an address bar and there is no way to verify the domain without using developer tools

Really PayPal should get with the times and offer WebAuthn, where upon it isn't a problem (WebAuthn credentials are domain bound, so, if that window isn't PayPal then it can't have PayPal credentials) Asking humans, who often don't even notice when they wrote an entire word twice in a sentence, to "verify the domain" is nonsense, machines are good at this problem, let the machines do it.

Ebay supports WebAuthn, does PayPal not?

Re: Less secure apps and your Google Account

#226

This is going to be a big impact for a lot of our customers. The app we use only supports user/pass auth and lots of people set up special sending only gmail accounts to just get it out and not impact security of their orgs commercial gsuite stuff. Fun times ahead.

Shameless plug: move to inbox.eu. We have migration tool to move away from gmail. We use separate auto-generated IMAP password for more secure access via standard IMAP protocol. Auto-generated passwords by our experience are secure and we haven't have problems with account hacking via them

If the passwords are being used by some automated service this is probably fine, at least modulo the quality of the service implementation.

If they're for actual humans, even in the best case you're vulnerable to phishing, also you are a perpetual risk because you know these passwords (or a password equivalent) so an adversary might steal your passwords (e.g. from a backup, logs, test systems, ...) and now they can impersonate all users.

It's almost certainly safer than letting users pick their own passwords, but it's less protected than, say, a Google user who set up 2-step, and much less than if they went with Advanced Protection and thus can't get phished or impersonated.

Re: Less secure apps and your Google Account

#227
post #223

Earlier quoted context omitted.

You aren't necessarily actually sending it to a third party per se though. Less secure access also enables using software running on your own computer to access your email easily. For example offlineimap and imapfilter. In theory it ought to work with OAuth but damned if I can get it to work and any instructions a few years old are useless because something has changed in the interim. It's actually less hassle to mig…

> Less secure access also enables using software running on your own computer to access your email easily. For example offlineimap and imapfilter. In theory it ought to work with OAuth but damned if I can get it to work and any instructions a few years old are useless because something has changed in the interim. You shouldn't need OAuth; have you tried application-specific passwords ( https://support.google.com/acco…

If this is an effective workaround why is it useful to disable the feature in the first place. It seems like a 16 digit password this is actually much less secure than the current state of affairs.

It's probably not much worth exploring because I'm also having to migrate off of legacy google apps for your domain as well.

Re: Less secure apps and your Google Account

#230

Can some please ELIF about how this affects Thunderbird. I currently (and for years) have used POP3 to download my gmail mailbox (and SMTP to send outgoing). My Thunderbird account setting for gmail currently shows "normal password". Will I have to change it to OAuth or one of the others? Or will I need a special "password" just for use with Thunderbird (this is something my Yahoo/AT&T email started requiring last ye…

Since nobody else responded:

I don't use Thunderbird, but yes, if you have anything vaguely close to a modern Thunderbird then you should choose OAuth2 instead of "Normal Password" for both sending and receiving. You may need to exit Thunderbird and go back in, then it should prompt you via what is in effect a web frame, to log in by whatever means you ordinarily use for Google, then Google asks if you really want to let Thunderbird read and send mail (you do) and this grants it a token that it will use to access your mail.

The alternative would be to set up an "App password" in your Google account and then paste the password (which Google chooses) into Thunderbird. That password is then independent of your actual Google password and can't be used to sign in as you on Google, just by mail clients for checking mail and so on, sounds like you did this with Yahoo/AT&T already once. Prefer OAuth2.

Post reply on HN