44 ms·
Less secure apps and your Google Account
- Maxburn 5y agoThis is going to be a big impact for a lot of our customers. The app we use only supports user/pass auth and lots of people set up special sending only gmail accounts to just get it out and not impact security of their orgs commercial gsuite stuff. Fun times ahead.
- malinens 5y agoShameless plug: move to inbox.eu. We have migration tool to move away from gmail. We use separate auto-generated IMAP password for more secure access via standard IMAP protocol. Auto-generated passwords by our experience are secure and we haven't have problems with account hacking via them
- tialaramex 5y agoIf the passwords are being used by some automated service this is probably fine, at least modulo the quality of the service implementation. If they're for actual humans, even in the best case you're vulnerable to phishing, also you are a perpetual risk because you know these passwords (or a password equivalent) so an adversary might steal your passwords (e.g. from a backup, logs, test systems, ...) and now they can impersonate all users. It's almost certainly safer than letting users pick their own passwords, but it's less protected than, say, a Google user who set up 2-step, and much less than if they went with Advanced Protection and thus can't get phished or impersonated.
- malinens 5y agoI agree but "advanced" users should have the ability to switch advanced protections off (for example, sending emails via SMTP or for easier migration to another provider)
- whyoh 5y agoJust a comment: the difference between business and personal accounts is not very clear. It looks like the business account is better, but it's cheaper. Or is that price just temporary? That slow long scrolling of the pages isn't great either. I suggest making some simple comparison table/chart.
- malinens 5y agoThanks for feedback and I agree with you. Owners of inbox.eu first wanted to market product for less technical small business people. Now we are moving away from this business model and will give more priority for custom domain e-mail. Soon we are launching new pricing page with feature list of free/premium personal mailboxes and custom domain mailboxes
- noduerme 5y agoProbably a stupid question, but, I've been using Thunderbird to d/l my gmail for ten years with POP3, leaving nothing on the server. I don't store a password on my device, I remember it and enter it. I don't use 2FA, because I consider simjacking a risk; my personal email server is my backup address if I get locked out of gmail. I suppose this means that no part of this strategy viz-a-viz gmail, Thunderbird and POP3 is going to work for me anymore..? The good news, I guess, is I won't lose any mail. The bad news is, gmail users have recently started to get email from my private server to their spam, occasionally, even though my IP's nowhere near a blacklist and hasn't been for years; thus, being able to send gmail-to-gmail has been helpful sometimes.
- T3RMINATED 5y ago
- ddtaylor 5y agoI hope YouTube Vanced keeps working since the stock Android YouTube app is complete garbage.
- karlerss 5y agoIs this turning off IMAP access to gmail mailboxes?
- vdfs 5y agoNo, you can use IMAP without password, using app token like any other OAuth
- Ronnie76er 5y agoIn my dim recollection, I've used mail clients that used OAuth for IMAP access, plus it appears they are not taking away App Passwords, which I use for almost all my mail clients.
- eadmund 5y agoDoes this mean no more app tokens, e.g. to retrieve IMAP mail?
- rwmj 5y agoThankfully not so far - it says on that page you can still use an App Password.
- deleted 5y ago[deleted]
- jaimehrubiks 5y agoGreat. There's nothing I hate more than an app or game asking to login with Google and redirecting me to a non Google domain. Of course I have a separate email for those cases
- Cthulhu_ 5y agoI've got great distrust for these pop-up "sign in with Google" or whichever SSO provider you have you find in a lot of apps (or even Apple's accounts thing on macos); how can I verify it is in fact Google and not a 3rd party lookalike?
- shadowgovt 5y agoCheck the URL and check the lock icon. If you're feeling extra paranoid, you can also click the log to get more information on the security certificate to confirm it's the certificate belonging to the provider.
- mortehu 5y agoIf it's in an app you don't necessarily get full browser functionality. You just have to trust the app.
- shadowgovt 5y agoGood point. Although in general, if it's an app, it's gone through the vetting process to arrive on its app store and such password-thieving shenanigans would have been caught during that process. (Ensuring the integrity of that process is one of the reasons the app stores constrain so heavily apps that allow for some flavor of self-modification, via embedding a programming language, running downloaded code, etc.).
- jsnell 5y agoGoogle does not allow oauth from embedded webviews: https://developers.googleblog.com/2021/06/upcoming-security-changes-to-googles-oauth-2.0-authorization-endpoint.html https://developers.googleblog.com/2021/06/upcoming-security-... So you should never need to trust the app.
- shimonabi 5y agoI had to turn this on to transfer emails from Workspace to a free Gmail account with imapsync.
- bxparks 5y agoI used the 16-character App Password. It requires 2FA to be enabled though.
- deleted 5y ago[deleted]
- tomxor 5y agoI've noticed gmail randomly blocks Firefox these days under the pretence of "your browser may not be secure" (i.e it doesn't persist through page refreshes), similar to how they try to make you do a captcha unless you refresh the page... I seem to have less and less control over where and how I am allowed to sign in (even thought I'm using a U2F key), and as a result I'm definitely getting pushed closer to the threshold to move away from gmail out of lockout anxiety. [edit] To all those comments that assume I'm: running an outdated browser, have a broken profile, am running untrustworthy plugins, am doing UA spoofing or have been pwned etc etc... First you are missing the point: I dislike being held to increasingly arbitrary and opaque metrics of what Google defines as "safe"... because that is anxiety inducing, what will it be next week? even if I can log in now, will I be able to log in then? Second: No, this is Google's fault, not mine. I have not been pwned, this occurs through multiple OS installs. I always keep my browser(s) up to date (i'm a web dev), I know the implications of runing lots of plugins (I do not). However i DO employ restrictions as do many HN readers that Google will find undesirable, uBlock Origin, Firefox enhanced tracking protection, block third part cookies, DNS level ad and tracker blocking etc... It's likely Google doesn't like one of these, but back to point no. 1: it's an opaque metric, I do not like this... hell it may even be because i'm running Linux - so maybe I should do UA spoofing after all to pretend to be a "normal" Windows or Mac user.
- emsixteen 5y agoHave never experienced that since switching back to Firefox after years on various Chromium browsers. Developer Edition, on Windows fwiw.
- dijit 5y agoAs others have mentioned it's probably privacy extensions blocking google's checks. NoScript (or, not enabling javascript globally) is known to cause issues for me. Things that hide or obfuscate user agents will break google too. Anything that replaces common CDNs with privacy friendly ones also causes issues.
- dageshi 5y agoI've never experienced this and have used FF for years.
- einpoklum 5y agoI suggest all HN readers use this opportunity to stop using Google accounts, if they haven't done so already. Potential benefits: * Better privacy (on many/most alternatives); Google will no longer read your email, store it for use by themselves and their partners, and perhaps pass a copy along to the NSA as Edward Snowden has revealed happens. * Less exposure to manipulative ads, and lower finesse of manipulation due to less data about you. * Easier for you to turn on ad-blockers without worrying about that also blocking Google junk. * Less chance of Google applying censorship to content you publish or transmit.
- bcanzanella 5y agoWhat are some alternatives?
- gspr 5y agoThe only thing I used my google account for was email. There are many good alternatives – I myself have been happy with mailbox.org for years.
- Nextgrid 5y agoOffice 365.
- einpoklum 5y agoHere's one survey of alternatives: https://restoreprivacy.com/google-alternatives/ https://restoreprivacy.com/google-alternatives/ Personally, I use: * DDG for search. * gmx.com as my main email server (not sure it's that great for privacy, ProtonMail is probably better). * OpenStreetMap for maps (caveat: Some info is on Google Maps and not on there) * HereWeGo for car navigation * Thunderbird as my mail client + calendar * I don't publish videos, but otherwise probably PeerTube * IRC and Matrix for group chatting * F-Droid for FOSS mobile apps, Aurora for anonymous access to Google Play Store Not yet de-googlified: * I use an Android phone (albeit Chinese) * Still need a good alternative for Google Translate.
- bloak 5y agoSo what are the options for people who like to download all their e-mail onto a Linux box and handle it locally?
- shadowgovt 5y agoApplication specific password.
- 3np 5y agoWith offlineimap or mbsync.
- Piskvorrr 5y agoUse a client that implements this authentication protocol - or pick a different mail provider. I know GMail is convenient, but as you're obviously aware, its cost is not just surrendering your data.
- throwaway123x2 5y agoDoes this mean email aliasing is gmail is going to break? I think you need less secure sign in for that to work.
- admn2 5y agoI would also really like to know this. Can anyone help?
- marioletto 5y agoI just did this for a bunch of Gmail accounts that have aliases setup to send out from custom domain email address. So yes, You can still use less secure apps and set up gmail aliases as long as you enable 2fa and obtain an app specific pw that you then use to setup the alias or to log in into your google mail via the less secure app of your choice. Note that there is no need for a phone number to setup 2fa as you can instead use the option of one time login codes and then validate access from your phone using any google app such as the gmail.
- pmlnr 5y agoThey are not saying App Passwords are going away.
- cocoafleck 5y agoAs a note: Google requires two-factor authentication to be enabled to use this feature.
- dataflow 5y agoWhat about GSuite with custom 2FA? There are no App Password options there...
- servytor 5y agoThis kills gnus/mu through Emacs, right?
- jefftk 5y agoNo: the announcement says you can use application specific passwords https://support.google.com/accounts/answer/185833 https://support.google.com/accounts/answer/185833
- rascul 5y agoGoogle keeps making it more and more difficult for me to use their services. It's going to be painful when Google finally forces me off Gmail.
- afandian 5y agoMake the leap before you're pushed!
- lolinder 5y agoSuggestion? Start now. I moved my primary email to a custom domain a bit over a year ago, and it takes a while to slowly migrate everything over. You don't want to be doing that while under pressure from whatever it is that forces you off.
- andrelaszlo 5y agoI'm looking to do that now, since Google will starts charging for (old grandfathered) custom domains. What service are you using for emails?
- lolinder 5y agoI'm using Fastmail, and I've loved it so far. The biggest thing that landed me there was the built-in snooze feature, which works just like Gmail's. Everything else has worked perfectly, too.
- dddnzzz334 5y agoAny suggestions for good privacy-centric email providers?
- pasttense01 5y agoIf you want serious protection you should probably use one NOT based in the country you live in.
- fsflover 5y ago
- MartijnBraam 5y agoIs this the end for git-send-email through Google infra?
- jefftk 5y agoNo: the announcement says you can use application specific passwords https://support.google.com/accounts/answer/185833 https://support.google.com/accounts/answer/185833
- cxr 5y agoIt's interesting how words can be strung together to avert scrutiny of relevant facts pertaining to the message being communicated—and sometimes even used to mask dishonesty.* The terse form of the advisory states: > To help keep your account secure, starting May 30, 2022, Google will no longer support the use of third-party apps or devices which ask you to sign in to your Google Account using only your username and password. It's the innuendo that's interesting. The message in the subtext of this statement is, Look at these apps! They want you to use them for e.g. checking your email, but look at what they do! Isn't it awful? In order to let you check your email, they make you give them the password for your _whole_ Google account! Of course, the only one who's responsible for the current arrangement is Google. Google, not third-party developers, are to blame (and _solely_ to blame) for why access to the various Google services is consolidated into a single account. Google, not the Thunderbird team, are to blame for why your Gmail password is the same as your Google Vault password, which is the same as your YouTube password, which is the same as the password you use to mark your phone as needing to be locked out of your account after it's stolen. * This is why I'm skeptical of the whole "writing forces you to be honest because it means you have to actually think things through well enough to put them into words that can be put into coherent sentences" meme. Nobody seems to talk about how writing and the revision process that's inherent to it also provides the opportunity to finesse words. Some idea can be made to appear as if it's sound and backed by solid reasoning even when the truth is actually much less straightforward—or even contradictory.
- md_ 5y ago> Google, not the Thunderbird team, are to blame for why your Gmail password is the same as your Google Vault password… Hmm, but couldn’t third party developers just use OAuth instead? Thunderbird works with Google’s standard XOATH Oauth IMAP implementation, last I checked.
- striking 5y agoYeah, and for those that don't, app passwords are not hard to use. Slightly cumbersome, maybe, but I bet it'd take less time than GP took to write their comment.
- 5y ago
- FpUser 5y agoEvery application / service that insists on using Google / FB / Whatever as sign in method exclusively is a 100% no go for me.
- haughty 5y agoOk, it's not less secure. But i hope this won't affect my NeoMutt set-up and that 'application password' work around will work as it does now.
- deleted 5y ago[deleted]
- marstall 5y agowhy is google's font so damn tiny? It's like they don't want you to read this stuff.
- apocalyptic0n3 5y agoDo you have the page zoomed out or something? The font-size on that page is 16px tall on desktop. Hacker News titles are 16px and comments are 14px. (Note: I measured in px manually due to the use of rems in the CSS; easier to compare this way)
- jaywalk 5y agoIt's .875rem, which works out to 14px with standard settings. That isn't huge but it's far from "damn tiny" in my opinion. You might have your browser set to a smaller default font size?
- danlugo92 5y agoI just moved to my own domain + Zoho mail. I sleep soundly well knowing I will never lose access to my email.
- spark3k 5y agoIsn't this going to break their own "send mail as" feature in Gmail to send as another Gmail address you own? Which I basically use constantly.
- capableweb 5y agoOne thing you can generally be sure about, no matter what changes they go through: They won't ruin their own services and income-streams. Removing cookies? They have replacement for that in their browser that no extensions will be able to help with. Removing sign-in methods? Within their ecosystem they pass whatever token they want, wherever they want.
- marioletto 5y agoNot really. You just need to use the apps specific pw that you can obtain from your account security page. I just did this for a bunch of Gmail accounts that have aliases setup to send out from custom domain email address. The only change is that you have to enable 2fa to obtain an app specific pw that you then use to setup the alias or to log in into your google mail via the less secure app of your choice. Note that there is no need for a phone number to setup 2fa as you can instead use the option of one time login codes and then validate access from your phone using any google app such as the gmail.
- fortran77 5y agoI'm sure from a business standpoint they don't want to make it harder for users. But My 88 year-old-mother is always getting security warnings from Google when she tries to log in to email (despite me telling her NOT TO DO THIS) from a Kindle Fire device (which is basically an android tablet). And then she panics and tries to change her password, and then she forgets her password even though I tell her to WRITE IT DOWN and put the date next to it. (Don't tell me to get an 88 year old to use a password manager. They would be way too confusing for her.)
- sydney6 5y agoExcerpt from the Mutt OAuth readme page: Mutt can present a token inside IMAP/POP/SMTP, but by design mutt itself does not know how to have a separate conversation (outside of IMAP/POP/SMTP) with the server to authorize the user and obtain refresh and access tokens. Mutt just needs an access token, and has a hook for an external script to somehow obtain one. mutt_oauth2.py is an example of such an external script. It likely can be adapted to work with OAuth2 on many different cloud mail providers, and has been tested against: - Google consumer account (@gmail.com) ...
- tannhaeuser 5y agoJust wanting to point out that as an alternative to ProtonMail, FastMail, etc. you can simply buy your own domain, and point your DNS MX record to a traditional mail service with POP and IMAP access. All DNS registrars I know do offer that, plus RoundCube as web mail service if you want to access it from browsers.
- suzzer99 5y agoWe use pop3 access to gmail accounts for all our automated sign up tests. Will this break that?
- jefftk 5y agoThe sign-in method they're removing really is less secure: you're sending your full username and password to a third-party. Application-specific passwords (https://support.google.com/accounts/answer/185833 https://support.google.com/accounts/answer/185833) and OAuth are much better. Disclosure: I work for Google, speaking only for myself
- samtheDamned 5y agoI agree, I have always hated having to give my google credentials to random apps instead of just using something like oauth where I can be more confident in the security of my credentials.
- Wowfunhappy 5y agoAn email client running on my own machine is not a third party. But regardless, this is why the feature is called "enable access for less secure apps". It's disabled by default, and it re-disables itself automatically unless you're actively using it to sign in. My Google account does not contain nuclear launch codes, and my threat model is not the same as Google's. I am far more worried about getting locked out of my own account due to some mishap than I am someone else getting in, and I think I should be able to assess my own risk. Google can set defaults, but I know my own life. (I will say that I wouldn't mind switching to app-specific passwords, but Google won't let me because I have 2FA turned off. I don't want 2FA because I don't want to get locked out of my account, I don't need 2FA because I use a password manager, and I don't understand how 2FA and app-specific passwords are related.)
- jefftk 5y agoI do think you're right about 2FA, and there should be an option to use an application specific password without 2FA.
- ASalazarMX 5y agoFWIW, 2FA is very low friction. You'll get a "Is this you?" popup in your phone or tablet whenever someone uses your username and password in a new device/browser/application. If it wasn't you, then someone else besides you knows your credentials and you need to change them ASAP. If it was you, you have another 2FA point. Also, I enabled 2FA a couple of years ago, and have been happily using app-specific passwords ("app passwords" now) since they were implemented. Tying them to 2FA activation doesn't look like an engineering limitation.
- jorgesborges 5y agoOops. I have small web apps that use gmail accounts to send mail via SMTP, but this requires turning on "allow less secure apps". Will this break those apps? I suspected this would happen eventually and it's been finicky the past year or so anyway. It was a lazy solution to begin with -- so, I'm setting a reminder about this for May 20th.
- FujiApple 5y agoSadly I believe it will stop working. I'm in the same boat and have been putting off moving to a Google blessed solution because of the effort required to navigate the bewildering array of documentation, client libraries and authentication mechanisms Google offers. Much of the documentation and examples Google makes available are targeted at accessing Gmail on behalf of a human user (who has access to a browser) rather than accessing it on behalf of a machine (which does not). Cutting through the noise is half the battle! I reluctantly spent some time this morning trawling through it and whilst I now have a working solution I couldn't begin to say whether it is the right approach. In the end I decided to ditch SMTP and use the GMail API [1] with a service account [2] setup with domain-wide delegation [3] which is nearly as scary as it sounds. One caveat of this approach is that I choose to use a service account `key` (not to be confused with an `API Key`!) rather than the Google recommended "Workload Identity Federation" [4] so no-doubt this will be depreciated at some point. If you must stick with SMTP then [5] is a good resource for showing how to use SASL XOAUTH with an access token to authenticate with Gmail SMTP. Of course, you need to obtain the access token from Google IAM to use this anyway so there is little benefit of doing this vs using the GMail API directly. [1] https://developers.google.com/gmail/api/guides/sending https://developers.google.com/gmail/api/guides/sending [2] https://developers.google.com/identity/protocols/oauth2#serviceaccount https://developers.google.com/identity/protocols/oauth2#serv... [3] https://developers.google.com/identity/protocols/oauth2/service-account#delegatingauthority https://developers.google.com/identity/protocols/oauth2/serv... [4] https://cloud.google.com/iam/docs/workload-identity-federation https://cloud.google.com/iam/docs/workload-identity-federati... [5] https://developers.google.com/gmail/imap/xoauth2-protocol#smtp_protocol_exchange https://developers.google.com/gmail/imap/xoauth2-protocol#sm...
- 5y ago
- belter 5y agoSo many startups implementing absurd ideas, when the best opportunity is right in front of your eyes. Create a paid, highly reliable, highly secure, client side encrypted, email based service on a proper jurisdiction. Open source your clients and open yourself to independent audits. Be open with your customers, friendly and transparent. Earn the money... Fastmail, Rackspace and Protonmail are good offers, but as mentioned in this thread for one reason or the other can still be improved. Any takers?
- PopAlongKid 5y agoCan some please ELIF about how this affects Thunderbird. I currently (and for years) have used POP3 to download my gmail mailbox (and SMTP to send outgoing). My Thunderbird account setting for gmail currently shows "normal password". Will I have to change it to OAuth or one of the others? Or will I need a special "password" just for use with Thunderbird (this is something my Yahoo/AT&T email started requiring last year). Maybe related, I have seen for years that whenever I try to download gmail into Thunderbird and I am not at my normal office location, Google requires me to first log in to my account via a browser, then it allows the Thunderbird login.
- tialaramex 5y agoSince nobody else responded: I don't use Thunderbird, but yes, if you have anything vaguely close to a modern Thunderbird then you should choose OAuth2 instead of "Normal Password" for both sending and receiving. You may need to exit Thunderbird and go back in, then it should prompt you via what is in effect a web frame, to log in by whatever means you ordinarily use for Google, then Google asks if you really want to let Thunderbird read and send mail (you do) and this grants it a token that it will use to access your mail. The alternative would be to set up an "App password" in your Google account and then paste the password (which Google chooses) into Thunderbird. That password is then independent of your actual Google password and can't be used to sign in as you on Google, just by mail clients for checking mail and so on, sounds like you did this with Yahoo/AT&T already once. Prefer OAuth2.
- i13e 5y agoHonestly this seems like a good thing. Using app passwords to sign in to insecure apps instead of your actual password is much more secure, I already use that for Google and my Nextcloud instance and it makes it easier to keep track of where you're signed in. You Google account holds so much information about you nowadays that securing it is tantamount.
- throwaway5486nv 5y agoTranslation: Every account must be tied to mobile number. No more privacy
- tialaramex 5y agoTranslation: throwaway5486nv has poor reading comprehension
- throwaway5486nv 5y agoIts not about what's written. Its about the intention behind this.
- meesterdude 5y agoRelatedly... I also can't sign in via embedded browser. I understand they have reasons, but like, shouldn't there be A way to do it if it's an embed that you trust? I don't get it.
- asveikau 5y agoLooks like they're not disabling the "app passwords" feature. So you can still do things like IMAP via that.
- chimeracoder 5y agoAnnoyingly, Google doesn't actually support app-specific passwords for accounts that don't have two-factor authentication enabled. So for use cases that require a password (eg SMTP), there's literally no other option available. (Yes, 2FA increases security, but if someone doesn't or can't have it enabled, for whatever reason, that's no reason to prevent them from using app-specific passwords)
- malinens 5y agoGoogle will soon disable free access to legacy free domain mailboxes (G-Suite). When developing migration tool at inbox.eu it was major headache to implement migration from google. You either use web oauth2 login for each mailbox one by one (imagine pain moving thousands of mailboxes), or enable less secure apps option which now works unreliably or use not easy to obtain global service key to have full access to all domain (which admins do not want). Google makes really hard to move to another mailbox provider. I am actually updating migration tool to make it simpler to migrate
- tambourine_man 5y agoDoes this means that the curl hack to send email won’t work anymore? If so, that’s a bummer
- squarefoot 5y agoThe heck I'm ditching Claws Mail for that slower than molasses web interface. Any recommendation for a secure and very cheap mail service that doesn't hate SMTP+POP? I'm already aware of Fastmail which would probably be my choice if I don't find a better+cheaper alternative.
- majpourmal 5y ago
- spacexsucks 5y agoIt is not your data, it is data for google to mine. Google "engineering" excuse everytime is it is for your safety