Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #248090 > unrolled thread

google account say it will no longer deliver email

Started byFero Dali <ferodali@gmail.com>
First post2022-05-11 15:30 +0200
Last post2022-06-04 23:10 +0200
Articles 20 on this page of 105 — 30 participants

Back to article view | Back to linux.debian.user


Contents

  google account say it will no longer deliver email Fero Dali <ferodali@gmail.com> - 2022-05-11 15:30 +0200
    Re: google account say it will no longer deliver email Eike Lantzsch ZP6CGE <zp6cge@gmx.net> - 2022-05-11 15:40 +0200
    Re: google account say it will no longer deliver email mick crane <mick.crane@gmail.com> - 2022-05-11 16:40 +0200
    Re: google account say it will no longer deliver email Brian <ad44@cityscape.co.uk> - 2022-05-11 20:00 +0200
      Re: google account say it will no longer deliver email Brian <ad44@cityscape.co.uk> - 2022-05-11 20:10 +0200
      Re: google account say it will no longer deliver email Fero Dali <ferodali@gmail.com> - 2022-05-11 20:10 +0200
        Re: google account say it will no longer deliver email Brian <ad44@cityscape.co.uk> - 2022-05-11 20:20 +0200
          Re: google account say it will no longer deliver email Fero Dali <ferodali@gmail.com> - 2022-05-11 20:50 +0200
        Re: google account say it will no longer deliver email Virgo Pärna <virgo.parna@mail.ee> - 2022-05-12 12:10 +0200
          Re: google account say it will no longer deliver email Curt <curty@free.fr> - 2022-05-12 15:30 +0200
          Re: google account say it will no longer deliver email Fero Dali <ferodali@gmail.com> - 2022-05-12 15:30 +0200
            Re: google account say it will no longer deliver email Greg Wooledge <greg@wooledge.org> - 2022-05-12 15:40 +0200
            Re: google account say it will no longer deliver email Virgo Pärna <virgo.parna@mail.ee> - 2022-05-12 20:10 +0200
              Re: google account say it will no longer deliver email Fero Dali <ferodali@gmail.com> - 2022-05-12 21:00 +0200
                Re: google account say it will no longer deliver email Virgo Pärna <virgo.parna@mail.ee> - 2022-05-13 08:00 +0200
            Re: google account say it will no longer deliver email Ash Joubert <ash@transient.nz> - 2022-05-13 01:10 +0200
              Re: google account say it will no longer deliver email "tv.debian" <tv.debian@googlemail.com> - 2022-05-13 01:40 +0200
              Re: google account say it will no longer deliver email Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-05-13 02:30 +0200
                Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-05-13 07:20 +0200
                  Re: google account say it will no longer deliver email Curt <curty@free.fr> - 2022-05-13 11:40 +0200
                    Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-05-13 13:40 +0200
                      Re: google account say it will no longer deliver email Curt <curty@free.fr> - 2022-05-13 13:50 +0200
                        Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-05-13 14:10 +0200
                          Re: google account say it will no longer deliver email David Wright <deblis@lionunicorn.co.uk> - 2022-05-13 17:20 +0200
                  Re: google account say it will no longer deliver email Michael Stone <mstone@debian.org> - 2022-05-13 14:50 +0200
                    Re: google account say it will no longer deliver email Brian <ad44@cityscape.co.uk> - 2022-05-13 19:30 +0200
                    Re: google account say it will no longer deliver email Ash Joubert <ash@transient.nz> - 2022-05-14 05:10 +0200
                      Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-05-14 07:30 +0200
                        Re: google account say it will no longer deliver email Celejar <celejar@gmail.com> - 2022-05-16 15:20 +0200
                      Re: google account say it will no longer deliver email Celejar <celejar@gmail.com> - 2022-05-16 15:20 +0200
                Re: google account say it will no longer deliver email Ash Joubert <ash@transient.nz> - 2022-05-14 04:50 +0200
                  Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-05-14 07:30 +0200
                    Re: google account say it will no longer deliver email Brian <ad44@cityscape.co.uk> - 2022-05-14 13:50 +0200
                      Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-05-14 15:30 +0200
                        Re: google account say it will no longer deliver email Brian <ad44@cityscape.co.uk> - 2022-05-14 18:40 +0200
                        Re: google account say it will no longer deliver email Brian <ad44@cityscape.co.uk> - 2022-05-14 20:50 +0200
                          Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-05-14 21:00 +0200
                            Re: google account say it will no longer deliver email Brian <ad44@cityscape.co.uk> - 2022-05-14 21:30 +0200
                              Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-05-15 06:40 +0200
                                Re: google account say it will no longer deliver email gene heskett <gheskett@shentel.net> - 2022-05-15 14:00 +0200
                                  Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-05-15 15:50 +0200
                          Re: google account say it will no longer deliver email gene heskett <gheskett@shentel.net> - 2022-05-14 22:20 +0200
                  Re: google account say it will no longer deliver email Curt <curty@free.fr> - 2022-05-14 11:00 +0200
                    Re: google account say it will no longer deliver email tomas@tuxteam.de - 2022-05-14 11:30 +0200
                    Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-05-14 11:30 +0200
                      Re: google account say it will no longer deliver email Curt <curty@free.fr> - 2022-05-14 14:10 +0200
                        Re: google account say it will no longer deliver email Brian <ad44@cityscape.co.uk> - 2022-05-14 15:10 +0200
                          Re: google account say it will no longer deliver email David Wright <deblis@lionunicorn.co.uk> - 2022-05-16 05:40 +0200
                            Re: google account say it will no longer deliver email Curt <curty@free.fr> - 2022-05-16 10:10 +0200
                              Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-05-16 12:00 +0200
                                Re: google account say it will no longer deliver email Curt <curty@free.fr> - 2022-05-16 14:40 +0200
                            Re: google account say it will no longer deliver email Stella Ashburne <rewefie@gmx.com> - 2022-05-16 13:10 +0200
                            Re: google account say it will no longer deliver email Brian <ad44@cityscape.co.uk> - 2022-05-16 15:40 +0200
                              Re: google account say it will no longer deliver email David Wright <deblis@lionunicorn.co.uk> - 2022-05-16 18:00 +0200
                    Re: google account say it will no longer deliver email Brian <ad44@cityscape.co.uk> - 2022-05-14 14:10 +0200
          Re: google account say it will no longer deliver email Brian <ad44@cityscape.co.uk> - 2022-06-01 19:10 +0200
            Re: google account say it will no longer deliver email Patrick Bartek <nemommxiv@gmail.com> - 2022-06-01 19:50 +0200
              Re: google account say it will no longer deliver email Brian <ad44@cityscape.co.uk> - 2022-06-01 20:40 +0200
            Re: google account say it will no longer deliver email nemo <moelmoel2714@gmail.com> - 2022-06-02 17:20 +0200
              Re: google account say it will no longer deliver email rhkramer@gmail.com - 2022-06-02 20:10 +0200
                Re: google account say it will no longer deliver email <paulf@quillandmouse.com> - 2022-06-02 20:30 +0200
                  Re: google account say it will no longer deliver email Felmon Davis <moelmoel2714@gmail.com> - 2022-06-02 20:40 +0200
                    Re: google account say it will no longer deliver email Curt <curty@free.fr> - 2022-06-04 14:00 +0200
                      Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-06-04 14:20 +0200
                        Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-06-04 16:30 +0200
                          Re: google account say it will no longer deliver email Felmon Davis <moelmoel2714@gmail.com> - 2022-06-04 16:50 +0200
                            Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-06-04 19:50 +0200
                        Re: google account say it will no longer deliver email Curt <curty@free.fr> - 2022-06-04 16:30 +0200
                      Re: google account say it will no longer deliver email Felmon Davis <moelmoel2714@gmail.com> - 2022-06-04 15:50 +0200
                        Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-06-04 16:00 +0200
                          Re: google account say it will no longer deliver email Felmon Davis <moelmoel2714@gmail.com> - 2022-06-04 19:30 +0200
                            Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-06-04 19:50 +0200
                              Re: google account say it will no longer deliver email Felmon Davis <moelmoel2714@gmail.com> - 2022-06-08 03:40 +0200
                                Re: google account say it will no longer deliver email <tomas@tuxteam.de> - 2022-06-08 06:50 +0200
                                Re: google account say it will no longer deliver email rhkramer@gmail.com - 2022-06-08 14:50 +0200
                                  Re: google account say it will no longer deliver email Felmon Davis <moelmoel2714@gmail.com> - 2022-06-08 18:00 +0200
                                    Re: google account say it will no longer deliver email Curt <curty@free.fr> - 2022-06-08 18:20 +0200
                                      Re: google account say it will no longer deliver email rhkramer@gmail.com - 2022-06-08 18:30 +0200
                                        Re: google account say it will no longer deliver email Curt <curty@free.fr> - 2022-06-08 19:20 +0200
                      Re: google account say it will no longer deliver email Curt <curty@free.fr> - 2022-06-04 16:30 +0200
                Re: google account say it will no longer deliver email rhkramer@gmail.com - 2022-06-03 21:00 +0200
    Re: google account say it will no longer deliver email Brian <ad44@cityscape.co.uk> - 2022-05-11 20:30 +0200
      Re: google account say it will no longer deliver email Fero Dali <ferodali@gmail.com> - 2022-05-11 21:00 +0200
        Re: google account say it will no longer deliver email Siard <shiems@mailbox.org> - 2022-05-11 22:00 +0200
          Re: google account say it will no longer deliver email John Hasler <john@sugarbit.com> - 2022-05-12 04:00 +0200
        Re: google account say it will no longer deliver email Brian <ad44@cityscape.co.uk> - 2022-05-11 22:20 +0200
          Re: google account say it will no longer deliver email Fero Dali <ferodali@gmail.com> - 2022-05-11 22:30 +0200
    Re: google account say it will no longer deliver email "sp007@caiway.net" <sp007@caiway.net> - 2022-06-04 21:00 +0200
      Re: google account say it will no longer deliver email Richard Owlett <rowlett@cloud85.net> - 2022-06-04 21:10 +0200
      Re: google account say it will no longer deliver email John Hasler <john@sugarbit.com> - 2022-06-04 21:10 +0200
        Re: google account say it will no longer deliver email "sp007@caiway.net" <sp007@caiway.net> - 2022-06-04 22:10 +0200
          Re: google account say it will no longer deliver email John Hasler <john@sugarbit.com> - 2022-06-04 22:40 +0200
            Re: google account say it will no longer deliver email "sp007@caiway.net" <sp007@caiway.net> - 2022-06-04 22:50 +0200
              Re: google account say it will no longer deliver email Edwin Zimmerman <edwin@plainemail.net> - 2022-06-04 23:10 +0200
                Re: google account say it will no longer deliver email "sp007@caiway.net" <sp007@caiway.net> - 2022-06-04 23:40 +0200
          Re: google account say it will no longer deliver email wec <wec@upwardmail.net> - 2022-06-04 23:10 +0200
            Re: google account say it will no longer deliver email "sp007@caiway.net" <sp007@caiway.net> - 2022-06-04 23:20 +0200
              Re: google account say it will no longer deliver email Larry Martell <larry.martell@gmail.com> - 2022-06-05 02:50 +0200
                Re: google account say it will no longer deliver email "sp007@caiway.net" <sp007@caiway.net> - 2022-06-05 02:50 +0200
                  Re: google account say it will no longer deliver email Larry Martell <larry.martell@gmail.com> - 2022-06-05 03:00 +0200
                    Re: google account say it will no longer deliver email John Hasler <john@sugarbit.com> - 2022-06-05 03:10 +0200
                      Re: google account say it will no longer deliver email "sp007@caiway.net" <sp007@caiway.net> - 2022-06-05 06:10 +0200
                    Re: google account say it will no longer deliver email "sp007@caiway.net" <sp007@caiway.net> - 2022-06-05 03:20 +0200
                Re: google account say it will no longer deliver email gene heskett <gheskett@shentel.net> - 2022-06-05 03:50 +0200
          Re: google account say it will no longer deliver email Alain D D Williams <addw@phcomp.co.uk> - 2022-06-04 23:10 +0200

Page 3 of 6 — ← Prev page 1 2 [3] 4 5 6  Next page →


#248227

From<tomas@tuxteam.de>
Date2022-05-15 15:50 +0200
Message-ID<EnmNb-fDWB-1@gated-at.bofh.it>
In reply to#248226

[Multipart message — attachments visible in raw view] — view raw

On Sun, May 15, 2022 at 07:58:25AM -0400, gene heskett wrote:

[...]

> So are we tolerating the vegetables, Tomas, but not too well.
> Politicians and diapers need frequent changing, usually for the same 
> reason.

I was rather thinking in terms "we vegetables are well tolerated" ;-)

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#248218

Fromgene heskett <gheskett@shentel.net>
Date2022-05-14 22:20 +0200
Message-ID<En6p3-fumH-7@gated-at.bofh.it>
In reply to#248214
On Saturday, 14 May 2022 14:43:08 EDT Brian wrote:
> On Sat 14 May 2022 at 15:21:06 +0200, tomas@tuxteam.de wrote:
> > On Sat, May 14, 2022 at 12:42:28PM +0100, Brian wrote:
> [...]
> 
> > > Let me introduce you to my bank: they reduced the maximum 20 chars
> > > to 16 and did not allow some special chars such as "!" and ".".
> > > Mind you, I feel much more secure - 3FA is used :).
> > 
> > Three? Why not go all the way to 5FA [1]?
> > 
> > Cheers
> > 
> > [1] https://boingboing.net/2005/09/14/gillettes-5blade-raz.html
> > 
> >     (not linking to the original Onion because their Javascript
> >     doesn't want to play with me)
> 
> I have just realised that PayPal does 5FA. It meets the Gillete
> standard. Or should that be the MAD standard? Our capacity to
> put up with sysadmin (management?) nonsense is unlimited.
> 
> --
> Brian.
> 
No, it is not unlimited, Brian.  Business sites in particular often have 
a 20+ char pw for me, and if, after I set a 20+ char pw, I have to trim 
the end of it to make it work again, they get a nastygram. My bank, about 
2 years ago did some minor revamping and wound at an 8 char limit. They 
not only thanked me for the nastygram, and advised me that it had been 
raised to 32.  I am a big enough depositor they don't want to upset me.

The nagging thing about using FF is that it drops to a secret question 
and a 6 digit OTP response I've 5 minutes to respond to. And I can't set 
kmail to refresh the local imap image any faster than 5 minutes...

Take care, and stay well, Brian.

Cheers, Gene Heskett.
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author, 1940)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis

[toc] | [prev] | [next] | [standalone]


#248194

FromCurt <curty@free.fr>
Date2022-05-14 11:00 +0200
Message-ID<EmVMZ-fo2x-3@gated-at.bofh.it>
In reply to#248184
On 2022-05-14, Ash Joubert <ash@transient.nz> wrote:
> On 13/05/2022 12:23, Nicholas Geovanis wrote:
>> That's the value added in exchange for Ash's "massive pain in the arse".
>> Just making the 1st factor be
>> a loong password is not equivalent to 2FA in any way. Machine reaching back
>> to you is the difference.
>
> There are attacks that 2FA can defeat, especially things like password 
> reset via compromised email server, but in general, two weak factors are 
> not a match for a strong unique random password. In particular, it is 
> not uncommon for sms/email/totp second factor to resolve to exactly the 
> same device as the first factor, reducing 2FA to a single factor. 
> Compromise such a user's phone and it is all over.

What about data breaches, and sites keeping your password
in plain text (though it seems access to the cryptographically hashed
passcodes is already a pretty good leg up)? What good is our entropy then?

https://en.wikipedia.org/wiki/List_of_data_breaches

https://arstechnica.com/information-technology/2013/05/how-crackers-make-minced-meat-out-of-your-passwords/

[toc] | [prev] | [next] | [standalone]


#248195

Fromtomas@tuxteam.de
Date2022-05-14 11:30 +0200
Message-ID<EmWg1-for6-1@gated-at.bofh.it>
In reply to#248194

[Multipart message — attachments visible in raw view] — view raw

On Sat, May 14, 2022 at 11:21:39AM +0200, tomas@tuxteam.de wrote:
> On Sat, May 14, 2022 at 08:58:37AM -0000, Curt wrote:
> 
> [...]
> 
> > What about data breaches [...]

> As stated elsewhere: unique passwords [...]

Or, if I may put it in another terms: Recycle your trash. Never
recycle your passwords.

Cheers
-- 
t 

[toc] | [prev] | [next] | [standalone]


#248196

From<tomas@tuxteam.de>
Date2022-05-14 11:30 +0200
Message-ID<EmWg1-for6-3@gated-at.bofh.it>
In reply to#248194

[Multipart message — attachments visible in raw view] — view raw

On Sat, May 14, 2022 at 08:58:37AM -0000, Curt wrote:

[...]

> What about data breaches, and sites keeping your password
> in plain text (though it seems access to the cryptographically hashed
> passcodes is already a pretty good leg up)? What good is our entropy then?

As stated elsewhere: unique passwords. Don't use a password you're using
elsewhere. Much less so with a site you don't trust.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#248202

FromCurt <curty@free.fr>
Date2022-05-14 14:10 +0200
Message-ID<EmYKR-fpYW-5@gated-at.bofh.it>
In reply to#248196
On 2022-05-14, <tomas@tuxteam.de> <tomas@tuxteam.de> wrote:
>
> On Sat, May 14, 2022 at 08:58:37AM -0000, Curt wrote:
>
> [...]
>
>> What about data breaches, and sites keeping your password
>> in plain text (though it seems access to the cryptographically hashed
>> passcodes is already a pretty good leg up)? What good is our entropy then?
>
> As stated elsewhere: unique passwords. Don't use a password you're using
> elsewhere. Much less so with a site you don't trust.

As always, I'm very uncertain where your goal posts are placed or what
tacit agenda you're following. No one has advocated the use of unique
passwords. 

In my plausible scenario, you're password entropy counts for nothing.
Your password, unique or otherwise, has been compromised. 2FA would
prevent illegal entry to your account in this case. The subject we're
addressing here is your assertion that 2FA adds no extra security. I
have demonstrated that it does. 

> Cheers

[toc] | [prev] | [next] | [standalone]


#248203

FromBrian <ad44@cityscape.co.uk>
Date2022-05-14 15:10 +0200
Message-ID<EmZGV-fqws-3@gated-at.bofh.it>
In reply to#248202
On Sat 14 May 2022 at 12:02:49 -0000, Curt wrote:

> On 2022-05-14, <tomas@tuxteam.de> <tomas@tuxteam.de> wrote:
> >
> > On Sat, May 14, 2022 at 08:58:37AM -0000, Curt wrote:
> >
> > [...]
> >
> >> What about data breaches, and sites keeping your password
> >> in plain text (though it seems access to the cryptographically hashed
> >> passcodes is already a pretty good leg up)? What good is our entropy then?
> >
> > As stated elsewhere: unique passwords. Don't use a password you're using
> > elsewhere. Much less so with a site you don't trust.
> 
> As always, I'm very uncertain where your goal posts are placed or what
> tacit agenda you're following. No one has advocated the use of unique
> passwords. 
> 
> In my plausible scenario, you're password entropy counts for nothing.
> Your password, unique or otherwise, has been compromised. 2FA would
> prevent illegal entry to your account in this case. The subject we're
> addressing here is your assertion that 2FA adds no extra security. I
> have demonstrated that it does.

Preventing data breaches are outside the scope of the user, providing
a high entropy password is not. If accessing a  site is of importance
to him, then, in your plausible scenario, an eight character password
effectively gives little security.

That is not an argument for 2FA but for a user having a responsible
password policy to guard agains such breaches.

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#248259

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2022-05-16 05:40 +0200
Message-ID<EnzKp-fLDP-9@gated-at.bofh.it>
In reply to#248203
On Sat 14 May 2022 at 14:02:36 (+0100), Brian wrote:
> On Sat 14 May 2022 at 12:02:49 -0000, Curt wrote:
> > On 2022-05-14, <tomas@tuxteam.de> wrote:
> > > On Sat, May 14, 2022 at 08:58:37AM -0000, Curt wrote:
> > >
> > > [...]
> > >
> > >> What about data breaches, and sites keeping your password
> > >> in plain text (though it seems access to the cryptographically hashed
> > >> passcodes is already a pretty good leg up)? What good is our entropy then?
> > >
> > > As stated elsewhere: unique passwords. Don't use a password you're using
> > > elsewhere. Much less so with a site you don't trust.
> > 
> > As always, I'm very uncertain where your goal posts are placed or what
> > tacit agenda you're following. No one has advocated the use of unique
> > passwords. 
> > 
> > In my plausible scenario, you're password entropy counts for nothing.
> > Your password, unique or otherwise, has been compromised. 2FA would
> > prevent illegal entry to your account in this case. The subject we're
> > addressing here is your assertion that 2FA adds no extra security. I
> > have demonstrated that it does.
> 
> Preventing data breaches are outside the scope of the user, providing
> a high entropy password is not. If accessing a  site is of importance
> to him, then, in your plausible scenario, an eight character password
> effectively gives little security.
> 
> That is not an argument for 2FA but for a user having a responsible
> password policy to guard agains such breaches.

Preventing data breaches might be outside my control, but mitigating
their effect might not be. So I like to have 2FA set up as entering
a code in response to a phone call. There's some peace of mind in my
/not/ receiving any of those calls unless /I/ try to login.

Were it to ring unexpectedly and I heard a woman with a crisp British
accent announce "Hello [pause] You have requested a code for logging
in to your account; the number is one three fave [sic] seven nine
nine; this code will expire in ten minutes", I would know something's
afoot, and I've got some urgent calls to make.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#248263

FromCurt <curty@free.fr>
Date2022-05-16 10:10 +0200
Message-ID<EnDXH-fOhU-1@gated-at.bofh.it>
In reply to#248259
On 2022-05-16, David Wright <deblis@lionunicorn.co.uk> wrote:
>> 
>> Preventing data breaches are outside the scope of the user, providing
>> a high entropy password is not. If accessing a  site is of importance
>> to him, then, in your plausible scenario, an eight character password
>> effectively gives little security.
>> 
>> That is not an argument for 2FA but for a user having a responsible
>> password policy to guard agains such breaches.
>
> Preventing data breaches might be outside my control, but mitigating
> their effect might not be. So I like to have 2FA set up as entering

B. purports breaches are outside user control but then with alacrity
asserts that the user should guard against them. 

2FA is a mitigating factor in this real-world case (and they are
*legion*). No rational argument has been presented so far as to why it
wouldn't be (all brain-damaged "theories" and ill-formed "ideologies"
and ersatz "philosophies" by the usual straw men aside).

[toc] | [prev] | [next] | [standalone]


#248266

From<tomas@tuxteam.de>
Date2022-05-16 12:00 +0200
Message-ID<EnFG9-fP4V-21@gated-at.bofh.it>
In reply to#248263

[Multipart message — attachments visible in raw view] — view raw

On Mon, May 16, 2022 at 07:59:38AM -0000, Curt wrote:

[...]

> B. purports breaches are outside user control but then with alacrity
> asserts that the user should guard against them. 
> 
> 2FA is a mitigating factor in this real-world case (and they are
> *legion*). No rational argument has been presented so far as to why it
> wouldn't be (all brain-damaged "theories" and ill-formed "ideologies"
> and ersatz "philosophies" by the usual straw men aside).

Difficult to say to whom you are referring to, due to lots of passive
voice being used in your post.

Just in case, let me stated that I never implied that 2FA doesn't do
any good. It /is/ a mitigation indeed. But for me, the bang it brings
isn't worth the buck it costs. Simply that.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#248275

FromCurt <curty@free.fr>
Date2022-05-16 14:40 +0200
Message-ID<EnIaZ-fQBr-1@gated-at.bofh.it>
In reply to#248266
On 2022-05-16, <tomas@tuxteam.de> <tomas@tuxteam.de> wrote:

> Just in case, let me stated that I never implied that 2FA doesn't do
> any good. It /is/ a mitigation indeed. But for me, the bang it brings
> isn't worth the buck it costs. Simply that.
>

But you did imply it. To the question of data breaches and sites storing
your password in plain text, you replied, "unique passwords," as if that
non sequitur in the form of sound advice rendered 2FA superfluous and
could mitigate the scenario in which your unique password is part of a
list on the darknet following a data breach.

[toc] | [prev] | [next] | [standalone]


#248268

FromStella Ashburne <rewefie@gmx.com>
Date2022-05-16 13:10 +0200
Message-ID<EnGLU-fPUs-5@gated-at.bofh.it>
In reply to#248259
Excuse me, Fero Dali, how is your post/question relevant to this mailing list?

[toc] | [prev] | [next] | [standalone]


#248278

FromBrian <ad44@cityscape.co.uk>
Date2022-05-16 15:40 +0200
Message-ID<EnJ73-fR9Q-1@gated-at.bofh.it>
In reply to#248259
On Sun 15 May 2022 at 22:39:14 -0500, David Wright wrote:

> On Sat 14 May 2022 at 14:02:36 (+0100), Brian wrote:
> > On Sat 14 May 2022 at 12:02:49 -0000, Curt wrote:
> > > On 2022-05-14, <tomas@tuxteam.de> wrote:
> > > > On Sat, May 14, 2022 at 08:58:37AM -0000, Curt wrote:
> > > >
> > > > [...]
> > > >
> > > >> What about data breaches, and sites keeping your password
> > > >> in plain text (though it seems access to the cryptographically hashed
> > > >> passcodes is already a pretty good leg up)? What good is our entropy then?
> > > >
> > > > As stated elsewhere: unique passwords. Don't use a password you're using
> > > > elsewhere. Much less so with a site you don't trust.
> > > 
> > > As always, I'm very uncertain where your goal posts are placed or what
> > > tacit agenda you're following. No one has advocated the use of unique
> > > passwords. 
> > > 
> > > In my plausible scenario, you're password entropy counts for nothing.
> > > Your password, unique or otherwise, has been compromised. 2FA would
> > > prevent illegal entry to your account in this case. The subject we're
> > > addressing here is your assertion that 2FA adds no extra security. I
> > > have demonstrated that it does.
> > 
> > Preventing data breaches are outside the scope of the user, providing
> > a high entropy password is not. If accessing a  site is of importance
> > to him, then, in your plausible scenario, an eight character password
> > effectively gives little security.
> > 
> > That is not an argument for 2FA but for a user having a responsible
> > password policy to guard agains such breaches.
> 
> Preventing data breaches might be outside my control, but mitigating
> their effect might not be. So I like to have 2FA set up as entering
> a code in response to a phone call. There's some peace of mind in my
> /not/ receiving any of those calls unless /I/ try to login.
> 
> Were it to ring unexpectedly and I heard a woman with a crisp British
> accent announce "Hello [pause] You have requested a code for logging
> in to your account; the number is one three fave [sic] seven nine
> nine; this code will expire in ten minutes", I would know something's
> afoot, and I've got some urgent calls to make.

Something may be untoward, but it very likely won't be as a result of
your 16/20 character, high entropy password being brute-forced after a
data breach at your credit card provider. This mitigation technique
should be sufficient to bring peace of mind.

OTOH, 2FA is part of the regulatory aspect for some financial entities
and impossible to avoid. Of what use is a strong password in that
situation? Strong or weak, autherntication now takes place with the
second factor.

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#248284

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2022-05-16 18:00 +0200
Message-ID<EnLiy-fSlx-17@gated-at.bofh.it>
In reply to#248278
On Mon 16 May 2022 at 14:31:50 (+0100), Brian wrote:
> On Sun 15 May 2022 at 22:39:14 -0500, David Wright wrote:
> > On Sat 14 May 2022 at 14:02:36 (+0100), Brian wrote:
> > > On Sat 14 May 2022 at 12:02:49 -0000, Curt wrote:
> > > > On 2022-05-14, <tomas@tuxteam.de> wrote:
> > > > > On Sat, May 14, 2022 at 08:58:37AM -0000, Curt wrote:
> > > > >
> > > > > [...]
> > > > >
> > > > >> What about data breaches, and sites keeping your password
> > > > >> in plain text (though it seems access to the cryptographically hashed
> > > > >> passcodes is already a pretty good leg up)? What good is our entropy then?
> > > > >
> > > > > As stated elsewhere: unique passwords. Don't use a password you're using
> > > > > elsewhere. Much less so with a site you don't trust.
> > > > 
> > > > As always, I'm very uncertain where your goal posts are placed or what
> > > > tacit agenda you're following. No one has advocated the use of unique
> > > > passwords. 
> > > > 
> > > > In my plausible scenario, you're password entropy counts for nothing.
> > > > Your password, unique or otherwise, has been compromised. 2FA would
> > > > prevent illegal entry to your account in this case. The subject we're
> > > > addressing here is your assertion that 2FA adds no extra security. I
> > > > have demonstrated that it does.
> > > 
> > > Preventing data breaches are outside the scope of the user, providing
> > > a high entropy password is not. If accessing a  site is of importance
> > > to him, then, in your plausible scenario, an eight character password
> > > effectively gives little security.
> > > 
> > > That is not an argument for 2FA but for a user having a responsible
> > > password policy to guard agains such breaches.
> > 
> > Preventing data breaches might be outside my control, but mitigating
> > their effect might not be. So I like to have 2FA set up as entering
> > a code in response to a phone call. There's some peace of mind in my
> > /not/ receiving any of those calls unless /I/ try to login.
> > 
> > Were it to ring unexpectedly and I heard a woman with a crisp British
> > accent announce "Hello [pause] You have requested a code for logging
> > in to your account; the number is one three fave [sic] seven nine
> > nine; this code will expire in ten minutes", I would know something's
> > afoot, and I've got some urgent calls to make.
> 
> Something may be untoward, but it very likely won't be as a result of
> your 16/20 character, high entropy password being brute-forced after a
> data breach at your credit card provider. This mitigation technique
> should be sufficient to bring peace of mind.

Sure, there's always the argument that your password only has to be
difficult enough to crack that numerous others will already be being
exploited. There's no point in their trying to crack more and more
difficult passwords when there's already a plentiful harvest available.

> OTOH, 2FA is part of the regulatory aspect for some financial entities
> and impossible to avoid. Of what use is a strong password in that
> situation? Strong or weak, autherntication now takes place with the
> second factor.

Technically, it's only the "second" factor because it's normally
solicited by success with the password. It doesn't /have to/ be
that way. For example, I could schedule a code to be sent to my
phone at noon every Tuesday and, if I chose to use it, authentication
would take place with what we're currently calling the "first" factor,
the password.

One facility I didn't mention in connection with 2FA by phone. It's
conventional when you log in to be reminded of when you logged in
previously. With 2FA, I don't have to stretch my memory cells to
recall when that was, I can just look at the list of dialled calls.

(Note: I'm only explaining why 2FA by phone suits me. I'm not making
any arguments with respect to the exchanges further up the thread.)

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#248201

FromBrian <ad44@cityscape.co.uk>
Date2022-05-14 14:10 +0200
Message-ID<EmYKR-fpYW-3@gated-at.bofh.it>
In reply to#248194
On Sat 14 May 2022 at 08:58:37 -0000, Curt wrote:

> On 2022-05-14, Ash Joubert <ash@transient.nz> wrote:
> > On 13/05/2022 12:23, Nicholas Geovanis wrote:
> >> That's the value added in exchange for Ash's "massive pain in the arse".
> >> Just making the 1st factor be
> >> a loong password is not equivalent to 2FA in any way. Machine reaching back
> >> to you is the difference.
> >
> > There are attacks that 2FA can defeat, especially things like password 
> > reset via compromised email server, but in general, two weak factors are 
> > not a match for a strong unique random password. In particular, it is 
> > not uncommon for sms/email/totp second factor to resolve to exactly the 
> > same device as the first factor, reducing 2FA to a single factor. 
> > Compromise such a user's phone and it is all over.
> 
> What about data breaches, and sites keeping your password
> in plain text (though it seems access to the cryptographically hashed
> passcodes is already a pretty good leg up)? What good is our entropy then?
> 
> https://en.wikipedia.org/wiki/List_of_data_breaches
> 
> https://arstechnica.com/information-technology/2013/05/how-crackers-make-minced-meat-out-of-your-passwords/

The time to brute force a hash depends on password entropy. The
second link is an interesting read, but I do not think evrything
in a cracker's garden is rosy. One can only hope providers use
decentt hashing techniques and keep data safe.

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#248638

FromBrian <ad44@cityscape.co.uk>
Date2022-06-01 19:10 +0200
Message-ID<EtA14-1QHf-3@gated-at.bofh.it>
In reply to#248119
On Thu 12 May 2022 at 10:08:01 -0000, Virgo Pärna wrote:

> On Wed, 11 May 2022 20:09:14 +0200, Fero Dali <ferodali@gmail.com> wrote:
> > Sorry for misunderstanding: it seems that my account will continue to work but
> > ability to download mail with POP3 without OAUTH2 will be unavailable.
> >
> 
> 	Actually, even without OAUTH2 it should be still possible. With
> two factor authentication enabled it is possible to generate app
> password for use with standard authentication.

It's June 1st and my ability to collect mail via POP3 from gmail is
unimpaired. No  OAUTH2 or 2FA at this site. Whatever Google intended
the situation to be after May 30th, it appears the interpretation by
some users of their mail was off the mark.

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#248641

FromPatrick Bartek <nemommxiv@gmail.com>
Date2022-06-01 19:50 +0200
Message-ID<EtADL-1QTp-1@gated-at.bofh.it>
In reply to#248638
On Wed, 1 Jun 2022 18:04:02 +0100
Brian <ad44@cityscape.co.uk> wrote:

> On Thu 12 May 2022 at 10:08:01 -0000, Virgo Pärna wrote:
> 
> > On Wed, 11 May 2022 20:09:14 +0200, Fero Dali <ferodali@gmail.com>
> > wrote:  
> > > Sorry for misunderstanding: it seems that my account will
> > > continue to work but ability to download mail with POP3 without
> > > OAUTH2 will be unavailable. 
> > 
> > 	Actually, even without OAUTH2 it should be still possible.
> > With two factor authentication enabled it is possible to generate
> > app password for use with standard authentication.  
> 
> It's June 1st and my ability to collect mail via POP3 from gmail is
> unimpaired. No  OAUTH2 or 2FA at this site. Whatever Google intended
> the situation to be after May 30th, it appears the interpretation by
> some users of their mail was off the mark.
> 

Still works here, too. Claws-mail 3.17.3 IMAP.  No OAuth2 or 2FA.
Neither of which this version of Claws supports, IIRC. Of course,
notification email did say "may not" not won't.

FWIW: Yahoo mail ceased working with Claws several years ago due to
security changes.  Though still accessible via web browser with only a
password.

B

[toc] | [prev] | [next] | [standalone]


#248642

FromBrian <ad44@cityscape.co.uk>
Date2022-06-01 20:40 +0200
Message-ID<EtBq9-1RnB-1@gated-at.bofh.it>
In reply to#248641
On Wed 01 Jun 2022 at 10:44:17 -0700, Patrick Bartek wrote:

> On Wed, 1 Jun 2022 18:04:02 +0100
> Brian <ad44@cityscape.co.uk> wrote:
> 
> > On Thu 12 May 2022 at 10:08:01 -0000, Virgo Pärna wrote:
> > 
> > > On Wed, 11 May 2022 20:09:14 +0200, Fero Dali <ferodali@gmail.com>
> > > wrote:  
> > > > Sorry for misunderstanding: it seems that my account will
> > > > continue to work but ability to download mail with POP3 without
> > > > OAUTH2 will be unavailable. 
> > > 
> > > 	Actually, even without OAUTH2 it should be still possible.
> > > With two factor authentication enabled it is possible to generate
> > > app password for use with standard authentication.  
> > 
> > It's June 1st and my ability to collect mail via POP3 from gmail is
> > unimpaired. No  OAUTH2 or 2FA at this site. Whatever Google intended
> > the situation to be after May 30th, it appears the interpretation by
> > some users of their mail was off the mark.
> > 
> 
> Still works here, too. Claws-mail 3.17.3 IMAP.  No OAuth2 or 2FA.
> Neither of which this version of Claws supports, IIRC. Of course,
> notification email did say "may not" not won't.

Indeed, the mail did say that. However, many vociferous users went
into Chicken Licken mode and forecast distaster.

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#248670

Fromnemo <moelmoel2714@gmail.com>
Date2022-06-02 17:20 +0200
Message-ID<EtUM9-23MQ-3@gated-at.bofh.it>
In reply to#248638

[Multipart message — attachments visible in raw view] — view raw

On Wed, Jun 1, 2022 at 10:24 PM mick crane <mick.crane@gmail.com> wrote:

> On 2022-06-01 18:04, Brian wrote:
> > On Thu 12 May 2022 at 10:08:01 -0000, Virgo Pärna wrote:
> >
> >> On Wed, 11 May 2022 20:09:14 +0200, Fero Dali <ferodali@gmail.com>
> >> wrote:
> >> > Sorry for misunderstanding: it seems that my account will continue to
> work but
> >> > ability to download mail with POP3 without OAUTH2 will be unavailable.
> >> >
> >>
> >>      Actually, even without OAUTH2 it should be still possible. With
> >> two factor authentication enabled it is possible to generate app
> >> password for use with standard authentication.
> >
> > It's June 1st and my ability to collect mail via POP3 from gmail is
> > unimpaired. No  OAUTH2 or 2FA at this site. Whatever Google intended
> > the situation to be after May 30th, it appears the interpretation by
> > some users of their mail was off the mark.
>
> I'd just allowed non secure apps a year or so ago and seems to be still
> working.
>
> mick
>

Me too except today it doesn't seem to be working. must test but I think
I've been shut out, using Alpine with non-secure apps switched on.
fjd

[toc] | [prev] | [next] | [standalone]


#248676

Fromrhkramer@gmail.com
Date2022-06-02 20:10 +0200
Message-ID<EtXqF-25v8-7@gated-at.bofh.it>
In reply to#248670
On Thursday, June 02, 2022 11:13:14 AM nemo wrote:
> Me too except today it doesn't seem to be working. must test but I think
> I've been shut out, using Alpine with non-secure apps switched on.
> fjd

My gmail (normally delivered by pop3 to my old version of kmail (on Wheezy) 
stopped working around 8:30 am this morning. 

I set up an application specific password this morning, and that old version of 
kmail (version 1.13.7 for kde 4.8.4 on Debian Wheezy) works again using pop3 

I had a little trouble setting it up until I got to the right place in google 
-- I first tried to change the settings on the gmail webclient page but 
couldn't find the correct options.  Then logged in on google.com and did find 
the correct option (Security), and then, in general terms, turned on 2 step 
verification and eventually found the option to set up an application specific 
password.

I then entered that in place of the old passwords in kmail.  (I don't think it 
stated it -- I wasn't sure whether to enter the spaces as part of the password 
or not -- I did, and that worked.)

[toc] | [prev] | [next] | [standalone]


Page 3 of 6 — ← Prev page 1 2 [3] 4 5 6  Next page →

Back to top | Article view | linux.debian.user


csiph-web