Re: the great Gmail ERR [AUTH] therad

Charles Cazabon <[email protected]> Fri, 3 Jun 2022 16:21:36 -0600
Newsgroups gmane.mail.getmail.user
Message-ID <[email protected]>
Neil R. Ormos <[email protected]> wrote:
> 
> > But this does seem kind of academic.  If you do not have a working
> > computer, phone, tablet or other electronic device with working internet
> > access ... what exactly would you be doing that would require you to
> > interact with Google's authentication demands?  Are you using IP over
> > avian carrier?
> 
> The user might have a working computer or a working phone, with network
> access, but not necessarily both, or not necessarily simultaneously.

I get that ... but if Google is demanding you authenticate, you pretty much by
definition have a working device with network access.  Either that, or you're
accessing a Google service via telepathy, in which case ... well done.

Maybe it's not your phone, or your computer -- but you can install a TOTP
authenticator app on every device you own (for backup) and configure it with
your Google TOTP key, so access to any device will let you in.  And if you
want to handle the case of "My phone broke and I dropped by laptop in the
toilet", so you can access your email via someone else's machine or a
freshly-bought replacement phone, you can print that TOTP code out (as text or
QR code), keep it in your wallet, and easily set it up on any other device.
There are even web services where you can do this more-or-less securely, so
you wouldn't necessarily even need to install any software (i.e. a locked-down
public computer).

> I understand Google is said to support TOTP.  OTOH, Google's caprice knows
> no bounds, so even if an account is set up for TOTP 2FV, it's not clear to
> me that there won't be an authentication/verification challenge that can be
> satisfied only via some other path, such as a network-connected mobile
> phone.

For work accounts I have set up 2FA via TOTP with Google, for years.  They
have never asked me to verify by any other method since I set up TOTP -- I
previously used voice calls.

I don't like Google.  I don't trust them.  I don't use any of their services
for my personal use.  But I have to use them for many work situations, and my
experience is that 2FA via TOTP is extremely viable with them.

> I'm interested in OAUTH2 support not because I think it's objectively better
> security, but because, when the OAUTH2 stuff is built into an app, using it
> results in the lowest user authentication friction.

Sure, it's nice.

> I understand I'll have to wait for someone to contribute a patch.

Depends how important it is to you.  If you don't want to wait, you can always
pay someone else to do it, if you can't do it yourself.  Frankly, it looks
like a pretty simple job; there's even a basic HTTP server in the Python
standard library.

Charles
-- 
-----------------------------------------------------------------------
Charles Cazabon
GPL'ed software available at:               http://pyropus.ca/software/
-----------------------------------------------------------------------