Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > alt.comp.microsoft.windows > #1384 > unrolled thread
| Started by | Andy Burnelli <spam@nospam.com> |
|---|---|
| First post | 2022-03-04 16:57 +0000 |
| Last post | 2022-03-05 01:02 +0000 |
| Articles | 20 on this page of 45 — 9 participants |
Back to article view | Back to alt.comp.microsoft.windows
How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-04 16:57 +0000
Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-04 21:23 +0100
Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-04 12:40 -0800
Re: How to recover from Google dropping password support on May 30th 2022 Andy Burns <usenet@andyburns.uk> - 2022-03-04 20:49 +0000
Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-04 12:57 -0800
Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-04 22:10 +0100
Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-04 14:39 -0800
Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-04 23:51 +0100
Re: How to recover from Google dropping password support on May 30th 2022 Big Al <Bears@invalid.com> - 2022-03-04 17:58 -0500
Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-04 15:33 -0800
Re: How to recover from Google dropping password support on May 30th 2022 Jasen Betts <usenet@revmaps.no-ip.org> - 2022-03-05 01:00 +0000
Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-04 21:20 -0800
Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-05 09:22 +0100
Re: How to recover from Google dropping password support on May 30th 2022 Jasen Betts <usenet@revmaps.no-ip.org> - 2022-03-05 22:09 +0000
Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-05 09:27 +0100
Re: How to recover from Google dropping password support on May 30th 2022 "Gary R. Schmidt" <grschmidt@acm.org> - 2022-03-05 21:57 +1100
Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-05 13:11 +0100
Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 00:55 +0000
Re: How to recover from Google dropping password support on May 30th 2022 ant@zimage.comANT (Ant) - 2022-03-04 18:57 -0600
Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 01:28 +0000
Re: How to recover from Google dropping password support on May 30th 2022 Andy Burns <usenet@andyburns.uk> - 2022-03-05 11:18 +0000
Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 15:36 +0000
Re: How to recover from Google dropping password support on May 30th 2022 Andy Burns <usenet@andyburns.uk> - 2022-03-05 16:04 +0000
Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-05 18:58 +0100
Re: How to recover from Google dropping password support on May 30th 2022 Andy Burns <usenet@andyburns.uk> - 2022-03-05 18:47 +0000
Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-05 21:21 +0100
Re: How to recover from Google dropping password support on May 30th 2022 Andy Burns <usenet@andyburns.uk> - 2022-03-05 11:10 +0000
Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-06 09:11 -0800
Re: How to recover from Google dropping password support on May 30th 2022 Paul <nospam@needed.invalid> - 2022-03-06 12:46 -0500
Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-06 21:23 -0800
Re: How to recover from Google dropping password support on May 30th 2022 Andy Burns <usenet@andyburns.uk> - 2022-03-04 21:26 +0000
Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-04 23:05 +0100
Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-04 15:23 -0800
Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-05 09:31 +0100
Re: How to recover from Google dropping password support on May 30th 2022 Andy Burns <usenet@andyburns.uk> - 2022-03-05 11:20 +0000
Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 00:59 +0000
Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 01:48 +0000
Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-04 22:07 +0100
Re: How to recover from Google dropping password support on May 30th 2022 The Real Bev <bashley101@gmail.com> - 2022-03-04 14:15 -0800
Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-05 00:00 +0100
Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 01:05 +0000
Re: How to recover from Google dropping password support on May 30th 2022 "Carlos E.R." <robin_listas@es.invalid> - 2022-03-05 09:39 +0100
Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 15:24 +0000
Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 00:19 +0000
Re: How to recover from Google dropping password support on May 30th 2022 Andy Burnelli <spam@nospam.com> - 2022-03-05 01:02 +0000
Page 2 of 3 — ← Prev page 1 [2] 3 Next page →
| From | Andy Burns <usenet@andyburns.uk> |
|---|---|
| Date | 2022-03-05 11:18 +0000 |
| Message-ID | <j8gv7uFj370U1@mid.individual.net> |
| In reply to | #1412 |
Andy Burnelli wrote: > Anyway, after I set all that up, it gives me this confusing page: > <https://i.postimg.cc/MGs3HSyn/gmailpasswd04.jpg> K-9 doesn't support oAuth2, so you must be using "less secure apps" or an "app specific password" with it to gmail. Since I've not received the warning email from google, I'm not sure if they're only binning the former method or both methods.
[toc] | [prev] | [next] | [standalone]
| From | Andy Burnelli <spam@nospam.com> |
|---|---|
| Date | 2022-03-05 15:36 +0000 |
| Message-ID | <t00029$9b7$1@gioia.aioe.org> |
| In reply to | #1421 |
Andy Burns wrote: >> Anyway, after I set all that up, it gives me this confusing page: >> <https://i.postimg.cc/MGs3HSyn/gmailpasswd04.jpg> > > K-9 doesn't support oAuth2, so you must be using "less secure apps" or an "app > specific password" with it to gmail. Since I've not received the warning email > from google, I'm not sure if they're only binning the former method or both methods. Oh oh... that's bad news that K-9 doesn't support OAuth2 as that means if they don't support it by the Google deadline, we're all toast who use it. You are correct though that I currently have less secure apps set as shown: <https://i.postimg.cc/cL9r9qFW/gmailpasswd05.jpg> So the question (for Android) would be how to keep K9 working after cutoff.
[toc] | [prev] | [next] | [standalone]
| From | Andy Burns <usenet@andyburns.uk> |
|---|---|
| Date | 2022-03-05 16:04 +0000 |
| Message-ID | <j8hg17Fm6tsU1@mid.individual.net> |
| In reply to | #1425 |
Andy Burnelli wrote: > So the question (for Android) would be how to keep K9 working after cutoff. https://support.google.com/accounts/answer/185833?hl=en You're probably not going to like that it requires 2FA
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2022-03-05 18:58 +0100 |
| Message-ID | <bukcfi-qgn.ln1@Telcontar.valinor> |
| In reply to | #1426 |
On 2022-03-05 17:04, Andy Burns wrote: > Andy Burnelli wrote: > >> So the question (for Android) would be how to keep K9 working after >> cutoff. > > https://support.google.com/accounts/answer/185833?hl=en > > You're probably not going to like that it requires 2FA I concur. For me the problem is, that the only account where I got the warning mail, is not associated with any Android device, simply because it predates them, so AFAIK 2FA is not possible. My Android devices are associated with another Google account. -- Cheers, Carlos.
[toc] | [prev] | [next] | [standalone]
| From | Andy Burns <usenet@andyburns.uk> |
|---|---|
| Date | 2022-03-05 18:47 +0000 |
| Message-ID | <j8hpitFo1elU1@mid.individual.net> |
| In reply to | #1427 |
Carlos E.R. wrote: > For me the problem is, that the only account where I got the warning mail, is > not associated with any Android device, simply because it predates them, so > AFAIK 2FA is not possible. My Android devices are associated with another Google > account. Can't you add the old account, as a second google account, to one of your phones/tablets?
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2022-03-05 21:21 +0100 |
| Message-ID | <cbtcfi-t5q.ln1@Telcontar.valinor> |
| In reply to | #1428 |
On 2022-03-05 19:47, Andy Burns wrote: > Carlos E.R. wrote: > >> For me the problem is, that the only account where I got the warning >> mail, is not associated with any Android device, simply because it >> predates them, so AFAIK 2FA is not possible. My Android devices are >> associated with another Google account. > > Can't you add the old account, as a second google account, to one of > your phones/tablets? > Hum. I don't know if I want to do that :-? It would have to be on my main phone, the only device that is guaranteed to be near me in every case google wants me to authenticate. I'll have to think about it. -- Cheers, Carlos.
[toc] | [prev] | [next] | [standalone]
| From | Andy Burns <usenet@andyburns.uk> |
|---|---|
| Date | 2022-03-05 11:10 +0000 |
| Message-ID | <j8guokFj0h4U1@mid.individual.net> |
| In reply to | #1399 |
The Real Bev wrote: > oath2whatever can't be implemented for POP by Thunderbird We had this discussion a few months back, yes it can, pop is what I use with TB v91 and gmail, it may not be available with your older version?
[toc] | [prev] | [next] | [standalone]
| From | The Real Bev <bashley101@gmail.com> |
|---|---|
| Date | 2022-03-06 09:11 -0800 |
| Message-ID | <t02q0e$qu4$1@dont-email.me> |
| In reply to | #1420 |
On 03/05/2022 03:10 AM, Andy Burns wrote:
> The Real Bev wrote:
>
>> oath2whatever can't be implemented for POP by Thunderbird
>
> We had this discussion a few months back, yes it can, pop is what I use with TB
> v91 and gmail, it may not be available with your older version?
TB 38. Definitely older.
I'm wondering about downloading the latest TB version into a separate
subdirectory, letting (requiring?) it to create a new profile, and then
copying over the entire contents of my current profile over the new
profile (cp -arf * I think). This is my normal Firefox update method
and it seems to work fine. Will it work nicely with Thunderbird too?
--
Cheers, Bev
Linux: The penguin is mightier than the sword
[toc] | [prev] | [next] | [standalone]
| From | Paul <nospam@needed.invalid> |
|---|---|
| Date | 2022-03-06 12:46 -0500 |
| Message-ID | <t02s0s$br7$1@dont-email.me> |
| In reply to | #1431 |
On 3/6/2022 12:11 PM, The Real Bev wrote:
> On 03/05/2022 03:10 AM, Andy Burns wrote:
>> The Real Bev wrote:
>>
>>> oath2whatever can't be implemented for POP by Thunderbird
>>
>> We had this discussion a few months back, yes it can, pop is what I use with TB
>> v91 and gmail, it may not be available with your older version?
>
> TB 38. Definitely older.
>
> I'm wondering about downloading the latest TB version into a separate subdirectory, letting (requiring?) it to create a new profile, and then copying over the entire contents of my current profile over the new profile (cp -arf * I think). This is my normal Firefox update method and it seems to work fine. Will it work nicely with Thunderbird too?
>
Thunderbird has profile migration. It can note the
"version numbers" inside files and deal with them.
For example, if you define a filter (killfile), those
have version numbers, and the file might need to be
migrated. On minor release changes, just the version
number field might change.
Some details might not have changed, simply because
of a lack of developers who understand them. Mork
format for example, a kind of database format, only
a couple people have a good idea how it works. More common
things like .eml format, share details with other email
clients.
Any password scheme, will change between releases.
There's more reason to be tweaking that aspect.
Or maybe the storage of certificates might be messed about.
Seamonkey, a parallel development scheme, their web page
usually has warnings about how "compatible" their migration
is. I don't think Thunderbird has nearly the same level of
warnings.
No tool likes to go "backwards". It's unlikely the tool
will like a request to migrate from 91 to 38. Such as
if you move a 91 profile, to your TB38 installation.
As for the "copying" step, you can edit "profiles.ini"
and add an entry which points to where-ever the profile
is located. For example, right now I have a profile folder
which is in ~/Downloads, where I am more likely to
bump into it, back it up, and so on. On Linux, the
"file system distance", likely isn't that large between
where the profile is normally stored, and the Downloads folder.
On Windows, the path is a bit more obscure (for casual users
who haven't turned off all Hidden features). On Windows,
it might be down in AppData:Roaming (visibility problem).
This is an example of an older format for a profiles.ini . Newer
ones are more of a mess for some reason. I won't put a newer one,
because I couldn't explain what they were thinking :-)
[General]
StartWithLastProfile=1
[Profile0]
Name=default
IsRelative=0 <=== absolute path
Path=C:\Users\Username\Downloads\1234abcd.default <=== absolute path
Default=1 <=== "nominated"
Paul
[toc] | [prev] | [next] | [standalone]
| From | The Real Bev <bashley101@gmail.com> |
|---|---|
| Date | 2022-03-06 21:23 -0800 |
| Message-ID | <t044t3$8gp$1@dont-email.me> |
| In reply to | #1432 |
On 03/06/2022 09:46 AM, Paul wrote:
> On 3/6/2022 12:11 PM, The Real Bev wrote:
>> On 03/05/2022 03:10 AM, Andy Burns wrote:
>>> The Real Bev wrote:
>>>
>>>> oath2whatever can't be implemented for POP by Thunderbird
>>>
>>> We had this discussion a few months back, yes it can, pop is what I use with TB
>>> v91 and gmail, it may not be available with your older version?
>>
>> TB 38. Definitely older.
>>
>> I'm wondering about downloading the latest TB version into a separate subdirectory, letting (requiring?) it to create a new profile, and then copying over the entire contents of my current profile over the new profile (cp -arf * I think). This is my normal Firefox update method and it seems to work fine. Will it work nicely with Thunderbird too?
>>
>
> Thunderbird has profile migration. It can note the
> "version numbers" inside files and deal with them.
> For example, if you define a filter (killfile), those
> have version numbers, and the file might need to be
> migrated. On minor release changes, just the version
> number field might change.
>
> Some details might not have changed, simply because
> of a lack of developers who understand them. Mork
> format for example, a kind of database format, only
> a couple people have a good idea how it works. More common
> things like .eml format, share details with other email
> clients.
>
> Any password scheme, will change between releases.
> There's more reason to be tweaking that aspect.
> Or maybe the storage of certificates might be messed about.
>
> Seamonkey, a parallel development scheme, their web page
> usually has warnings about how "compatible" their migration
> is. I don't think Thunderbird has nearly the same level of
> warnings.
>
> No tool likes to go "backwards". It's unlikely the tool
> will like a request to migrate from 91 to 38. Such as
> if you move a 91 profile, to your TB38 installation.
>
> As for the "copying" step, you can edit "profiles.ini"
> and add an entry which points to where-ever the profile
> is located.
No, I want to leave TB38's profile untouched by anything but TB38. The
copy is to see if the latest version can cope with what I regard as
essential.
So far it's worked copying FF82's profile to the FF98(?) nightly, but
when I tried to update the nightly it broke. Just deleted the FF
nightly and haven't tried again. One of these days.
> For example, right now I have a profile folder
> which is in ~/Downloads, where I am more likely to
> bump into it, back it up, and so on. On Linux, the
> "file system distance", likely isn't that large between
> where the profile is normally stored, and the Downloads folder.
> On Windows, the path is a bit more obscure (for casual users
> who haven't turned off all Hidden features). On Windows,
> it might be down in AppData:Roaming (visibility problem).
No reason to move the profiles from where they are. I run a backup
almost every night of my entire working partition.
> This is an example of an older format for a profiles.ini . Newer
> ones are more of a mess for some reason. I won't put a newer one,
> because I couldn't explain what they were thinking :-)
>
> [General]
> StartWithLastProfile=1
>
> [Profile0]
> Name=default
> IsRelative=0 <=== absolute path
> Path=C:\Users\Username\Downloads\1234abcd.default <=== absolute path
> Default=1 <=== "nominated"
>
> Paul
>
--
Cheers, Bev
666øF -- the oven temperature for roast beast.
[toc] | [prev] | [next] | [standalone]
| From | Andy Burns <usenet@andyburns.uk> |
|---|---|
| Date | 2022-03-04 21:26 +0000 |
| Message-ID | <j8fefvFaegnU1@mid.individual.net> |
| In reply to | #1391 |
The Real Bev wrote: > Andy Burns wrote: > >> Depends if you have 2FA enabled or not. > > Two-factor authentication, right? Is the text-code-to-your-phone method the > only way of doing this? The way google do it, isn't by sending a text message with a code you have to input; they just pop-up a question "is that you signing in?" on all your phones/tablets linked to that account, you can answer on any of them I presume there's a backup method in case all your devices are out of battery of destroyed in a freak accident ... >>> Personally, password security is perfectly acceptable to me >> >> Then none of this is the end of the world to you, just carry on using your >> password. > > BUT google's messages seem to say that passwords will no longer work with google > apps. WTF? Google's website offers no enlightenment. I seem to have snipped your Q about bluemail, but yes it supports oAuth2, google aren't going to break their own apps with this, it might break some 3rd party apps (whether on phone or PC) that don't support oAuth2, for those the probably (not checked) then individual app passwords will still work, one "less secure apps" is turned off.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2022-03-04 23:05 +0100 |
| Message-ID | <c2fafi-t3l.ln1@Telcontar.valinor> |
| In reply to | #1395 |
On 2022-03-04 22:26, Andy Burns wrote: > The Real Bev wrote: >> Andy Burns wrote: >> >>> Depends if you have 2FA enabled or not. >> >> Two-factor authentication, right? Is the text-code-to-your-phone >> method the only way of doing this? > > The way google do it, isn't by sending a text message with a code you > have to input; they just pop-up a question "is that you signing in?" on > all your phones/tablets linked to that account, you can answer on any of > them > > I presume there's a backup method in case all your devices are out of > battery of destroyed in a freak accident ... The problem is on the accounts that are not associated to any phone or tablet. I have one such, from times before Android existed. And it is the only one that got that email notice. The question gets sent to the gmail account (which can not see it, as it was blocked) and to the recovery mail accounts. Then I have to use firefox to login and say "yes, that was me". Happens to me using Alpine and postfix (Linux), not Thunderbird. As there is no associated android device, it is not possible to activate 2FA, and thus I can not use application passwords, google doesn't activate the method. -- Cheers, Carlos.
[toc] | [prev] | [next] | [standalone]
| From | The Real Bev <bashley101@gmail.com> |
|---|---|
| Date | 2022-03-04 15:23 -0800 |
| Message-ID | <svu72d$eb9$1@dont-email.me> |
| In reply to | #1395 |
On 03/04/2022 01:26 PM, Andy Burns wrote: > The Real Bev wrote: > >> Andy Burns wrote: >> >>> Depends if you have 2FA enabled or not. >> >> Two-factor authentication, right? Is the text-code-to-your-phone method the >> only way of doing this? > > The way google do it, isn't by sending a text message with a code you have to > input; they just pop-up a question "is that you signing in?" on all your > phones/tablets linked to that account, you can answer on any of them Is that via wifi or phone? Wifi is OK, but NOT phone. > I presume there's a backup method in case all your devices are out of battery of > destroyed in a freak accident ... > >>>> Personally, password security is perfectly acceptable to me >>> >>> Then none of this is the end of the world to you, just carry on using your >>> password. >> >> BUT google's messages seem to say that passwords will no longer work with google >> apps. WTF? Google's website offers no enlightenment. > > I seem to have snipped your Q about bluemail, but yes it supports oAuth2, google > aren't going to break their own apps with this, it might break some 3rd party > apps (whether on phone or PC) that don't support oAuth2, for those the probably > (not checked) then individual app passwords will still work, one "less secure > apps" is turned off. I just discovered (and posted elsewhere) the fact that gmail IMAP accounts will accept oauth2 from Thunderbird 38, but POP accounts will not. I have two accounts marked IMAP within Thunderbird, but I marked them as both POP and IMAP at the gmail website. Perhaps if I mark my main google account IMAP instead of (or in addition to) POP the problem will be solved. Or not. It's a wrench moving from computer to phone and back again :-( -- Cheers, Bev "Well to be perfectly honest, in my humble opinion, of course without offending anyone who thinks differently from my point of view, but also by looking into this matter in a different perspective and without being condemning of one's view's and by trying to make it objectified, and by considering each and every one's valid opinion, I honestly believe that I completely forgot what I was going to say." -- S. Kumar
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2022-03-05 09:31 +0100 |
| Message-ID | <lojbfi-467.ln1@Telcontar.valinor> |
| In reply to | #1403 |
On 2022-03-05 00:23, The Real Bev wrote: > On 03/04/2022 01:26 PM, Andy Burns wrote: >> The Real Bev wrote: >> >>> Andy Burns wrote: >>> >>>> Depends if you have 2FA enabled or not. >>> >>> Two-factor authentication, right? Is the text-code-to-your-phone >>> method the >>> only way of doing this? >> >> The way google do it, isn't by sending a text message with a code you >> have to >> input; they just pop-up a question "is that you signing in?" on all your >> phones/tablets linked to that account, you can answer on any of them > > Is that via wifi or phone? Wifi is OK, but NOT phone. Computerese "or", which is not an exclusive "or" ;-) -- Cheers, Carlos.
[toc] | [prev] | [next] | [standalone]
| From | Andy Burns <usenet@andyburns.uk> |
|---|---|
| Date | 2022-03-05 11:20 +0000 |
| Message-ID | <j8gvbgFj370U2@mid.individual.net> |
| In reply to | #1403 |
The Real Bev wrote: > Andy Burns wrote: > >> The way google do it, isn't by sending a text message with a code you have to >> input; they just pop-up a question "is that you signing in?" on all your >> phones/tablets linked to that account, you can answer on any of them > > Is that via wifi or phone? Wifi is OK, but NOT phone. Any connectivity you have, I suppose. Certainly it works over my home wifi and over 4G
[toc] | [prev] | [next] | [standalone]
| From | Andy Burnelli <spam@nospam.com> |
|---|---|
| Date | 2022-03-05 00:59 +0000 |
| Message-ID | <svucm0$1jkb$1@gioia.aioe.org> |
| In reply to | #1395 |
Andy Burns wrote: > I seem to have snipped your Q about bluemail, but yes it supports oAuth2, google > aren't going to break their own apps with this, it might break some 3rd party > apps (whether on phone or PC) that don't support oAuth2, for those the probably > (not checked) then individual app passwords will still work, one "less secure > apps" is turned off. I'm mostly using K-9 Mail for Android. <https://i.postimg.cc/2yBvxJhJ/gmailpasswd02.jpg> as I do not have Android set to a Google account. For those who haven't done it, you don't need a Google account on Android but if you ever use "certain" apps, they _force_ an account to be created! The GMail app is one of those apps (as is Google Voice). So I use K-9 Mail. I remember some time ago they forced this OAuth2 stuff on us, so I changed "something" but I don't remember what as it was a long time ago. [Tools/AccountSettings/YourGmailAccount/ServerSettings/SecuritySettings/AuthenticationMethod] <https://i.postimg.cc/432zCNgx/gmailpasswd03.jpg> Current Gmail OATH2 setup Even so, Google sent me the nastigram. I'm confused why.
[toc] | [prev] | [next] | [standalone]
| From | Andy Burnelli <spam@nospam.com> |
|---|---|
| Date | 2022-03-05 01:48 +0000 |
| Message-ID | <svufha$e65$1@gioia.aioe.org> |
| In reply to | #1408 |
WaltS48 wrote: > Perhaps because K-9 Mail is a third party app. No? I would think so, but notice that when I logged into my Gmail account just moments ago it showed the following which doesn't even _list_ K-9 mail. <https://i.postimg.cc/MGs3HSyn/gmailpasswd04.jpg> Yet K-9 mail works just fine with my google email address for some reason. <https://i.postimg.cc/2yBvxJhJ/gmailpasswd02.jpg> As does Windows Thunderbird, which is already set to OAuth2 (a while ago). <https://i.postimg.cc/432zCNgx/gmailpasswd03.jpg> I'm not ashamed to admit I'm thoroughly confused what Google wants me to do. a. Is Google complaining about K-9 Mail? b. Is Google complaining about Thunderbird? c. Is Google complaining about something else (like my account settings)? What? Is it about some other MUA I don't use as frequently as K-9 and TB perhaps? <https://i.postimg.cc/cL9r9qFW/gmailpasswd05.jpg> What the heck is it that Google wants me to do anyway? <https://i.postimg.cc/MGfN2Z7r/gmailpasswd01.jpg> -- Only the Lord knows why I allowed SRWare Iron full control though.
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2022-03-04 22:07 +0100 |
| Message-ID | <0mbafi-8li.ln1@Telcontar.valinor> |
| In reply to | #1386 |
On 2022-03-04 21:40, The Real Bev wrote: > On 03/04/2022 12:23 PM, Carlos E.R. wrote: >> On 2022-03-04 17:57, Andy Burnelli wrote: ... >>> Do you have any solution that allows us to keep using a password in >>> an MUA? >> >> >> As you are setting the followup to alt.comp.software.thunderbird (which >> I ignored, of course), it means that you are only interested in an >> answer for Thunderbird. >> >> So, for Thunderbird, the solution is obvious: Use Oauth2, like it or not. >> >> Alternatively, use application passwords (a different password for each >> application). This requires you to active 2FA, which I know you dislike >> because it implies using your phone. >> >> Thus you can only stop using Google. > > So let me get this straight... I can keep using Thunderbird38 on my > computer with my gmail accounts as long as I implement Oauth2 (whatever > that is) and delete my stored passwords (which I just saved with an xv > screenshot). No. You need to change to a modern version of Thunderbird that does support Oauth2, and on the affected gmail account change security settings to connection security: ssl/tls authentication method: OAuth2 Alternatively, set up application passwords. > What about uploading photos to google photos? What about using google > maps? What about my saved places in google maps? What about those > things using my phone instead of my linux (or windows or laptop or other > people's computers) computer? Will they send me a text message with a > code to load in every single time I use a google app? As we are not in the phone forums, and this was posted to Windows and Linux forums instead, you are thus using a web browser to access any of that, so you are not affected. (In an android phone, you are already logged in to Google, so you are not affected, either) > > Personally, password security is perfectly acceptable to me -- if I were > plotting to overthrow the world perhaps I'd feel differently, but I > don't say a hell of a lot in email that I wouldn't be willing to post > publicly. I AM unwilling to pay T-Mobile a dime every time I need to > deal with a text message in order to deal with any google product. Your opinion, as mine, is irrelevant >:-P Anyway, the rationale is that Google is working for millions of people, not you, and that for millions of people their email is used to authenticate to many services remotely (say, Amazon, you bank, etc) and in those cases it is better to have secure defaults. It is a fact, so Google claims, that since they forced more secure defaults maybe a year ago successful attacks have been reduced significantly - but I have lost the source for this information. > > Is there a website that deals with the details of this travesty in detail? > -- Cheers, Carlos.
[toc] | [prev] | [next] | [standalone]
| From | The Real Bev <bashley101@gmail.com> |
|---|---|
| Date | 2022-03-04 14:15 -0800 |
| Message-ID | <svu32i$ekr$1@dont-email.me> |
| In reply to | #1393 |
On 03/04/2022 01:07 PM, Carlos E.R. wrote:
> On 2022-03-04 21:40, The Real Bev wrote:
>> On 03/04/2022 12:23 PM, Carlos E.R. wrote:
>>> On 2022-03-04 17:57, Andy Burnelli wrote:
>
> ...
>
>>>> Do you have any solution that allows us to keep using a password in
>>>> an MUA?
>>>
>>>
>>> As you are setting the followup to alt.comp.software.thunderbird (which
>>> I ignored, of course), it means that you are only interested in an
>>> answer for Thunderbird.
>>>
>>> So, for Thunderbird, the solution is obvious: Use Oauth2, like it or not.
>>>
>>> Alternatively, use application passwords (a different password for each
>>> application). This requires you to active 2FA, which I know you dislike
>>> because it implies using your phone.
>>>
>>> Thus you can only stop using Google.
>>
>> So let me get this straight... I can keep using Thunderbird38 on my
>> computer with my gmail accounts as long as I implement Oauth2 (whatever
>> that is) and delete my stored passwords (which I just saved with an xv
>> screenshot).
>
> No.
>
> You need to change to a modern version of Thunderbird that does support
> Oauth2, and on the affected gmail account change security settings to
>
> connection security: ssl/tls
> authentication method: OAuth2
The authentication settings are individual for each account. Double
crap. I have 14 mail accounts (not all gmail) and 6 news accounts. The
passwords all seem to be saved in the same file/database/whatever. So
for google's 'security' I have to re-enter all the non-google
information as well as ensuring that the gmail smtp server will still
work with the non-google mail accounts....
My profile, including my stored mail going back to 1990, is 8.7GB. It's
irreplaceable. Assuming I have to give up the extensions and .css
entries that stopped working in versions later than 38, how can I avoid
losing all that? (1) A simple update to whatever the latest POS is or
(2) a completely new thunderbird installation, create a new profile, and
copy over the contents of the old profile? Or something else? I
normally use method #2 with firefox, but I haven't made any changes to
TB since 2015.
> Alternatively, set up application passwords.
Does TB38 allow that? Seems like a better alternative.
>> What about uploading photos to google photos? What about using google
>> maps? What about my saved places in google maps? What about those
>> things using my phone instead of my linux (or windows or laptop or other
>> people's computers) computer? Will they send me a text message with a
>> code to load in every single time I use a google app?
>
> As we are not in the phone forums, and this was posted to Windows and
> Linux forums instead, you are thus using a web browser to access any of
> that, so you are not affected.
>
> (In an android phone, you are already logged in to Google, so you are
> not affected, either)
>> Personally, password security is perfectly acceptable to me -- if I were
>> plotting to overthrow the world perhaps I'd feel differently, but I
>> don't say a hell of a lot in email that I wouldn't be willing to post
>> publicly. I AM unwilling to pay T-Mobile a dime every time I need to
>> deal with a text message in order to deal with any google product.
>
> Your opinion, as mine, is irrelevant >:-P
I've noticed that...
> Anyway, the rationale is that Google is working for millions of people,
> not you, and that for millions of people their email is used to
> authenticate to many services remotely (say, Amazon, you bank, etc) and
> in those cases it is better to have secure defaults. It is a fact, so
> Google claims, that since they forced more secure defaults maybe a year
> ago successful attacks have been reduced significantly - but I have lost
> the source for this information.
It's probably a FALSE lie, as King Mongkut would say. I'm really tired
of a world which is increasingly designed to protect idiots from their
own idiocy.
>> Is there a website that deals with the details of this travesty in detail?
WTF do we need these newfangled "automobiles" for anyway? A horse was
good enough for my pa and it's good enough for me!
--
Cheers, Bev
"...so she told me it was either her or the ham radio, over."
[toc] | [prev] | [next] | [standalone]
| From | "Carlos E.R." <robin_listas@es.invalid> |
|---|---|
| Date | 2022-03-05 00:00 +0100 |
| Message-ID | <99iafi-j93.ln1@Telcontar.valinor> |
| In reply to | #1397 |
On 2022-03-04 23:15, The Real Bev wrote: > On 03/04/2022 01:07 PM, Carlos E.R. wrote: >> On 2022-03-04 21:40, The Real Bev wrote: >>> On 03/04/2022 12:23 PM, Carlos E.R. wrote: >>>> On 2022-03-04 17:57, Andy Burnelli wrote: >> >> ... >> >>>>> Do you have any solution that allows us to keep using a password in >>>>> an MUA? >>>> >>>> >>>> As you are setting the followup to alt.comp.software.thunderbird (which >>>> I ignored, of course), it means that you are only interested in an >>>> answer for Thunderbird. >>>> >>>> So, for Thunderbird, the solution is obvious: Use Oauth2, like it or >>>> not. >>>> >>>> Alternatively, use application passwords (a different password for each >>>> application). This requires you to active 2FA, which I know you dislike >>>> because it implies using your phone. >>>> >>>> Thus you can only stop using Google. >>> >>> So let me get this straight... I can keep using Thunderbird38 on my >>> computer with my gmail accounts as long as I implement Oauth2 (whatever >>> that is) and delete my stored passwords (which I just saved with an xv >>> screenshot). >> >> No. >> >> You need to change to a modern version of Thunderbird that does support >> Oauth2, and on the affected gmail account change security settings to >> >> connection security: ssl/tls >> authentication method: OAuth2 > > The authentication settings are individual for each account. Double > crap. I have 14 mail accounts (not all gmail) and 6 news accounts. The > passwords all seem to be saved in the same file/database/whatever. So > for google's 'security' I have to re-enter all the non-google > information as well as ensuring that the gmail smtp server will still > work with the non-google mail accounts.... > > My profile, including my stored mail going back to 1990, is 8.7GB. It's > irreplaceable. Assuming I have to give up the extensions and .css > entries that stopped working in versions later than 38, how can I avoid > losing all that? (1) A simple update to whatever the latest POS is or > (2) a completely new thunderbird installation, create a new profile, and > copy over the contents of the old profile? Or something else? I > normally use method #2 with firefox, but I haven't made any changes to > TB since 2015. Oauth2 is interactive. So, when you configure for oauth, Thunderbird will prompt with a different window to type your credentials (I think it is done with javascript). You can not enter your credentials in a configuration file. Thunderbird must see you typing the login and password, and gmail must believe you. AFAIR it can do things like asking you to identify pedestrian crossings in a bunch of small photos. Yes, just as if you login via web. >> Alternatively, set up application passwords. > > Does TB38 allow that? Seems like a better alternative. It doesn't depend on the tool. You have to login via web, enter certain menu (sorry, I forgot which, but I can look it up if you want), and ask google to generate the password for the external tool. And it is a long one. This only works if you have 2FA enabled. >>> What about uploading photos to google photos? What about using google >>> maps? What about my saved places in google maps? What about those >>> things using my phone instead of my linux (or windows or laptop or other >>> people's computers) computer? Will they send me a text message with a >>> code to load in every single time I use a google app? >> >> As we are not in the phone forums, and this was posted to Windows and >> Linux forums instead, you are thus using a web browser to access any of >> that, so you are not affected. >> >> (In an android phone, you are already logged in to Google, so you are >> not affected, either) > >>> Personally, password security is perfectly acceptable to me -- if I were >>> plotting to overthrow the world perhaps I'd feel differently, but I >>> don't say a hell of a lot in email that I wouldn't be willing to post >>> publicly. I AM unwilling to pay T-Mobile a dime every time I need to >>> deal with a text message in order to deal with any google product. >> >> Your opinion, as mine, is irrelevant >:-P > > I've noticed that... > >> Anyway, the rationale is that Google is working for millions of people, >> not you, and that for millions of people their email is used to >> authenticate to many services remotely (say, Amazon, you bank, etc) and >> in those cases it is better to have secure defaults. It is a fact, so >> Google claims, that since they forced more secure defaults maybe a year >> ago successful attacks have been reduced significantly - but I have lost >> the source for this information. > > It's probably a FALSE lie, as King Mongkut would say. I'm really tired > of a world which is increasingly designed to protect idiots from their > own idiocy. > >>> Is there a website that deals with the details of this travesty in >>> detail? > > WTF do we need these newfangled "automobiles" for anyway? A horse was > good enough for my pa and it's good enough for me! :-D -- Cheers, Carlos.
[toc] | [prev] | [next] | [standalone]
Page 2 of 3 — ← Prev page 1 [2] 3 Next page →
Back to top | Article view | alt.comp.microsoft.windows
csiph-web