There's an evil with social login in that you give up the knowledge of your social (presumably personal) network to random 3rd parties. That's even worse than email address. With password managers being essentially mandatory now, it's not too hard to create a new email/password based account for every new site. But recently I realized that I don't use my FB for anything. I have zero friends, don't allow friend reques…
I don't think password managers have as much penetration as you think and they only work on devices you own. Social login doesn't necessarily give up that much info. Your social network knows who logged in to. The third-party only gets whatever info you accede to which usually is just an email address or name. The huge bonus to users and site owners is that that site isn't storing a password for you. It's easy to scr…
Mind you, products would have to adopt it. But from a sec + privacy perspective it makes sense to have a 3rd party whose biz model isn't to harvest your personal details.