Live data from Hacker News

Ask HN: Google SSO or Password Manager?

news.ycombinator.com

11–20 of 64 posts

Re: Ask HN: Google SSO or Password Manager?

#11
post #9

1. Email on your own domain. You can still use Google (or any other service) for this, but having your own domain means you're not dead in the water if your provider decides they don't like you. 2. For accounts on large websites (big targets) use a unique email address that is only used on that website. Obviously passwords should never be reused, which leads to: 3. Password manager. Just do it. 4. Use the highest sec…

> Email on your own domain. You can still use Google (or any other service) for this, but having your own domain means you're not dead in the water if your provider decides they don't like you.

And if you give up your domain then someone just have to buy it and use the "forgot password" option :D

Re: Ask HN: Google SSO or Password Manager?

#12
post #9

1. Email on your own domain. You can still use Google (or any other service) for this, but having your own domain means you're not dead in the water if your provider decides they don't like you. 2. For accounts on large websites (big targets) use a unique email address that is only used on that website. Obviously passwords should never be reused, which leads to: 3. Password manager. Just do it. 4. Use the highest sec…

Note that email on your domain opens you up to a different sort of risks along the lines of domain hijacking / registrar account takeover. However, if you pick a good registrar you should be okay, and also there are commercial/legal remedies available.

Re: Ask HN: Google SSO or Password Manager?

#13
post #9

1. Email on your own domain. You can still use Google (or any other service) for this, but having your own domain means you're not dead in the water if your provider decides they don't like you. 2. For accounts on large websites (big targets) use a unique email address that is only used on that website. Obviously passwords should never be reused, which leads to: 3. Password manager. Just do it. 4. Use the highest sec…

A lot of orgs will (for security reasons) treat your Google OAuth login, and a email+password login as two distinct accounts, even if they are on the same email address.

So it is possible that if Google shuts your account, and you migrate your email to a different provider - you will still lose access to your service account.

Re: Ask HN: Google SSO or Password Manager?

#14

You can have many copies of your password manager database in many places, but you have only one Google. If you lose one thing, what would you rather lose? If you lose a password database, restore a backup. If you lose access to Google, what then? You can't restore a backup of Google. Stick around HN long enough, and within a week, you'll read stories of people losing access to their Google accounts for unexplained r…

Wow. I need to google this. Never seen any of those stories. Thanks.

Re: Ask HN: Google SSO or Password Manager?

#15
post #11
post #9

1. Email on your own domain. You can still use Google (or any other service) for this, but having your own domain means you're not dead in the water if your provider decides they don't like you. 2. For accounts on large websites (big targets) use a unique email address that is only used on that website. Obviously passwords should never be reused, which leads to: 3. Password manager. Just do it. 4. Use the highest sec…

> Email on your own domain. You can still use Google (or any other service) for this, but having your own domain means you're not dead in the water if your provider decides they don't like you. And if you give up your domain then someone just have to buy it and use the "forgot password" option :D

You do have some additional management overhead, but a good registrar will bug you well before your domain expires if they aren't able to auto renew it for some reason. You also have a 30 day grace period after it expires before someone else grabs it.

Re: Ask HN: Google SSO or Password Manager?

#16
post #9

1. Email on your own domain. You can still use Google (or any other service) for this, but having your own domain means you're not dead in the water if your provider decides they don't like you. 2. For accounts on large websites (big targets) use a unique email address that is only used on that website. Obviously passwords should never be reused, which leads to: 3. Password manager. Just do it. 4. Use the highest sec…

A lot of orgs will (for security reasons) treat your Google OAuth login, and a email+password login as two distinct accounts, even if they are on the same email address. So it is possible that if Google shuts your account, and you migrate your email to a different provider - you will still lose access to your service account.

Well, that's one reason why using Google SSO wasn't on my list of things to do.

Re: Ask HN: Google SSO or Password Manager?

#18
post #2

I would choose a password manager. With Google SSO you will always be dependent on their services, if they get down, they get hacked (which is very unlikely at the moment, but things might change) or someone compromises your google account you will be lost.

Are there big email providers, maybe paid, where potentially should be more reliable. Meaning at least they have a customer-service and you will not get locked out by the script?

Re: Ask HN: Google SSO or Password Manager?

#19
The other comments do a good enough job explaining why not SSO.

I'm a very happy 1Password customer, but put in the place of answering what you should really do: self-hosted BitWarden. Geo- and vendor-redundancy, local hard backup.

Whatever you do, don't use the Chrome password manager.

Post reply on HN