2023-09-04 Archiv

Oh Autsch Zwei.

OAuth2 *in practice* is abused to control what applications can access YOUR OWN mail.

Do you need to register your slippers or mailbox key with $YOURCOUNTRY's Postal Service before you can open your mailbox and get your mail out? No. But that is what Google and Microsoft do with OAuth2 in practice.

With mail providers requiring applications to be registered, possibly fee-paying assessment - no thanks.

Matthias, on fetchmail-users (2022-10-22)