Google App Passwords

Discussions revolve around Google's policy ending support for less secure authentication apps for Gmail, with users debating the use of app-specific passwords generated via 2FA as a workaround for email clients lacking OAuth support.

📉 Falling 0.3x Security
1,665
Comments
19
Years Active
5
Top Authors
#238
Topic ID

Activity Over Time

2008
9
2009
10
2010
46
2011
71
2012
152
2013
83
2014
43
2015
43
2016
78
2017
88
2018
110
2019
96
2020
121
2021
93
2022
245
2023
123
2024
147
2025
100
2026
7

Keywords

e.g PHP OAUTH POV answer.py RFC6238 JavaScript PIN K9 MFA google passwords app oauth password gmail account apps auth google apps

Sample Comments

gtirloni Nov 21, 2020 View on HN

Not much. If you're not using app passwords and your client wants to authenticate using Google auth (e.g. Thunderbird), it has to open the user's browser and setup the oauth flows instead of embedding the browser directly in the app.

martius Mar 1, 2022 View on HN

Google provides the App passwords feature:> An App password is a 16-digit passcode that gives a non-Google app or device permission to access your Google Account. Learn more about how to sign in using App Passwords.Maybe I misunderstand the announcement, but it looks to me that this feature will still be a valid alternative when Oauth can't be used.

adnans Dec 4, 2012 View on HN

Disappointed that Google's own application doesn't support 2-step authentication and application specific password.

PStamatiou Oct 4, 2010 View on HN

using google apps premier two factor auth and create a new key for it so you dont have to give it your real password and can revoke at anytime. (assuming Sparrow supports google apps email?)

yock Jun 2, 2012 View on HN

Google's own products don't even conform to this. My Galaxy Nexus and Chrome browser requires app-specific passwords.

joshuamorton Jan 19, 2024 View on HN

Sure but Google doesn't know that, and app passwords are a way to functionally ensure no password reuse.

throwaway67743 Jun 7, 2022 View on HN

I did see a mail from them a few months ago about this, you need to use their oauth2 flow now I believe for any "less secure" apps, more vendor lock-in

tptacek May 5, 2020 View on HN

Google Mail's OAuth2 instructions discuss this point explicitly.

jefftk Mar 1, 2022 View on HN

No: the announcement says you can use application specific passwords https://support.google.com/accounts/answer/185833

jefftk Mar 1, 2022 View on HN

No: the announcement says you can use application specific passwords https://support.google.com/accounts/answer/185833