Re: the great Gmail ERR [AUTH] therad
Charles Cazabon <[email protected]> Fri, 3 Jun 2022 16:21:36 -0600
| Newsgroups | gmane.mail.getmail.user |
|---|---|
| Message-ID | <[email protected]> |
Neil R. Ormos <[email protected]> wrote: > > > But this does seem kind of academic. If you do not have a working > > computer, phone, tablet or other electronic device with working internet > > access ... what exactly would you be doing that would require you to > > interact with Google's authentication demands? Are you using IP over > > avian carrier? > > The user might have a working computer or a working phone, with network > access, but not necessarily both, or not necessarily simultaneously. I get that ... but if Google is demanding you authenticate, you pretty much by definition have a working device with network access. Either that, or you're accessing a Google service via telepathy, in which case ... well done. Maybe it's not your phone, or your computer -- but you can install a TOTP authenticator app on every device you own (for backup) and configure it with your Google TOTP key, so access to any device will let you in. And if you want to handle the case of "My phone broke and I dropped by laptop in the toilet", so you can access your email via someone else's machine or a freshly-bought replacement phone, you can print that TOTP code out (as text or QR code), keep it in your wallet, and easily set it up on any other device. There are even web services where you can do this more-or-less securely, so you wouldn't necessarily even need to install any software (i.e. a locked-down public computer). > I understand Google is said to support TOTP. OTOH, Google's caprice knows > no bounds, so even if an account is set up for TOTP 2FV, it's not clear to > me that there won't be an authentication/verification challenge that can be > satisfied only via some other path, such as a network-connected mobile > phone. For work accounts I have set up 2FA via TOTP with Google, for years. They have never asked me to verify by any other method since I set up TOTP -- I previously used voice calls. I don't like Google. I don't trust them. I don't use any of their services for my personal use. But I have to use them for many work situations, and my experience is that 2FA via TOTP is extremely viable with them. > I'm interested in OAUTH2 support not because I think it's objectively better > security, but because, when the OAUTH2 stuff is built into an app, using it > results in the lowest user authentication friction. Sure, it's nice. > I understand I'll have to wait for someone to contribute a patch. Depends how important it is to you. If you don't want to wait, you can always pay someone else to do it, if you can't do it yourself. Frankly, it looks like a pretty simple job; there's even a basic HTTP server in the Python standard library. Charles -- ----------------------------------------------------------------------- Charles Cazabon GPL'ed software available at: http://pyropus.ca/software/ -----------------------------------------------------------------------