Live data from Hacker News

Ask HN: How do you keep track of “Log in with” accounts

news.ycombinator.com

21–30 of 50 posts

Re: Ask HN: How do you keep track of “Log in with” accounts

#22
post #20
post #17

Earlier quoted context omitted.

The point is that it allows you to remember which provider you used to sign in with and you’re not having to guess whether you logged in with Google or GitHub or whatever else.

If you are already using a password manager, why not login using password? No 3rd party dependency and risk, and no need to remember how you signed in.

That is also my preference. However, that is not the question that is being asked.

Re: Ask HN: How do you keep track of “Log in with” accounts

#23
post #17

To the people using a password manager to store the fact that they used third party login, this is some of the most perplexing behavior I've seen in a while. It's like storing a photo of gold bars inside your basement safe. With almost zero extra effort, you could be in control of your own keys. You already have the entire infrastructure set up to do this and all you use it for is a glorified log book? Can someone ex…

The point is that it allows you to remember which provider you used to sign in with and you’re not having to guess whether you logged in with Google or GitHub or whatever else.

I get that part, but by the time you've set up this reminder, why not go the extra millimeter and actually add a password?

You go from delegating some of the most important elements of your life to a third party who can take your account away at any moment with no recourse (an extremely vulnerable position), to having complete control over all those accounts, with zero extra effort.

It's very confusing.

Re: Ask HN: How do you keep track of “Log in with” accounts

#24
post #22
post #20

Earlier quoted context omitted.

If you are already using a password manager, why not login using password? No 3rd party dependency and risk, and no need to remember how you signed in.

That is also my preference. However, that is not the question that is being asked.

[deleted]

Re: Ask HN: How do you keep track of “Log in with” accounts

#25
post #22
post #20

Earlier quoted context omitted.

If you are already using a password manager, why not login using password? No 3rd party dependency and risk, and no need to remember how you signed in.

That is also my preference. However, that is not the question that is being asked.

I'm not responding to the question being asked, I'm responding to the people answering it.

When I used third party login the whole point was that if I saw it was available, I was sure I'd use it, so I didn't need to store or remember anything. If I tried and it didn't work, I knew I didn't have an account.

So to see these responses was very odd to me.

Re: Ask HN: How do you keep track of “Log in with” accounts

#26
post #17

Earlier quoted context omitted.

The point is that it allows you to remember which provider you used to sign in with and you’re not having to guess whether you logged in with Google or GitHub or whatever else.

I get that part, but by the time you've set up this reminder, why not go the extra millimeter and actually add a password? You go from delegating some of the most important elements of your life to a third party who can take your account away at any moment with no recourse (an extremely vulnerable position), to having complete control over all those accounts, with zero extra effort. It's very confusing.

I suppose there could be any number of reasons. Maybe they were already using SSO prior to using a password manager and it would take more effort than an extra millimeter to switch.

Re: Ask HN: How do you keep track of “Log in with” accounts

#27
post #19

Regarding Google, you are wrong, luckily. There is a page in Google where you can view the associations you made with third party sites and you can cancel them. Where you find this is: 1. Go to your Google Account (e.g. www.google.com, click on your avatar, then on Manage Google Account in the popup that appears.) 2. Click on Security in the left navigation pane. 3. Scroll down, and find a box "Your connections to th…

There are also sites that send you through Google signin, then they still want you to make a username and password. So you shared your email address for nothing.

Is this against the terms of service? I seem to recall that if you do this with Apple they will ban you.

Re: Ask HN: How do you keep track of “Log in with” accounts

#28

To the people using a password manager to store the fact that they used third party login, this is some of the most perplexing behavior I've seen in a while. It's like storing a photo of gold bars inside your basement safe. With almost zero extra effort, you could be in control of your own keys. You already have the entire infrastructure set up to do this and all you use it for is a glorified log book? Can someone ex…

Some platforms only support SSO. There will be Google, Apple, Microsoft, Discord, and that's it.

Re: Ask HN: How do you keep track of “Log in with” accounts

#29
I've mostly stopped using third party identity providers. They have multiple problems, but the thing that finally drove me away was bad implementations locking me out of the accounts they were supposed to protect.

The most recent example was a GitLab instance that was demanding my password before it would let me update the email address on my account. I didn't have a password, because I created the account by logging in with another site. Tech support was nonexistent. I ended up abandoning the account.

Re: Ask HN: How do you keep track of “Log in with” accounts

#30

I like Bitwarden. Tried all the rest. Bitwarden is really great. Plus... I'm a huge fan of how it generates passwords. Celtic-Twisted-Endowment-Petal4-Anybody I try and avoid SSO for the most part. I like being able to use Gmail modifiers so I can create filters if I need to block certain accounts from being spammy. first.last+serviceURL@gmail.com is usually what I use. So like first.last+news.ycombinator.com@gmail.c…

I think this works in practice but I still prefer to have an anonymous/hidden/random email for each service. If one of your Gmail alias emails is sold, isn’t it trivial to write a script and figure out the real Gmail addresses?

Fair. Feels like it’s an uncommon enough practice that most marketers don’t bother. I had access to a 6,000,000+ email list one time and I was curious how many people did this trick and it was under 100.
Post reply on HN