Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

21–30 of 544 posts

Re: Don't use third party auth to sign in

#21
post #2

I realized that recently after Gmail locked my account for using email outreach software. I restored it but automatically had to start thinking about a backup plan where I’d have to point my MX records away from Gmail to something else immediately in order to prevent email downtime.

> for using email outreach software.

I hope they ban people sending bulk email too... You should send that stuff from your own server or MailChimp etc.

Re: Don't use third party auth to sign in

#22
post #6

Has anyone else noticed random popups on 3rd party websites asking for google sign in? I even used firefox when it happened: https://imgur.com/a/JC52lBV (lequipe.fr) https://imgur.com/a/VSM3Uk9 (reddit.com) https://imgur.com/a/KpVCYBL (medium.com)

Yeah. Reddit is especially really intrusive and annoying. I feel like they just don't want people to use their site anymore. Whenever I open new Reddit, my memory and CPU usage goes up so badly.

old.reddit.com.

Re: Don't use third party auth to sign in

#23
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

$6/month doesn't sound like much... Till you realise you'll probably have this setup for 20 years, and suddenly it's $1200. That's a lot to protect against a thing that will probably not happen (account being banned)

6 * 12 * 20 = 1440

Re: Don't use third party auth to sign in

#24

"Never Use Google to Sign-In" he says it as he offers Google Sign-In through Disqus comment section on his blog.

If they had built their own comment section with Google login, that would be weird indeed. But if you just like Disqus comments (they certainly were hot when I actively blogged in 2012) and one of their login options is Google... I don't see the issue there unless they're really pushing you to use it.

Re: Don't use third party auth to sign in

#25
We went through a process of changing email domains recently and we use Google Sign In for many of our services. Switching emails over varied greatly between services. Sometimes it all just worked and my new email would sign in to my account and my email address on the service was updated automatically. Some allowed me to sign in fine, but I had to contact them directly to update the email address. A number of times I ended up having to go through recovery processes.

I guess at least if you’re using your own domain, you’d be able to repoint mx records to do the recovery.

I tend not to use it for my personal accounts, but honestly, Google Sign In for our work systems has generally been a good experience. Works well for our small team, anyway.

Re: Don't use third party auth to sign in

#27

Earlier quoted context omitted.

$6/month doesn't sound like much... Till you realise you'll probably have this setup for 20 years, and suddenly it's $1200. That's a lot to protect against a thing that will probably not happen (account being banned)

I pay for gsuite for myself and a couple of my domains. Call it $12/month, because you'll want to setup two accounts: * The admin-user. * The daily/real-user. In my case I have my real account "steve@steve..", and "admin@steve" which is the gsuite administrator. I only login to make changes to the domain setup, never to send/receive email. It's annoying to have to pay for that second user, but I feel happier with the…

Why not me@steve, iam@steve, thisis@steve, thereal@steve or any of the other variants?

Re: Don't use third party auth to sign in

#28
post #9

Earlier quoted context omitted.

For that you have this: https://takeout.google.com/ You can export all your email in a single .mbox file. This might not work if your account is suspended, but if you set up email forwarding to an alternative address (e.g. to protonmail) that might still stay active so you can transition your addresses.

I wonder if Google lets you Takeout if they’ve locked your account…

They do now (although you only have 7 days to do so I think).

It also depends on the reason for the block - if for example they suspect you of having illegal content (child porn) in your Gmail, you aren't allowed to takeout it.

Re: Don't use third party auth to sign in

#30
post #15

Isn't that obvious? Convenience always hat some kind of price tag, particularly a security related one. I would have canceled my facebook account long ago if I had not chosen their login for a (unknown) number of service. What would be a better alternative? Use same credentials everywhere? No, because it is just a matter of time it would leak out of one service. Use unique credentials for each service in local passwo…

> What would be a better alternative? Use same credentials everywhere? No, because it is just a matter of time it would leak out of one service. Use unique credentials for each service in local password manager? Nay, because most of us at least want to sync between desktop an mobile. Use something like Chrome's password manager? That bears similar dangers like those the article points out.

I use BitWarden and it works pretty well on all my iOS devices and across major browsers.

Post reply on HN