Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

11–20 of 544 posts

Re: Don't use third party auth to sign in

#11
The truth is you should not use Google login to Google services either. You get the service promise you pay for, none. If their secret algorithms decide that you are in breach of whatever ToS, they will lock you out. Not very likely for the average user. But more likely for HN reader who might experiment with programmatic access to the services or do other atypical stuff.

Yes, I need to move away from gmail...

Re: Don't use third party auth to sign in

#12
post #9

Earlier quoted context omitted.

Yeah but they’ve still got your emails.

For that you have this: https://takeout.google.com/ You can export all your email in a single .mbox file. This might not work if your account is suspended, but if you set up email forwarding to an alternative address (e.g. to protonmail) that might still stay active so you can transition your addresses.

I wonder if Google lets you Takeout if they’ve locked your account…

Re: Don't use third party auth to sign in

#14
post #6

Has anyone else noticed random popups on 3rd party websites asking for google sign in? I even used firefox when it happened: https://imgur.com/a/JC52lBV (lequipe.fr) https://imgur.com/a/VSM3Uk9 (reddit.com) https://imgur.com/a/KpVCYBL (medium.com)

Yeah. Reddit is especially really intrusive and annoying. I feel like they just don't want people to use their site anymore. Whenever I open new Reddit, my memory and CPU usage goes up so badly.

Re: Don't use third party auth to sign in

#15
Isn't that obvious? Convenience always hat some kind of price tag, particularly a security related one.

I would have canceled my facebook account long ago if I had not chosen their login for a (unknown) number of service.

What would be a better alternative? Use same credentials everywhere? No, because it is just a matter of time it would leak out of one service. Use unique credentials for each service in local password manager? Nay, because most of us at least want to sync between desktop an mobile. Use something like Chrome's password manager? That bears similar dangers like those the article points out.

Re: Don't use third party auth to sign in

#16
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

$6/month doesn't sound like much... Till you realise you'll probably have this setup for 20 years, and suddenly it's $1200. That's a lot to protect against a thing that will probably not happen (account being banned)

It's insurance, a waste of money most of the time, and extremely good value for money very occasionally

Re: Don't use third party auth to sign in

#17
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

$6/month doesn't sound like much... Till you realise you'll probably have this setup for 20 years, and suddenly it's $1200. That's a lot to protect against a thing that will probably not happen (account being banned)

I pay for gsuite for myself and a couple of my domains. Call it $12/month, because you'll want to setup two accounts:

* The admin-user.

* The daily/real-user.

In my case I have my real account "steve@steve..", and "admin@steve" which is the gsuite administrator. I only login to make changes to the domain setup, never to send/receive email.

It's annoying to have to pay for that second user, but I feel happier with the privilege separation in place.

Re: Don't use third party auth to sign in

#18
post #3

I only ever use "sign in with" for throaway stuff I don't care enough about to register an account - if it's in any way important I setup an account, and add whatever form of 2FA I can.

I really wish 2fa was implemented in convenient form everywhere. There are ton of sites that just force me to use SMS.

Re: Don't use third party auth to sign in

#20
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

You don't need gsuite to both send/receive from a custom domain on gmail.

Takes a few minutes extra messing around with settings I guess but they offer the service for free, I can guarantee this.

Post reply on HN