Live data from Hacker News

Turning off less-secure app access to G Suite accounts

gsuiteupdates.googleblog.com

31–37 of 37 posts

Re: Turning off less-secure app access to G Suite accounts

#31
This is going to be a bit cumbersome for those using Thunderbird or Mail.app (on Mac) or Outlook (Mac) over (plain) IMAP — the document instructs users to remove and re-add these accounts. That would mean (in my understanding, at least of Thunderbird) re-downloading all mails and folders once again into the newly setup account in the client. Those who use only a single device are probably going to have to schedule this appropriately to avoid having no visibility into mails for sometime.

Re: Turning off less-secure app access to G Suite accounts

#32
post #24
post #21

yandex has free mail with free custom domain hosting https://connect.yandex.com/pdd/

Any company based in Russia, China (or any other regime perceived as authoritarian and lacking in the rule of law department) is going to struggle to get on the short-list of "organizations to trust with the master keys to your whole online life".

it depends on your threat model

Re: Turning off less-secure app access to G Suite accounts

#34
post #2

This change will prevent us from using a large number of open source apps, effectively locking us into Google's own tools. My org will be eyeing alternatives when this rolls out.

I've been using Thunderbird fine with App Specific Passwords. Despite the name, these are just revocable passwords. https://support.google.com/accounts/answer/185833?hl=en

That is what is being deprecated, no?

Re: Turning off less-secure app access to G Suite accounts

#35
post #2

This change will prevent us from using a large number of open source apps, effectively locking us into Google's own tools. My org will be eyeing alternatives when this rolls out.

We have our helpdesk ticketing system linked through Google Mail. We have to find another solution.

Re: Turning off less-secure app access to G Suite accounts

#36
post #28

Earlier quoted context omitted.

eh? using your g suite password for email is a huge mistake. the problem isn't the password auth per se, it's that the permissions you grant if the password is exposed are vast, not limited to just sending/receiving email. that said, why they insist on turning it off, rather than just use ASPs, is a bit unfriendly. but it's definitely not because they are treating you as a child.

Not if the sole purpose of that account is email and nothing more. I should be able to make decisions about what an account is used for and how to authenticate, even if that's the "wrong" or "less-secure" decision.

That's a complex (more than necessary) product roadmap, to support the negligible percentage of users that can actually use it "securely". When it comes to security, the typical user leans towards making the wrong choices given the freedom to do so.

You also aren't being denied the capability. There are seemingly innumerable mail hosting services that will let you do IMAP with normal password. You can also host it yourself, using gmail as relay service if you desire.

Re: Turning off less-secure app access to G Suite accounts

#37

Earlier quoted context omitted.

I've been using Thunderbird fine with App Specific Passwords. Despite the name, these are just revocable passwords. https://support.google.com/accounts/answer/185833?hl=en

That is what is being deprecated, no?

Didn't realize until your comment. Bummer.
Post reply on HN