App-Specific Passwords: Origins, Functionality, Security Risks and Mitigation

Originally published by Astrix on August 14, 2024.Written by Tomer Yahalom.Google announced it will terminate support for Less Secure Apps (LSAs) on September 30, which presents a great opportunity to dive into their evolution – App-Specific Passwords, and the security concerns that still remain.Less Secure Apps (LSAs): How it all beganLess Secure Apps (probably called regular apps back in the day) are applications that were created before the introduction of the Open Authorization Framework …