On Friday, 3 June 2022 12:15:53 BST spareproject776 wrote:

> How did you even enable the oauth thing ? only had security device or
> push to an authenticated device available. Then lied and forced enabling
> sms as a 'recovery' option.

When I enabled OAuth2 it was early days and Google did not ask for 2FA as a 
prerequisite back then.  All you had to provide, for account recovery, was 
another email address.  So I set up a second Google email address for this 
purpose and cross referenced the two accounts.  Some months thereafter Google 
started asking for 2FA via SMS, before you could access the page to set up app 
access.  More recently they also started asking for DOB, "... for legal 
purposes".  Soon they will be asking for digital ID and a DNA test, or 
whatever.  :p

I noticed whenever I tried to login from a remote location Google would block 
the mail client and also block webmail login if I tried to use a browser.  
Evidently, geolocation/IP address was being used as a security check.  To 
acknowledge this was not an attempt by some remote and nefarious actor to 
compromise my account, I had to connect to Google by tunneling via a VPN 
connection to my home and from there to the Google webmail.  After that I was 
able to login remotely.

The question about privacy is a moot point.  Privacy is often conflated with 
identity and consequently with security.  All a mail service provider *need* 
to know is if the person trying to login is the same person who set up/owns 
the account.  A single or multiple challenge-response mechanism over an 
encrypted network connection is enough to identify the owner of the account 
via the credentials exchanged between client and server.  No sharing of any 
other private and personally identifiable information needs to be part of it.

Attachment: signature.asc
Description: This is a digitally signed message part.

Reply via email to