Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

71–80 of 544 posts

Re: Don't use third party auth to sign in

#71
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

Yeah but they’ve still got your emails.

There are alternatives to GSuite -- for instance, Fastmail. Or even the old PObox.com service which has been around since the 90s and is really cheap (Fastmail have bought it now, I notice).

Re: Don't use third party auth to sign in

#72

Earlier quoted context omitted.

I pay for gsuite for myself and a couple of my domains. Call it $12/month, because you'll want to setup two accounts: * The admin-user. * The daily/real-user. In my case I have my real account "steve@steve..", and "admin@steve" which is the gsuite administrator. I only login to make changes to the domain setup, never to send/receive email. It's annoying to have to pay for that second user, but I feel happier with the…

Are you actually the owner of steve.com? Because I've been ordering Dominos pizza with the email steve@steve.com for years. Edit: nevermind. I see you own the .net tld. I've definitely used that to order pizza too. Sorry about that.

Couldn't you use @example.com?

Re: Don't use third party auth to sign in

#73
post #51
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

This is such excellent advice that I wrote a detailed step-by-step instruction guide for people that don't know how to do precisely that: https://sneak.berlin/20201029/stop-emailing-like-a-rube/ It even has special instructions about how to secure the domain registration and DNS accounts. :) (Don't use G Suite, though.)

I have attempted to read two articles on your site. As I am a privacy-focused person the articles were of interest to me. Both times I haven't gotten past reading the opening sentences when an obnoxious pop-up appeared asking for my email address. It seems ironic that someone publishing articles on privacy advocacy would be so keen to collect my email address. This practice also creates a real miserable experience and I have simply closed the page immediately both times. If someone is interested in subscribing to your newsletter why not simply provide a link for them to do so at the end of an article?

Re: Don't use third party auth to sign in

#75

Earlier quoted context omitted.

old.reddit.com.

Use a browser plugin like this to always use the old site: https://addons.mozilla.org/en-US/firefox/addon/old-reddit-re...

And if you're signed in you can opt out of the new site (Preferences > Opt out of the redesign)

Re: Don't use third party auth to sign in

#77
post #65

Earlier quoted context omitted.

For those that don't want to pay, Yandex allows you to set up a number of emails using your own domain for free.

The only thing worse I can think than having Google read your email is having Yandex read it.

The issue here isn't privacy but independence from a specific provider. If privacy is an issue as well then you should be using encryption as emails are not private.

Re: Don't use third party auth to sign in

#78
post #39

Earlier quoted context omitted.

$6/month doesn't sound like much... Till you realise you'll probably have this setup for 20 years, and suddenly it's $1200. That's a lot to protect against a thing that will probably not happen (account being banned)

> That's a lot to protect against a thing that will probably not happen (account being banned) $1,200 is a lot of money, but... anyone aged 23+ is older than Google. 17+ is older than GMail. It is an illusion to say we know what will or will not happen to Google over the next 20 years. We don't know how entrenched the tech giants are over decades because we've never had anything like them before. This is a problem th…

> It is an illusion to say we know what will or will not happen to Google over the next 20 years. We don't know how entrenched the tech giants are over decades because we've never had anything like them before.

Realistically we have little control or have any clue on what's going to happen a few years out in almost every aspect of life.

Look at Kodak (the photography company). They were around for over a 100 years, then digital photography came along to disrupt their market and they pretty much disappeared in a few months.

Kodak and Google aren't that different as being a company that offers a service that tons of folks use(d). Kodak used to be "the" place to buy film and get photos developed.

I'm all for controlling your own email (even tho I'm guilty of not doing so), but I think even if you controlled your own email, you'll still be victim of the company you're using maybe going out of business in the future. I wish nothing but success for Fastmail or any other email service that lets you control your email, but if they go down then you're in the same position as Google going down while using gmail.

Re: Don't use third party auth to sign in

#79
post #64

Good point, but if Google suspends my account I've got bigger things to worry about than the dozens of sites I've used once or twice a year. Paying for your own domain also comes with its own troubles. If you're not using Google (or some other service) as your mail forwarder, good luck being able to email anyone. Stealing you custom domain is also a real possibility, and negates your investment in Gmail 2FA.

How could my domain be stolen? :O

Social engineering attack on your domain registrar, court order, choosing a domain controlled by a dodgy registar.

There's actually quite a few ways.

Re: Don't use third party auth to sign in

#80
I also think it can be the other way round too. Like I use this amazing app called Smart youtube player that works best if you sign in with your YouTube id. Now this app breaks some rules like skipping ads which may voilate their Tos which can put your account in jeopardy also.
Post reply on HN