Less secure apps and your Google Account
231–240 of 272 posts
Re: Less secure apps and your Google Account
#232The sign-in method they're removing really is less secure: you're sending your full username and password to a third-party. Application-specific passwords ( https://support.google.com/accounts/answer/185833 ) and OAuth are much better. Disclosure: I work for Google, speaking only for myself
Re: Less secure apps and your Google Account
#233Does this mean email aliasing is gmail is going to break? I think you need less secure sign in for that to work.
I would also really like to know this. Can anyone help?
Re: Less secure apps and your Google Account
#234Isn't this going to break their own "send mail as" feature in Gmail to send as another Gmail address you own? Which I basically use constantly.
Re: Less secure apps and your Google Account
#235Earlier quoted context omitted.
IMAP with OAuth is standard. What am I missing?
It is not, in fact, a standard. It's a proprietary complicating thing that megacorps do and everyone else assumes is standard. https://datatracker.ietf.org/doc/html/rfc6749 "The OAuth 2.0 Authorization Framework" >This specification is designed for use with HTTP ([RFC2616]). The use of OAuth over any protocol other than HTTP is out of scope. So now you have HTTP protocol being used for IMAP, or worse and more common,…
Re: Less secure apps and your Google Account
#236Earlier quoted context omitted.
Really PayPal should get with the times and offer WebAuthn, where upon it isn't a problem (WebAuthn credentials are domain bound, so, if that window isn't PayPal then it can't have PayPal credentials) Asking humans, who often don't even notice when they wrote an entire word twice in a sentence, to "verify the domain" is nonsense, machines are good at this problem, let the machines do it.
Ebay supports WebAuthn, does PayPal not?
Re: Less secure apps and your Google Account
#237Earlier quoted context omitted.
Conveniently Google also controls the allowed usages for “proper” OAuth access to Gmail. If your client is performing a function they don’t like then you’re screwed. I would expect that to be fair Google would have to also allow arbitrary access to the Gmail API to these now untouchable clients, but snowballs chance in hell Google will be so rational.
I am willing to think that Google performs fingerprinting on the OAUTH login dialog window, which if prevented, similar to the comment above regarding Firefox being unsafe, it would block login through OAUTH as it pleases.
Re: Less secure apps and your Google Account
#238The sign-in method they're removing really is less secure: you're sending your full username and password to a third-party. Application-specific passwords ( https://support.google.com/accounts/answer/185833 ) and OAuth are much better. Disclosure: I work for Google, speaking only for myself
I really think Google needs to make a distinction between sending your credentials to a foreign 3rd party service/domain vs a “3rd party” client that runs on your machine. Sending your credentials somewhere else is understandably best avoided. Using a different “3rd party” user agent than the top 3 browsers to access some google services, on the other hand, really isn’t less secure at all and I even think an argument…
How could a rule like that be enforced?
> lock down API access to blessed google clients and services.
What's wrong with application specific passwords?
(Still speaking only for myself)
Re: Less secure apps and your Google Account
#239Great. There's nothing I hate more than an app or game asking to login with Google and redirecting me to a non Google domain. Of course I have a separate email for those cases
I've got great distrust for these pop-up "sign in with Google" or whichever SSO provider you have you find in a lot of apps (or even Apple's accounts thing on macos); how can I verify it is in fact Google and not a 3rd party lookalike?
If the flow asks me for my password again, something has gone wrong.
Re: Less secure apps and your Google Account
#240Earlier quoted context omitted.
An email client running on my own machine is not a third party. But regardless, this is why the feature is called "enable access for less secure apps". It's disabled by default, and it re-disables itself automatically unless you're actively using it to sign in. My Google account does not contain nuclear launch codes, and my threat model is not the same as Google's. I am far more worried about getting locked out of my…
FWIW, 2FA is very low friction. You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. If it wasn't you, then someone else besides you knows your credentials and you need to change them ASAP. If it was you, you have another 2FA point. Also, I enabled 2FA a couple of years ago, and have been happily using app-specific passwords ("…