Earlier quoted context omitted.
You aren't necessarily actually sending it to a third party per se though. Less secure access also enables using software running on your own computer to access your email easily. For example offlineimap and imapfilter. In theory it ought to work with OAuth but damned if I can get it to work and any instructions a few years old are useless because something has changed in the interim. It's actually less hassle to mig…
> Less secure access also enables using software running on your own computer to access your email easily. For example offlineimap and imapfilter. In theory it ought to work with OAuth but damned if I can get it to work and any instructions a few years old are useless because something has changed in the interim. You shouldn't need OAuth; have you tried application-specific passwords ( https://support.google.com/acco…
I didn't ever understand why Google allowed you to enter a password into a random piece of software. In fact I'm still somewhat perplexed by them letting you enter it into a browser, but I guess they could be using the browser DRM module to get some assurance they are dealing with software they can trust.
I guess it's just too hard to make move everything to hardware security tokens. Nonetheless, I don't see an choice in the long term - physical security tokens that don't allow firmware upgrades is where we must end up.