Re: OT - Google accounts turning off less secure access

May 24, 2022 Last reply: 4 years ago 82 Replies


I run a home server and all our email goes through that, but it also picks up


> email from a number of accounts that we don't use day to day, but need to know
> if important notifications arrive from them.

Not used it, but another approach could be


formatting link

Well, things that google chooses to label "insecure apps" are going to be denied access, leaving many with a practical problem of accessing email. But do not confuse google's claims of "insecurity" with any sort of guaranteed truth; although some email downloading software blocked by google might be insecure, there is also long established and actively maintained software which isn't insecure, and will still be blocked.

#Paul

Could be useful, but for now, I have done what you previously mentioned and set up an app specific password - which is working fine.

As have I. Although I have to say I'm not sure how it counts as being that much more secure. Anyway, all I care about is that it looks like it won't obsolete my app, so thanks to Andy for that.

" a practical problem of accessing *gmail*" maybe but there's nothing forcing people into using gmail. Even Android users are perfectly at liberty to use other email providers.

They should know google already knows enough about them to not make the helicopter worthwhile :-)

I use Aquamail on Android, handles multiple mailboxes nicely and very configurable. It is oAuth2 compliant !

It does mean that your email program's access password is not the same as your Google account's, so someone getting hold of your password will be able to access your email, but not the rest of your account - which with Google able to be used to log you in to all sorts of accounts and to make payments, might matter.

More likely the other way given that the new approach only applys to gmail, making it harder for someone who pinches your google password to access your other stuff.

Email is probably the only Google function that you access with a specific third-party app - which could leak the account details. To enable a specific password, without 2fa for email, you have to turn on

2fa, which makes the rest of your account more secure than your email.

I don't think that they are trying to protect your email from the rest of your account, just bringing the general level up, taking away the system that let you use external email readers before, but implementing a new system to allow you to continue using them without compromising the new systems for everything else.

That's all, in fact, that they have done, other than only allowing this if you agree to them having your phone number. And in fact there was never any reason that, for setting up access to your gmail via a third party app, they couldn't right from the beginning have insisted that you set up the password just as they are doing now for an app password.

Giving them a phone number to allow a confirmation by text message or voice call is one option for enabling 2SV, but it's not their preferred option, which is to use an existing phone or tablet already signed-in to the the same google account, the third option is a USB or NFC security dongle.

formatting link

After the initial sign-up, there is even an option to print out a batch of one-time codes, to allow signing in when you don't have your phone or dongle with you.

Lots of stuff allows you to use google to login now.

But if you don't use gmail, you don't need to change anything.

Yes, but not the other way around.

Agreed, but then you'd not have third party app to potentially compromise your password.

Still had normal gmail access 11:30 BST today via Thunderbird v15, I think, cookies enabled but as ancient i assumed it would cease gmail function. Due to this thread I checked via library access and web browser last week and secondary authorising via ref to a defunct email account I used to have. Again library access today about 10:30 and simple PW only access . I thought libraries wiped all cookies after each person's session???? Perhaps cuts in 9am CPT or something yanky

I am using Thunderbird for gmail. I enabled the 'use insecure application' bollox.

settings are

SMTP ==== port 465 on smtp.gmail.com using :SSL/TLS security and method: Oauth2

POP === port 995 on pop.gmail.com using :SSL/TLS security and method: Oauth2

I have also had IMAP working but prefer to delete messages off the server - I only use gmail for where I need a google account.

HTH

Nothing's going to change for web browser access to gmail, only email client access ...

That is what they are due to disable, you need to either use oauth2, or create a thunderbird specific password.

web access , only testing, as a last resort if required, otherwise un-installed latest version of TB on a thumbstick, left unexecuted so far. It was bad enough 10 years or so ago, but now there is a phenominal amount of irrelevant (to emal) crap on web-browser "gmail" , alright for those who like playing the video game , whack-a-mole on infuriating irrelvant popups I suppose.

Oauth2 *is* 'insecure application' IIRC..

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required