Live data from Hacker News

Less secure apps and your Google Account

support.google.com

231–240 of 272 posts

Re: Less secure apps and your Google Account

#231
The heck I'm ditching Claws Mail for that slower than molasses web interface. Any recommendation for a secure and very cheap mail service that doesn't hate SMTP+POP? I'm already aware of Fastmail which would probably be my choice if I don't find a better+cheaper alternative.

Re: Less secure apps and your Google Account

#232
post #119

The sign-in method they're removing really is less secure: you're sending your full username and password to a third-party. Application-specific passwords ( https://support.google.com/accounts/answer/185833 ) and OAuth are much better. Disclosure: I work for Google, speaking only for myself

I really think Google needs to make a distinction between sending your credentials to a foreign 3rd party service/domain vs a “3rd party” client that runs on your machine. Sending your credentials somewhere else is understandably best avoided. Using a different “3rd party” user agent than the top 3 browsers to access some google services, on the other hand, really isn’t less secure at all and I even think an argument could be made that it’s more secure than a browser in many cases. Local (wouldn't even mind if it was limited to open source) apps should be given unrestricted access to the Gmail OAuth scopes. Until then, I can’t see how this is anything other than a platform control play under the guise of user safety to lock down API access to blessed google clients and services.

Re: Less secure apps and your Google Account

#233
post #163

Does this mean email aliasing is gmail is going to break? I think you need less secure sign in for that to work.

I would also really like to know this. Can anyone help?

I just did this for a bunch of Gmail accounts that have aliases setup to send out from custom domain email address. So yes, You can still use less secure apps and set up gmail aliases as long as you enable 2fa and obtain an app specific pw that you then use to setup the alias or to log in into your google mail via the less secure app of your choice. Note that there is no need for a phone number to setup 2fa as you can instead use the option of one time login codes and then validate access from your phone using any google app such as the gmail.

Re: Less secure apps and your Google Account

#234
post #81

Isn't this going to break their own "send mail as" feature in Gmail to send as another Gmail address you own? Which I basically use constantly.

Not really. You just need to use the apps specific pw that you can obtain from your account security page. I just did this for a bunch of Gmail accounts that have aliases setup to send out from custom domain email address. The only change is that you have to enable 2fa to obtain an app specific pw that you then use to setup the alias or to log in into your google mail via the less secure app of your choice. Note that there is no need for a phone number to setup 2fa as you can instead use the option of one time login codes and then validate access from your phone using any google app such as the gmail.

Re: Less secure apps and your Google Account

#235
post #94

Earlier quoted context omitted.

IMAP with OAuth is standard. What am I missing?

It is not, in fact, a standard. It's a proprietary complicating thing that megacorps do and everyone else assumes is standard. https://datatracker.ietf.org/doc/html/rfc6749 "The OAuth 2.0 Authorization Framework" >This specification is designed for use with HTTP ([RFC2616]). The use of OAuth over any protocol other than HTTP is out of scope. So now you have HTTP protocol being used for IMAP, or worse and more common,…

Why is it an issue that getting a token for use with IMAP requires an out-of-band HTTP request? How do you think SSO works for anything other than web services?

Re: Less secure apps and your Google Account

#236
post #225

Earlier quoted context omitted.

Really PayPal should get with the times and offer WebAuthn, where upon it isn't a problem (WebAuthn credentials are domain bound, so, if that window isn't PayPal then it can't have PayPal credentials) Asking humans, who often don't even notice when they wrote an entire word twice in a sentence, to "verify the domain" is nonsense, machines are good at this problem, let the machines do it.

Ebay supports WebAuthn, does PayPal not?

If it does, that's be great, as I do have a PayPal account to solve a problem I had with one payment platform, but when I last looked it only offered TOTP

Re: Less secure apps and your Google Account

#237
post #165
post #83

Earlier quoted context omitted.

Conveniently Google also controls the allowed usages for “proper” OAuth access to Gmail. If your client is performing a function they don’t like then you’re screwed. I would expect that to be fair Google would have to also allow arbitrary access to the Gmail API to these now untouchable clients, but snowballs chance in hell Google will be so rational.

I am willing to think that Google performs fingerprinting on the OAUTH login dialog window, which if prevented, similar to the comment above regarding Firefox being unsafe, it would block login through OAUTH as it pleases.

It also straight up doesn't allow you to publish an OAuth application that uses “restricted” scopes (like `gmail.*`) without a review process subject to arbitrary usage guidelines determined by the Google APIs team. That’s the catch. It doesn't even matter how you run the OAuth flow (though I agree I suspect they fingerprint that too). You get blocked earlier.

Re: Less secure apps and your Google Account

#238
post #232
post #119

The sign-in method they're removing really is less secure: you're sending your full username and password to a third-party. Application-specific passwords ( https://support.google.com/accounts/answer/185833 ) and OAuth are much better. Disclosure: I work for Google, speaking only for myself

I really think Google needs to make a distinction between sending your credentials to a foreign 3rd party service/domain vs a “3rd party” client that runs on your machine. Sending your credentials somewhere else is understandably best avoided. Using a different “3rd party” user agent than the top 3 browsers to access some google services, on the other hand, really isn’t less secure at all and I even think an argument…

> Local (wouldn't even mind if it was limited to open source) apps

How could a rule like that be enforced?

> lock down API access to blessed google clients and services.

What's wrong with application specific passwords?

(Still speaking only for myself)

Re: Less secure apps and your Google Account

#239

Great. There's nothing I hate more than an app or game asking to login with Google and redirecting me to a non Google domain. Of course I have a separate email for those cases

I've got great distrust for these pop-up "sign in with Google" or whichever SSO provider you have you find in a lot of apps (or even Apple's accounts thing on macos); how can I verify it is in fact Google and not a 3rd party lookalike?

My strategy--which is more browser-centric--is that I open another tab and proactively log in to the identity-provider (Google, Steam, etc.) and only after that do I go to the third-party site.

If the flow asks me for my password again, something has gone wrong.

Re: Less secure apps and your Google Account

#240

Earlier quoted context omitted.

An email client running on my own machine is not a third party. But regardless, this is why the feature is called "enable access for less secure apps". It's disabled by default, and it re-disables itself automatically unless you're actively using it to sign in. My Google account does not contain nuclear launch codes, and my threat model is not the same as Google's. I am far more worried about getting locked out of my…

FWIW, 2FA is very low friction. You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. If it wasn't you, then someone else besides you knows your credentials and you need to change them ASAP. If it was you, you have another 2FA point. Also, I enabled 2FA a couple of years ago, and have been happily using app-specific passwords ("…

Googles 2fa requires the user to give google his phone number before being able to add a totp authenticatior. That alone is reason for me to never use it for my google account. The popup also doesn't come up if you haven't signed up with google on your phone, obviously. There is nothing stopping them from just allowing anyone to add a normal totp 2fa generator, they just chose to not do that to get more of that sweet, sweet data.
Post reply on HN