7 ms·
My heart skipped a beat when I read this — I have various scripts and things that interact with Gmail. But it's okay. App passwords will still work, it seems.
by interroboink 3y ago
My heart skipped a beat when I read this — I have various scripts and things that interact with Gmail.
But it's okay. App passwords will still work, it seems. This is just removal of "Less Secure Apps" support, using the account's plain account user/password.
I shudder to think how much automation would die if Google truly killed off everything but OAuth.
I don't like the complexity OAuth. I enjoyed this Perl module documentation[1] that breaks down how the dang thing works, clearly written by someone as exasperated as me (:
[1] https://metacpan.org/dist/LWP-Authen-OAuth2/view/lib/LWP/Authen/OAuth2/Overview.pod https://metacpan.org/dist/LWP-Authen-OAuth2/view/lib/LWP/Aut...
- leipert 3y agoShouldn't be _too_ hard to convert your scripts. I ran into the same problem and one workspace disallows App passwords. You can simply get the OAuth token with a little python script and then use it as the password: https://github.com/google/gmail-oauth2-tools/blob/master/python/oauth2.py https://github.com/google/gmail-oauth2-tools/blob/master/pyt... (see for example https://github.com/lefcha/imapfilter/issues/186 https://github.com/lefcha/imapfilter/issues/186)
- booi 3y agoand then have to reauthenticate it every 2 weeks because the refresh token seemingly expires for no reason...
- justinc8687 3y agoIf you set your app to "production", the refresh token works properly. Ignore the verification steps. It'll yell at you, but it'll work.
- xmprt 3y agoHow can you set an app to production without Google verification if you're not in a workspace. I'm guessing the answer is that there is no way.
- nunez 3y agoThe refresh token shouldn't expire.
- firecall 3y agoMe too! I have a few scripts and dev environments that use App Passwords to send email via Gmail SMTP!
- flanked-evergl 3y agohttps://github.com/smallstep/cli https://github.com/smallstep/cli implements some OAuth flows from the CLI, it may be helpful for you.
- deleted 3y ago[deleted]
- deleted 3y ago[deleted]
- bagels 3y agoThank you! This was my concern as well.
- boiler_up800 3y agoWow thanks for clarifying. Heavy user of app passwords here.
- _Algernon_ 3y agoProblem seems that you cannot set app passwords yourself and they seem laughably insecure. 16 lowercase letters (in groups of 4 separated by space), no numbers, no special characters. Keepass evaluates this as a weak password with 65 bits of entropy (if spaces are removed) How is this an improvement?
- SpaghettiCthulu 3y agoThat should be plenty seeing as Google would lock your account before an attacker were ever able to bruteforce an app password, right?
- _Algernon_ 3y agoAssuming the attacker doesn't have a leaked database of hashed passwords and therefore can't run the brute force on a local database. I want my account to be secure even if there is a leak which has been the standard for authentication for more than a decade.
- freedomben 3y agoThis password should not be in any leaked database of hashed passwords, because it is completely randomly generated. You can't even set it.* *unless you take this password after it's generated and start reusing it in other services, but that is pure self sabotage
- jjnoakes 3y agoIt would be if Google's app password hash database was leaked.
- freedomben 3y agoGood point, although if that happens, then I think we probably have a much bigger problem
- 3y ago
- ojosilva 3y agoI just hope that Gmail itself (as client) becomes something other than a Less Secure App. Right now I have to keep that LSA switch going so that my main Gmail account can SMTP send mail with credentials from my other many Gmail accounts. I've never understood why Gmail itself is a LSA in the eyes of other Gmail accounts.
- Arnt 3y agoI don't know why it is that, but I know why it was that at one time, quite long ago: One team had set terms for what avoids LSAness, another team hadn't updated some code to match the new terms.
- chimeracoder 3y ago> I've never understood why Gmail itself is a LSA in the eyes of other Gmail accounts. Because Google isn't special-casing itself (which is a good thing). You can enable 2FA on the other accounts and then use app-specific passwords, which will allow you to disable the switch.
- systems 3y agoCPAN , the jewel , the original, the king , may raku find your success
- bdavbdav 3y agoPhew. Wasn’t sure what to do with networked devices that inevitably don’t support Oauth
- blinkingled 3y agoI had been wanting to read a document on OAuth as I have several things in pipeline where OAuth would be involved and the link you posted is just timely and perfect - so thank you!
- deleted 3y ago[deleted]