macOS

Google to Block Less Secure Apps Accessing Gsuite Accounts Data

Google to block access for less secure apps (LSAs) to access the Gsuite account data, instead, Google recommends using apps that support OAuth.

OAuth is an authorization framework that describes how the unrelated servers and services can be access to secure data without sharing the login related information. You can find a detailed article about OAuth here.

Impacts of LSAs Turned off

The users of services like legacy email, calendar, and contact apps are to be most impacted. The turnoff to be handled in two different stages.

  • At the first stage on June 15, 2020, Google to block the first time users who try to connect with an LSA apps, it includes third-party apps that allow “password-only access to Google calendars, contacts, and email via protocols such as CalDAV, CardDAV, IMAP, and Exchange ActiveSync (Google Sync).”
  • Starting February 15, 2021, will be completed turned off for all the G Suite accounts.

Why Google has taken this Decision

Google has taken this decision because several users who use non-Google apps and give permissions to access G Suite data, the access to the account provided using username and password if the bad actor gets access to username and password it may results in account compromise.

It is recommended by Google using OAuth as they “get more details about the login and can validate it the same way we would with any other login to your account.”

To maintain compatibility developers are recommended to update with OAuth 2.0 as a connection method. For Scanners and other devices, no change required.

For end-users, those you using Google account with only a username and password are recommended to switch with a more secure method to access our email, calendar, or contacts.

You can follow us on LinkedinTwitterFacebook for daily Cyber Security and hacking news updates.

Also Read: What is OAuth 2.0 ? How it Works ? A Detailed Explanation of Authorization Framework

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago