Path: csiph.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail From: Mike Easter Newsgroups: alt.comp.software.thunderbird Subject: Re: How to recover from Google dropping password support on May 30th 2022 Date: Fri, 4 Mar 2022 10:01:13 -0800 Lines: 56 Message-ID: References: Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 8bit X-Trace: individual.net QGJr4rQAU5jFVb/f7ELIVQWdBqvsWjcz7yXdVwQZvpUaimClQI Cancel-Lock: sha1:B4FGSHz/on9fdf1CdC0r2Zkr3lc= User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Thunderbird/68.10.0 In-Reply-To: Content-Language: en-US Xref: csiph.com alt.comp.software.thunderbird:3584 Andy Burnelli wrote: > Do you have a solution that allows us to keep using a passwd in an MUA? > > Did you get this message today in all your Google email accounts? Here's it from google: https://support.google.com/accounts/answer/6010255?hl=en Less secure apps & your Google Account This is not the first time that google has decided to make that policy; in the past it has pushed the deadline back and then eliminated it. Maybe this time it is for 'real'. > It implies Google is dropping third-party mail user agent passwd support. Rather it *says* google is going to require anything that accesses to be NOT 'LSA' less secure app. The concept that google wants to enforce is that just user/pass is not sufficiently secure. Imagine that with the millions and millions of gmail accounts how many of them must have been hacked, with great resultant misery on the part of the users and such users turning to google for 'what can I do' bemoaning that the account has been hacked and misused. > > "On May 30, you may lose access to apps that are using  less secure > sign-in technology >  To help keep your account secure, Google will no longer support  the > use of third-party apps or devices which ask you to sign in  to your > Google Account using only your username and password. >  Instead, you'll need to sign in using Sign in with Google  or other > more secure technologies, like OAuth 2.0." > > I'm sure I'm like others in that I do _not_ want to use my phone to > authorize anything (not text, not 2FA, not my IP, nothing). I simply want a > login and a password and I don't want anything more than only that. > If you feel strongly and you don't want to use an app that has more secure login like 0AUTH2, then you should find an email provider that suits your wishes. > I'm not even sure if I want to use OATH2 (only if there is no other way). > > I don't use Google applications if I can help it, so I use 3rd party > MUAs on > all my platforms (K-9 Mail, Thunderbird, FairEmail, etc.). > > Do you have any solution that allows us to keep using a password in an MUA? Tb supports 0AUTH2. -- Mike Easter