Porthos
Well-Known Member
- Reaction score
- 14,102
- Location
- San Antonio Tx
Google announced that it will block less secure apps (LSAs) from accessing G Suite account data starting February 2021, following an initial stage of limiting their access during June 2020.
This announcement follows the removal of the "Enforce access to less secure apps for all users" setting from the Google Admin console on October 30, 2019.
LSAs are non-Google apps that access Google accounts using only a username and password pair and thus exposing users who use them to account hijacking attacks.
The process through which apps are sending username/password pairs with every authentication request made when connecting to a server, an endpoint, or an online service is also known as basic authentication or proxy authentication.
While this simplifies the authentication process, it also makes it a lot easier for potential attackers to steal the user's credentials when connections are not secured using Transport Layer Security (TLS) or to obtain them via credential dumps following a data breach.
https://www.bleepingcomputer.com/ne...-force-oauth-in-g-suite-to-increase-security/
This announcement follows the removal of the "Enforce access to less secure apps for all users" setting from the Google Admin console on October 30, 2019.
LSAs are non-Google apps that access Google accounts using only a username and password pair and thus exposing users who use them to account hijacking attacks.
The process through which apps are sending username/password pairs with every authentication request made when connecting to a server, an endpoint, or an online service is also known as basic authentication or proxy authentication.
While this simplifies the authentication process, it also makes it a lot easier for potential attackers to steal the user's credentials when connections are not secured using Transport Layer Security (TLS) or to obtain them via credential dumps following a data breach.
https://www.bleepingcomputer.com/ne...-force-oauth-in-g-suite-to-increase-security/