Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > alt.comp.microsoft.windows > #1384 > unrolled thread

How to recover from Google dropping password support on May 30th 2022

Started byAndy Burnelli <spam@nospam.com>
First post2022-03-04 16:57 +0000
Last post2022-03-05 01:02 +0000
Articles 20 on this page of 45 — 9 participants

Back to article view | Back to alt.comp.microsoft.windows


Contents

  How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-04 16:57 +0000
    Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-04 21:23 +0100
      Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-04 12:40 -0800
        Re: How to recover from Google dropping password support on May 30th 2022 Andy Burns <usenet@andyburns.uk> - 2022-03-04 20:49 +0000
          Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-04 12:57 -0800
            Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-04 22:10 +0100
              Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-04 14:39 -0800
                Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-04 23:51 +0100
                  Re: How to recover from Google dropping password support on May 30th 2022 Big Al <Bears@invalid.com> - 2022-03-04 17:58 -0500
                  Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-04 15:33 -0800
                    Re: How to recover from Google dropping password support on May 30th 2022 Jasen Betts <usenet@revmaps.no-ip.org> - 2022-03-05 01:00 +0000
                      Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-04 21:20 -0800
                        Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-05 09:22 +0100
                        Re: How to recover from Google dropping password support on May 30th 2022 Jasen Betts <usenet@revmaps.no-ip.org> - 2022-03-05 22:09 +0000
                    Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-05 09:27 +0100
                      Re: How to recover from Google dropping password support on May 30th 2022 "Gary R. Schmidt" <grschmidt@acm.org> - 2022-03-05 21:57 +1100
                        Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-05 13:11 +0100
                Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 00:55 +0000
                  Re: How to recover from Google dropping password support on May 30th 2022 ant@zimage.comANT (Ant) - 2022-03-04 18:57 -0600
                    Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 01:28 +0000
                      Re: How to recover from Google dropping password support on May 30th 2022 Andy Burns <usenet@andyburns.uk> - 2022-03-05 11:18 +0000
                        Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 15:36 +0000
                          Re: How to recover from Google dropping password support on May 30th 2022 Andy Burns <usenet@andyburns.uk> - 2022-03-05 16:04 +0000
                            Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-05 18:58 +0100
                              Re: How to recover from Google dropping password support on May 30th 2022 Andy Burns <usenet@andyburns.uk> - 2022-03-05 18:47 +0000
                                Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-05 21:21 +0100
                Re: How to recover from Google dropping password support on May 30th 2022 Andy Burns <usenet@andyburns.uk> - 2022-03-05 11:10 +0000
                  Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-06 09:11 -0800
                    Re: How to recover from Google dropping password support on May 30th 2022 Paul <nospam@needed.invalid> - 2022-03-06 12:46 -0500
                      Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-06 21:23 -0800
            Re: How to recover from Google dropping password support on May 30th 2022 Andy Burns <usenet@andyburns.uk> - 2022-03-04 21:26 +0000
              Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-04 23:05 +0100
              Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-04 15:23 -0800
                Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-05 09:31 +0100
                Re: How to recover from Google dropping password support on May 30th 2022 Andy Burns <usenet@andyburns.uk> - 2022-03-05 11:20 +0000
              Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 00:59 +0000
                Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 01:48 +0000
        Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-04 22:07 +0100
          Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-04 14:15 -0800
            Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-05 00:00 +0100
          Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 01:05 +0000
            Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-05 09:39 +0100
              Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 15:24 +0000
      Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 00:19 +0000
      Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 01:02 +0000

Page 2 of 3 — ← Prev page 1 [2] 3  Next page →


#1421

FromAndy Burns <usenet@andyburns.uk>
Date2022-03-05 11:18 +0000
Message-ID<j8gv7uFj370U1@mid.individual.net>
In reply to#1412
Andy Burnelli wrote:

> Anyway, after I set all that up, it gives me this confusing page:
> <https://i.postimg.cc/MGs3HSyn/gmailpasswd04.jpg>

K-9 doesn't support oAuth2, so you must be using "less secure apps" or an "app 
specific password" with it to gmail.  Since I've not received the warning email 
from google, I'm not sure if they're only binning the former method or both methods.

[toc] | [prev] | [next] | [standalone]


#1425

FromAndy Burnelli <spam@nospam.com>
Date2022-03-05 15:36 +0000
Message-ID<t00029$9b7$1@gioia.aioe.org>
In reply to#1421
Andy Burns wrote:

>> Anyway, after I set all that up, it gives me this confusing page:
>> <https://i.postimg.cc/MGs3HSyn/gmailpasswd04.jpg>
> 
> K-9 doesn't support oAuth2, so you must be using "less secure apps" or an "app 
> specific password" with it to gmail.  Since I've not received the warning email 
> from google, I'm not sure if they're only binning the former method or both methods.

Oh oh... that's bad news that K-9 doesn't support OAuth2 as that means if
they don't support it by the Google deadline, we're all toast who use it.

You are correct though that I currently have less secure apps set as shown:
 <https://i.postimg.cc/cL9r9qFW/gmailpasswd05.jpg>

So the question (for Android) would be how to keep K9 working after cutoff.

[toc] | [prev] | [next] | [standalone]


#1426

FromAndy Burns <usenet@andyburns.uk>
Date2022-03-05 16:04 +0000
Message-ID<j8hg17Fm6tsU1@mid.individual.net>
In reply to#1425
Andy Burnelli wrote:

> So the question (for Android) would be how to keep K9 working after cutoff.

https://support.google.com/accounts/answer/185833?hl=en

You're probably not going to like that it requires 2FA

[toc] | [prev] | [next] | [standalone]


#1427

From"Carlos E.R." <robin_listas@es.invalid>
Date2022-03-05 18:58 +0100
Message-ID<bukcfi-qgn.ln1@Telcontar.valinor>
In reply to#1426
On 2022-03-05 17:04, Andy Burns wrote:
> Andy Burnelli wrote:
> 
>> So the question (for Android) would be how to keep K9 working after 
>> cutoff.
> 
> https://support.google.com/accounts/answer/185833?hl=en
> 
> You're probably not going to like that it requires 2FA

I concur.


For me the problem is, that the only account where I got the warning 
mail, is not associated with any Android device, simply because it 
predates them, so AFAIK 2FA is not possible. My Android devices are 
associated with another Google account.

-- 
Cheers, Carlos.

[toc] | [prev] | [next] | [standalone]


#1428

FromAndy Burns <usenet@andyburns.uk>
Date2022-03-05 18:47 +0000
Message-ID<j8hpitFo1elU1@mid.individual.net>
In reply to#1427
Carlos E.R. wrote:

> For me the problem is, that the only account where I got the warning mail, is 
> not associated with any Android device, simply because it predates them, so 
> AFAIK 2FA is not possible. My Android devices are associated with another Google 
> account.

Can't you add the old account, as a second google account, to one of your 
phones/tablets?

[toc] | [prev] | [next] | [standalone]


#1429

From"Carlos E.R." <robin_listas@es.invalid>
Date2022-03-05 21:21 +0100
Message-ID<cbtcfi-t5q.ln1@Telcontar.valinor>
In reply to#1428
On 2022-03-05 19:47, Andy Burns wrote:
> Carlos E.R. wrote:
> 
>> For me the problem is, that the only account where I got the warning 
>> mail, is not associated with any Android device, simply because it 
>> predates them, so AFAIK 2FA is not possible. My Android devices are 
>> associated with another Google account.
> 
> Can't you add the old account, as a second google account, to one of 
> your phones/tablets?
> 

Hum.

I don't know if I want to do that :-?


It would have to be on my main phone, the only device that is guaranteed 
to be near me in every case google wants me to authenticate.

I'll have to think about it.

-- 
Cheers, Carlos.

[toc] | [prev] | [next] | [standalone]


#1420

FromAndy Burns <usenet@andyburns.uk>
Date2022-03-05 11:10 +0000
Message-ID<j8guokFj0h4U1@mid.individual.net>
In reply to#1399
The Real Bev wrote:

> oath2whatever can't be implemented for POP by Thunderbird

We had this discussion a few months back, yes it can, pop is what I use with TB 
v91 and gmail, it may not be available with your older version?

[toc] | [prev] | [next] | [standalone]


#1431

FromThe Real Bev <bashley101@gmail.com>
Date2022-03-06 09:11 -0800
Message-ID<t02q0e$qu4$1@dont-email.me>
In reply to#1420
On 03/05/2022 03:10 AM, Andy Burns wrote:
> The Real Bev wrote:
>
>> oath2whatever can't be implemented for POP by Thunderbird
>
> We had this discussion a few months back, yes it can, pop is what I use with TB
> v91 and gmail, it may not be available with your older version?

TB 38.  Definitely older.

I'm wondering about downloading the latest TB version into a separate 
subdirectory, letting (requiring?) it to create a new profile, and then 
copying over the entire contents of my current profile over the new 
profile (cp -arf * I think).  This is my normal Firefox update method 
and it seems to work fine.  Will it work nicely with Thunderbird too?

-- 
Cheers, Bev
    Linux:  The penguin is mightier than the sword

[toc] | [prev] | [next] | [standalone]


#1432

FromPaul <nospam@needed.invalid>
Date2022-03-06 12:46 -0500
Message-ID<t02s0s$br7$1@dont-email.me>
In reply to#1431
On 3/6/2022 12:11 PM, The Real Bev wrote:
> On 03/05/2022 03:10 AM, Andy Burns wrote:
>> The Real Bev wrote:
>>
>>> oath2whatever can't be implemented for POP by Thunderbird
>>
>> We had this discussion a few months back, yes it can, pop is what I use with TB
>> v91 and gmail, it may not be available with your older version?
> 
> TB 38.  Definitely older.
> 
> I'm wondering about downloading the latest TB version into a separate subdirectory, letting (requiring?) it to create a new profile, and then copying over the entire contents of my current profile over the new profile (cp -arf * I think).  This is my normal Firefox update method and it seems to work fine.  Will it work nicely with Thunderbird too?
> 

Thunderbird has profile migration. It can note the
"version numbers" inside files and deal with them.
For example, if you define a filter (killfile), those
have version numbers, and the file might need to be
migrated. On minor release changes, just the version
number field might change.

Some details might not have changed, simply because
of a lack of developers who understand them. Mork
format for example, a kind of database format, only
a couple people have a good idea how it works. More common
things like .eml format, share details with other email
clients.

Any password scheme, will change between releases.
There's more reason to be tweaking that aspect.
Or maybe the storage of certificates might be messed about.

Seamonkey, a parallel development scheme, their web page
usually has warnings about how "compatible" their migration
is. I don't think Thunderbird has nearly the same level of
warnings.

No tool likes to go "backwards". It's unlikely the tool
will like a request to migrate from 91 to 38. Such as
if you move a 91 profile, to your TB38 installation.

As for the "copying" step, you can edit "profiles.ini"
and add an entry which points to where-ever the profile
is located. For example, right now I have a profile folder
which is in ~/Downloads, where I am more likely to
bump into it, back it up, and so on. On Linux, the
"file system distance", likely isn't that large between
where the profile is normally stored, and the Downloads folder.
On Windows, the path is a bit more obscure (for casual users
who haven't turned off all Hidden features). On Windows,
it might be down in AppData:Roaming (visibility problem).

This is an example of an older format for a profiles.ini . Newer
ones are more of a mess for some reason. I won't put a newer one,
because I couldn't explain what they were thinking :-)

[General]
StartWithLastProfile=1

[Profile0]
Name=default
IsRelative=0                                       <=== absolute path
Path=C:\Users\Username\Downloads\1234abcd.default  <=== absolute path
Default=1                                          <=== "nominated"

    Paul

[toc] | [prev] | [next] | [standalone]


#1433

FromThe Real Bev <bashley101@gmail.com>
Date2022-03-06 21:23 -0800
Message-ID<t044t3$8gp$1@dont-email.me>
In reply to#1432
On 03/06/2022 09:46 AM, Paul wrote:
> On 3/6/2022 12:11 PM, The Real Bev wrote:
>> On 03/05/2022 03:10 AM, Andy Burns wrote:
>>> The Real Bev wrote:
>>>
>>>> oath2whatever can't be implemented for POP by Thunderbird
>>>
>>> We had this discussion a few months back, yes it can, pop is what I use with TB
>>> v91 and gmail, it may not be available with your older version?
>>
>> TB 38.  Definitely older.
>>
>> I'm wondering about downloading the latest TB version into a separate subdirectory, letting (requiring?) it to create a new profile, and then copying over the entire contents of my current profile over the new profile (cp -arf * I think).  This is my normal Firefox update method and it seems to work fine.  Will it work nicely with Thunderbird too?
>>
>
> Thunderbird has profile migration. It can note the
> "version numbers" inside files and deal with them.
> For example, if you define a filter (killfile), those
> have version numbers, and the file might need to be
> migrated. On minor release changes, just the version
> number field might change.
>
> Some details might not have changed, simply because
> of a lack of developers who understand them. Mork
> format for example, a kind of database format, only
> a couple people have a good idea how it works. More common
> things like .eml format, share details with other email
> clients.
>
> Any password scheme, will change between releases.
> There's more reason to be tweaking that aspect.
> Or maybe the storage of certificates might be messed about.
>
> Seamonkey, a parallel development scheme, their web page
> usually has warnings about how "compatible" their migration
> is. I don't think Thunderbird has nearly the same level of
> warnings.
>
> No tool likes to go "backwards". It's unlikely the tool
> will like a request to migrate from 91 to 38. Such as
> if you move a 91 profile, to your TB38 installation.
>
> As for the "copying" step, you can edit "profiles.ini"
> and add an entry which points to where-ever the profile
> is located.

No, I want to leave TB38's profile untouched by anything but TB38.  The 
copy is to see if the latest version can cope with what I regard as 
essential.

So far it's worked copying FF82's profile to the FF98(?) nightly, but 
when I tried to update the nightly it broke.  Just deleted the FF 
nightly and haven't tried again.  One of these days.

> For example, right now I have a profile folder
> which is in ~/Downloads, where I am more likely to
> bump into it, back it up, and so on. On Linux, the
> "file system distance", likely isn't that large between
> where the profile is normally stored, and the Downloads folder.
> On Windows, the path is a bit more obscure (for casual users
> who haven't turned off all Hidden features). On Windows,
> it might be down in AppData:Roaming (visibility problem).

No reason to move the profiles from where they are.  I run a backup 
almost every night of my entire working partition.

> This is an example of an older format for a profiles.ini . Newer
> ones are more of a mess for some reason. I won't put a newer one,
> because I couldn't explain what they were thinking :-)
>
> [General]
> StartWithLastProfile=1
>
> [Profile0]
> Name=default
> IsRelative=0                                       <=== absolute path
> Path=C:\Users\Username\Downloads\1234abcd.default  <=== absolute path
> Default=1                                          <=== "nominated"
>
>      Paul
>


-- 
Cheers, Bev
    666øF -- the oven temperature for roast beast.

[toc] | [prev] | [next] | [standalone]


#1395

FromAndy Burns <usenet@andyburns.uk>
Date2022-03-04 21:26 +0000
Message-ID<j8fefvFaegnU1@mid.individual.net>
In reply to#1391
The Real Bev wrote:

> Andy Burns wrote:
> 
>> Depends if you have 2FA enabled or not.
> 
> Two-factor authentication, right?  Is the text-code-to-your-phone method the 
> only way of doing this?

The way google do it, isn't by sending a text message with a code you have to 
input; they just pop-up a question "is that you signing in?" on all your 
phones/tablets linked to that account, you can answer on any of them

I presume there's a backup method in case all your devices are out of battery of 
destroyed in a freak accident ...

>>> Personally, password security is perfectly acceptable to me
>>
>> Then none of this is the end of the world to you, just carry on using your 
>> password.
> 
> BUT google's messages seem to say that passwords will no longer work with google 
> apps.  WTF?  Google's website offers no enlightenment.

I seem to have snipped your Q about bluemail, but yes it supports oAuth2, google 
aren't going to break their own apps with this, it might break some 3rd party 
apps (whether on phone or PC) that don't support oAuth2, for those the probably 
(not checked) then individual app passwords will still work, one "less secure 
apps" is turned off.

[toc] | [prev] | [next] | [standalone]


#1396

From"Carlos E.R." <robin_listas@es.invalid>
Date2022-03-04 23:05 +0100
Message-ID<c2fafi-t3l.ln1@Telcontar.valinor>
In reply to#1395
On 2022-03-04 22:26, Andy Burns wrote:
> The Real Bev wrote:
>> Andy Burns wrote:
>>
>>> Depends if you have 2FA enabled or not.
>>
>> Two-factor authentication, right?  Is the text-code-to-your-phone 
>> method the only way of doing this?
> 
> The way google do it, isn't by sending a text message with a code you 
> have to input; they just pop-up a question "is that you signing in?" on 
> all your phones/tablets linked to that account, you can answer on any of 
> them
> 
> I presume there's a backup method in case all your devices are out of 
> battery of destroyed in a freak accident ...

The problem is on the accounts that are not associated to any phone or 
tablet. I have one such, from times before Android existed. And it is 
the only one that got that email notice.

The question gets sent to the gmail account (which can not see it, as it 
was blocked) and to the recovery mail accounts. Then I have to use 
firefox to login and say "yes, that was me".

Happens to me using Alpine and postfix (Linux), not Thunderbird.

As there is no associated android device, it is not possible to activate 
2FA, and thus I can not use application passwords, google doesn't 
activate the method.


-- 
Cheers, Carlos.

[toc] | [prev] | [next] | [standalone]


#1403

FromThe Real Bev <bashley101@gmail.com>
Date2022-03-04 15:23 -0800
Message-ID<svu72d$eb9$1@dont-email.me>
In reply to#1395
On 03/04/2022 01:26 PM, Andy Burns wrote:
> The Real Bev wrote:
>
>> Andy Burns wrote:
>>
>>> Depends if you have 2FA enabled or not.
>>
>> Two-factor authentication, right?  Is the text-code-to-your-phone method the
>> only way of doing this?
>
> The way google do it, isn't by sending a text message with a code you have to
> input; they just pop-up a question "is that you signing in?" on all your
> phones/tablets linked to that account, you can answer on any of them

Is that via wifi or phone?  Wifi is OK, but NOT phone.

> I presume there's a backup method in case all your devices are out of battery of
> destroyed in a freak accident ...
>
>>>> Personally, password security is perfectly acceptable to me
>>>
>>> Then none of this is the end of the world to you, just carry on using your
>>> password.
>>
>> BUT google's messages seem to say that passwords will no longer work with google
>> apps.  WTF?  Google's website offers no enlightenment.
>
> I seem to have snipped your Q about bluemail, but yes it supports oAuth2, google
> aren't going to break their own apps with this, it might break some 3rd party
> apps (whether on phone or PC) that don't support oAuth2, for those the probably
> (not checked) then individual app passwords will still work, one "less secure
> apps" is turned off.

I just discovered (and posted elsewhere) the fact that gmail IMAP 
accounts will accept oauth2 from Thunderbird 38, but POP accounts will 
not.  I have two accounts marked IMAP within Thunderbird, but I marked 
them as both POP and IMAP at the gmail website.

Perhaps if I mark my main google account IMAP instead of (or in addition 
to) POP the problem will be solved.  Or not.

It's a wrench moving from computer to phone and back again :-(


-- 
Cheers, Bev
  "Well to be perfectly honest, in my humble opinion, of course
  without offending anyone who thinks differently from my point
  of view, but also by looking into this matter in a different
  perspective and without being condemning of one's view's and
  by trying to make it objectified, and by considering each and
  every one's valid opinion, I honestly believe that I completely
  forgot what I was going to say."                    -- S. Kumar

[toc] | [prev] | [next] | [standalone]


#1417

From"Carlos E.R." <robin_listas@es.invalid>
Date2022-03-05 09:31 +0100
Message-ID<lojbfi-467.ln1@Telcontar.valinor>
In reply to#1403
On 2022-03-05 00:23, The Real Bev wrote:
> On 03/04/2022 01:26 PM, Andy Burns wrote:
>> The Real Bev wrote:
>>
>>> Andy Burns wrote:
>>>
>>>> Depends if you have 2FA enabled or not.
>>>
>>> Two-factor authentication, right?  Is the text-code-to-your-phone 
>>> method the
>>> only way of doing this?
>>
>> The way google do it, isn't by sending a text message with a code you 
>> have to
>> input; they just pop-up a question "is that you signing in?" on all your
>> phones/tablets linked to that account, you can answer on any of them
> 
> Is that via wifi or phone?  Wifi is OK, but NOT phone.

Computerese "or", which is not an exclusive "or" ;-)

-- 
Cheers, Carlos.

[toc] | [prev] | [next] | [standalone]


#1422

FromAndy Burns <usenet@andyburns.uk>
Date2022-03-05 11:20 +0000
Message-ID<j8gvbgFj370U2@mid.individual.net>
In reply to#1403
The Real Bev wrote:

> Andy Burns wrote:
>
>> The way google do it, isn't by sending a text message with a code you have to
>> input; they just pop-up a question "is that you signing in?" on all your
>> phones/tablets linked to that account, you can answer on any of them
> 
> Is that via wifi or phone?  Wifi is OK, but NOT phone.

Any connectivity you have, I suppose.  Certainly it works over my home wifi and 
over 4G

[toc] | [prev] | [next] | [standalone]


#1408

FromAndy Burnelli <spam@nospam.com>
Date2022-03-05 00:59 +0000
Message-ID<svucm0$1jkb$1@gioia.aioe.org>
In reply to#1395
Andy Burns wrote:

> I seem to have snipped your Q about bluemail, but yes it supports oAuth2, google 
> aren't going to break their own apps with this, it might break some 3rd party 
> apps (whether on phone or PC) that don't support oAuth2, for those the probably 
> (not checked) then individual app passwords will still work, one "less secure 
> apps" is turned off.

I'm mostly using K-9 Mail for Android.
 <https://i.postimg.cc/2yBvxJhJ/gmailpasswd02.jpg>
as I do not have Android set to a Google account.

For those who haven't done it, you don't need a Google account on Android
but if you ever use "certain" apps, they _force_ an account to be created!

The GMail app is one of those apps (as is Google Voice).
So I use K-9 Mail.

I remember some time ago they forced this OAuth2 stuff on us, so I changed
"something" but I don't remember what as it was a long time ago.

[Tools/AccountSettings/YourGmailAccount/ServerSettings/SecuritySettings/AuthenticationMethod]
 <https://i.postimg.cc/432zCNgx/gmailpasswd03.jpg> Current Gmail OATH2 setup

Even so, Google sent me the nastigram. 
I'm confused why.

[toc] | [prev] | [next] | [standalone]


#1413

FromAndy Burnelli <spam@nospam.com>
Date2022-03-05 01:48 +0000
Message-ID<svufha$e65$1@gioia.aioe.org>
In reply to#1408
WaltS48 wrote:

> Perhaps because K-9 Mail is a third party app. No?

I would think so, but notice that when I logged into my Gmail account just
moments ago it showed the following which doesn't even _list_ K-9 mail.
 <https://i.postimg.cc/MGs3HSyn/gmailpasswd04.jpg>
Yet K-9 mail works just fine with my google email address for some reason.
 <https://i.postimg.cc/2yBvxJhJ/gmailpasswd02.jpg>
As does Windows Thunderbird, which is already set to OAuth2 (a while ago).
 <https://i.postimg.cc/432zCNgx/gmailpasswd03.jpg>

I'm not ashamed to admit I'm thoroughly confused what Google wants me to do.
a. Is Google complaining about K-9 Mail?
b. Is Google complaining about Thunderbird?
c. Is Google complaining about something else (like my account settings)?

What?

Is it about some other MUA I don't use as frequently as K-9 and TB perhaps?
 <https://i.postimg.cc/cL9r9qFW/gmailpasswd05.jpg>

What the heck is it that Google wants me to do anyway?
 <https://i.postimg.cc/MGfN2Z7r/gmailpasswd01.jpg>
-- 
Only the Lord knows why I allowed SRWare Iron full control though.

[toc] | [prev] | [next] | [standalone]


#1393

From"Carlos E.R." <robin_listas@es.invalid>
Date2022-03-04 22:07 +0100
Message-ID<0mbafi-8li.ln1@Telcontar.valinor>
In reply to#1386
On 2022-03-04 21:40, The Real Bev wrote:
> On 03/04/2022 12:23 PM, Carlos E.R. wrote:
>> On 2022-03-04 17:57, Andy Burnelli wrote:

...

>>> Do you have any solution that allows us to keep using a password in 
>>> an MUA?
>>
>>
>> As you are setting the followup to alt.comp.software.thunderbird (which
>> I ignored, of course), it means that you are only interested in an
>> answer for Thunderbird.
>>
>> So, for Thunderbird, the solution is obvious: Use Oauth2, like it or not.
>>
>> Alternatively, use application passwords (a different password for each
>> application). This requires you to active 2FA, which I know you dislike
>> because it implies using your phone.
>>
>> Thus you can only stop using Google.
> 
> So let me get this straight...  I can keep using Thunderbird38 on my 
> computer with my gmail accounts as long as I implement Oauth2 (whatever 
> that is) and delete my stored passwords (which I just saved with an xv 
> screenshot).

No.

You need to change to a modern version of Thunderbird that does support 
Oauth2, and on the affected gmail account change security settings to

   connection security:    ssl/tls
   authentication method:  OAuth2

Alternatively, set up application passwords.


> What about uploading photos to google photos?  What about using google 
> maps?  What about my saved places in google maps?  What about those 
> things using my phone instead of my linux (or windows or laptop or other 
> people's computers) computer?  Will they send me a text message with a 
> code to load in every single time I use a google app?

As we are not in the phone forums, and this was posted to Windows and 
Linux forums instead, you are thus using a web browser to access any of 
that, so you are not affected.

(In an android phone, you are already logged in to Google, so you are 
not affected, either)


> 
> Personally, password security is perfectly acceptable to me -- if I were 
> plotting to overthrow the world perhaps I'd feel differently, but I 
> don't say a hell of a lot in email that I wouldn't be willing to post 
> publicly.  I AM unwilling to pay T-Mobile a dime every time I need to 
> deal with a text message in order to deal with any google product.

Your opinion, as mine, is irrelevant >:-P

Anyway, the rationale is that Google is working for millions of people, 
not you, and that for millions of people their email is used to 
authenticate to many services remotely (say, Amazon, you bank, etc) and 
in those cases it is better to have secure defaults. It is a fact, so 
Google claims, that since they forced more secure defaults maybe a year 
ago successful attacks have been reduced significantly - but I have lost 
the source for this information.


> 
> Is there a website that deals with the details of this travesty in detail?
> 


-- 
Cheers, Carlos.

[toc] | [prev] | [next] | [standalone]


#1397

FromThe Real Bev <bashley101@gmail.com>
Date2022-03-04 14:15 -0800
Message-ID<svu32i$ekr$1@dont-email.me>
In reply to#1393
On 03/04/2022 01:07 PM, Carlos E.R. wrote:
> On 2022-03-04 21:40, The Real Bev wrote:
>> On 03/04/2022 12:23 PM, Carlos E.R. wrote:
>>> On 2022-03-04 17:57, Andy Burnelli wrote:
>
> ...
>
>>>> Do you have any solution that allows us to keep using a password in
>>>> an MUA?
>>>
>>>
>>> As you are setting the followup to alt.comp.software.thunderbird (which
>>> I ignored, of course), it means that you are only interested in an
>>> answer for Thunderbird.
>>>
>>> So, for Thunderbird, the solution is obvious: Use Oauth2, like it or not.
>>>
>>> Alternatively, use application passwords (a different password for each
>>> application). This requires you to active 2FA, which I know you dislike
>>> because it implies using your phone.
>>>
>>> Thus you can only stop using Google.
>>
>> So let me get this straight...  I can keep using Thunderbird38 on my
>> computer with my gmail accounts as long as I implement Oauth2 (whatever
>> that is) and delete my stored passwords (which I just saved with an xv
>> screenshot).
>
> No.
>
> You need to change to a modern version of Thunderbird that does support
> Oauth2, and on the affected gmail account change security settings to
>
>     connection security:    ssl/tls
>     authentication method:  OAuth2

The authentication settings are individual for each account.  Double 
crap.  I have 14 mail accounts (not all gmail) and 6 news accounts.  The 
passwords all seem to be saved in the same file/database/whatever.  So 
for google's 'security' I have to re-enter all the non-google 
information as well as ensuring that the gmail smtp server will still 
work with the non-google mail accounts....

My profile, including my stored mail going back to 1990, is 8.7GB.  It's 
irreplaceable.  Assuming I have to give up the extensions and .css 
entries that stopped working in versions later than 38, how can I avoid 
losing all that?  (1) A simple update to whatever the latest POS is or 
(2) a completely new thunderbird installation, create a new profile, and 
copy over the contents of the old profile?  Or something else? I 
normally use method #2 with firefox, but I haven't made any changes to 
TB since 2015.

> Alternatively, set up application passwords.

Does TB38 allow that?  Seems like a better alternative.

>> What about uploading photos to google photos?  What about using google
>> maps?  What about my saved places in google maps?  What about those
>> things using my phone instead of my linux (or windows or laptop or other
>> people's computers) computer?  Will they send me a text message with a
>> code to load in every single time I use a google app?
>
> As we are not in the phone forums, and this was posted to Windows and
> Linux forums instead, you are thus using a web browser to access any of
> that, so you are not affected.
>
> (In an android phone, you are already logged in to Google, so you are
> not affected, either)

>> Personally, password security is perfectly acceptable to me -- if I were
>> plotting to overthrow the world perhaps I'd feel differently, but I
>> don't say a hell of a lot in email that I wouldn't be willing to post
>> publicly.  I AM unwilling to pay T-Mobile a dime every time I need to
>> deal with a text message in order to deal with any google product.
>
> Your opinion, as mine, is irrelevant >:-P

I've noticed that...

> Anyway, the rationale is that Google is working for millions of people,
> not you, and that for millions of people their email is used to
> authenticate to many services remotely (say, Amazon, you bank, etc) and
> in those cases it is better to have secure defaults. It is a fact, so
> Google claims, that since they forced more secure defaults maybe a year
> ago successful attacks have been reduced significantly - but I have lost
> the source for this information.

It's probably a FALSE lie, as King Mongkut would say.  I'm really tired 
of a world which is increasingly designed to protect idiots from their 
own idiocy.

>> Is there a website that deals with the details of this travesty in detail?

WTF do we need these newfangled "automobiles" for anyway?  A horse was 
good enough for my pa and it's good enough for me!

-- 
Cheers, Bev
     "...so she told me it was either her or the ham radio, over."

[toc] | [prev] | [next] | [standalone]


#1402

From"Carlos E.R." <robin_listas@es.invalid>
Date2022-03-05 00:00 +0100
Message-ID<99iafi-j93.ln1@Telcontar.valinor>
In reply to#1397
On 2022-03-04 23:15, The Real Bev wrote:
> On 03/04/2022 01:07 PM, Carlos E.R. wrote:
>> On 2022-03-04 21:40, The Real Bev wrote:
>>> On 03/04/2022 12:23 PM, Carlos E.R. wrote:
>>>> On 2022-03-04 17:57, Andy Burnelli wrote:
>>
>> ...
>>
>>>>> Do you have any solution that allows us to keep using a password in
>>>>> an MUA?
>>>>
>>>>
>>>> As you are setting the followup to alt.comp.software.thunderbird (which
>>>> I ignored, of course), it means that you are only interested in an
>>>> answer for Thunderbird.
>>>>
>>>> So, for Thunderbird, the solution is obvious: Use Oauth2, like it or 
>>>> not.
>>>>
>>>> Alternatively, use application passwords (a different password for each
>>>> application). This requires you to active 2FA, which I know you dislike
>>>> because it implies using your phone.
>>>>
>>>> Thus you can only stop using Google.
>>>
>>> So let me get this straight...  I can keep using Thunderbird38 on my
>>> computer with my gmail accounts as long as I implement Oauth2 (whatever
>>> that is) and delete my stored passwords (which I just saved with an xv
>>> screenshot).
>>
>> No.
>>
>> You need to change to a modern version of Thunderbird that does support
>> Oauth2, and on the affected gmail account change security settings to
>>
>>     connection security:    ssl/tls
>>     authentication method:  OAuth2
> 
> The authentication settings are individual for each account.  Double 
> crap.  I have 14 mail accounts (not all gmail) and 6 news accounts.  The 
> passwords all seem to be saved in the same file/database/whatever.  So 
> for google's 'security' I have to re-enter all the non-google 
> information as well as ensuring that the gmail smtp server will still 
> work with the non-google mail accounts....
> 
> My profile, including my stored mail going back to 1990, is 8.7GB.  It's 
> irreplaceable.  Assuming I have to give up the extensions and .css 
> entries that stopped working in versions later than 38, how can I avoid 
> losing all that?  (1) A simple update to whatever the latest POS is or 
> (2) a completely new thunderbird installation, create a new profile, and 
> copy over the contents of the old profile?  Or something else? I 
> normally use method #2 with firefox, but I haven't made any changes to 
> TB since 2015.


Oauth2 is interactive.

So, when you configure for oauth, Thunderbird will prompt with a 
different window to type your credentials (I think it is done with 
javascript).

You can not enter your credentials in a configuration file. Thunderbird 
must see you typing the login and password, and gmail must believe you. 
AFAIR it can do things like asking you to identify pedestrian crossings 
in a bunch of small photos. Yes, just as if you login via web.



>> Alternatively, set up application passwords.
> 
> Does TB38 allow that?  Seems like a better alternative.

It doesn't depend on the tool.

You have to login via web, enter certain menu (sorry, I forgot which, 
but I can look it up if you want), and ask google to generate the 
password for the external tool. And it is a long one.

This only works if you have 2FA enabled.


>>> What about uploading photos to google photos?  What about using google
>>> maps?  What about my saved places in google maps?  What about those
>>> things using my phone instead of my linux (or windows or laptop or other
>>> people's computers) computer?  Will they send me a text message with a
>>> code to load in every single time I use a google app?
>>
>> As we are not in the phone forums, and this was posted to Windows and
>> Linux forums instead, you are thus using a web browser to access any of
>> that, so you are not affected.
>>
>> (In an android phone, you are already logged in to Google, so you are
>> not affected, either)
> 
>>> Personally, password security is perfectly acceptable to me -- if I were
>>> plotting to overthrow the world perhaps I'd feel differently, but I
>>> don't say a hell of a lot in email that I wouldn't be willing to post
>>> publicly.  I AM unwilling to pay T-Mobile a dime every time I need to
>>> deal with a text message in order to deal with any google product.
>>
>> Your opinion, as mine, is irrelevant >:-P
> 
> I've noticed that...
> 
>> Anyway, the rationale is that Google is working for millions of people,
>> not you, and that for millions of people their email is used to
>> authenticate to many services remotely (say, Amazon, you bank, etc) and
>> in those cases it is better to have secure defaults. It is a fact, so
>> Google claims, that since they forced more secure defaults maybe a year
>> ago successful attacks have been reduced significantly - but I have lost
>> the source for this information.
> 
> It's probably a FALSE lie, as King Mongkut would say.  I'm really tired 
> of a world which is increasingly designed to protect idiots from their 
> own idiocy.
> 
>>> Is there a website that deals with the details of this travesty in 
>>> detail?
> 
> WTF do we need these newfangled "automobiles" for anyway?  A horse was 
> good enough for my pa and it's good enough for me!

:-D


-- 
Cheers, Carlos.

[toc] | [prev] | [next] | [standalone]


Page 2 of 3 — ← Prev page 1 [2] 3  Next page →

Back to top | Article view | alt.comp.microsoft.windows


csiph-web