Live data from Hacker News

Less secure apps and your Google Account

support.google.com

241–250 of 272 posts

Re: Less secure apps and your Google Account

#241

Earlier quoted context omitted.

FWIW, 2FA is very low friction. You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. If it wasn't you, then someone else besides you knows your credentials and you need to change them ASAP. If it was you, you have another 2FA point. Also, I enabled 2FA a couple of years ago, and have been happily using app-specific passwords ("…

Googles 2fa requires the user to give google his phone number before being able to add a totp authenticatior. That alone is reason for me to never use it for my google account. The popup also doesn't come up if you haven't signed up with google on your phone, obviously. There is nothing stopping them from just allowing anyone to add a normal totp 2fa generator, they just chose to not do that to get more of that sweet…

Does Google fall back to SMS if you tell it you lost your totp authenticator? That’s problematic in its own way, but it would explain the phone number requirement.

Re: Less secure apps and your Google Account

#242

Earlier quoted context omitted.

FWIW, 2FA is very low friction. You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. If it wasn't you, then someone else besides you knows your credentials and you need to change them ASAP. If it was you, you have another 2FA point. Also, I enabled 2FA a couple of years ago, and have been happily using app-specific passwords ("…

> You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. I have two different concerns. The first is that I frequently end up having to clear my browser cookies, for a variety of reasons. Every time I do, I have to redo the 2FA dance, on every single website that requires 2FA. I suppose I could find a different cookie management…

Then try TOTP, and back up your seeds.

Re: Less secure apps and your Google Account

#243

Earlier quoted context omitted.

Shameless plug: move to inbox.eu. We have migration tool to move away from gmail. We use separate auto-generated IMAP password for more secure access via standard IMAP protocol. Auto-generated passwords by our experience are secure and we haven't have problems with account hacking via them

If the passwords are being used by some automated service this is probably fine, at least modulo the quality of the service implementation. If they're for actual humans, even in the best case you're vulnerable to phishing, also you are a perpetual risk because you know these passwords (or a password equivalent) so an adversary might steal your passwords (e.g. from a backup, logs, test systems, ...) and now they can i…

I agree but "advanced" users should have the ability to switch advanced protections off (for example, sending emails via SMTP or for easier migration to another provider)

Re: Less secure apps and your Google Account

#244

Earlier quoted context omitted.

FWIW, 2FA is very low friction. You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. If it wasn't you, then someone else besides you knows your credentials and you need to change them ASAP. If it was you, you have another 2FA point. Also, I enabled 2FA a couple of years ago, and have been happily using app-specific passwords ("…

> You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. I have two different concerns. The first is that I frequently end up having to clear my browser cookies, for a variety of reasons. Every time I do, I have to redo the 2FA dance, on every single website that requires 2FA. I suppose I could find a different cookie management…

Have you thought about multiple 2FA devices?

To my knowledge, you can use as 2FA w/Google:

1. A prompt on your phone

2. A hardware security key

3. TOTP token from authenticator

4. one of 10 backup codes

And you can also have multiple security keys as well, which is useful if you lose one.

Re: Less secure apps and your Google Account

#245

Earlier quoted context omitted.

> You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. I have two different concerns. The first is that I frequently end up having to clear my browser cookies, for a variety of reasons. Every time I do, I have to redo the 2FA dance, on every single website that requires 2FA. I suppose I could find a different cookie management…

Have you thought about multiple 2FA devices? To my knowledge, you can use as 2FA w/Google: 1. A prompt on your phone 2. A hardware security key 3. TOTP token from authenticator 4. one of 10 backup codes And you can also have multiple security keys as well, which is useful if you lose one.

A prompt on my phone and an app on my phone come down to the same thing, and I'm not interested in getting a physical hardware security key. The backup codes are one-time use, and there is no way I would keep track of a slip of paper for years without loosing it.

I could use my password manager (Bitwarden) as my TOTP generator, and I may eventually do that just to make all of these services shut up. But, wouldn't that leave my account no more secure than it already is today? It would effectively be single-factor authentication, since the password and the generator would be in the same place, protected by the same master password.

Re: Less secure apps and your Google Account

#246
post #16

I've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the thresh…

[deleted]

Re: Less secure apps and your Google Account

#248
post #119

The sign-in method they're removing really is less secure: you're sending your full username and password to a third-party. Application-specific passwords ( https://support.google.com/accounts/answer/185833 ) and OAuth are much better. Disclosure: I work for Google, speaking only for myself

Sometimes you can't use OAuth because your client doesn't support it. If you ever run into that problem you might find my project useful - OAuth Hopper serves as a simple proxy that removes OAuth from services.

github.com/bjesus/oauth-hopper/

Re: Less secure apps and your Google Account

#249
post #225

Earlier quoted context omitted.

Ebay supports WebAuthn, does PayPal not?

If it does, that's be great, as I do have a PayPal account to solve a problem I had with one payment platform, but when I last looked it only offered TOTP

I just went to the bother of logging in to my PayPal, it shows only TOTP and some sort of SMS nonsense I won't touch, so, TOTP it is until either PayPal implements WebAuthn or somebody else in this space takes my business (by offering WebAuthn).
Post reply on HN