Earlier quoted context omitted.
> I'd extend this even further: never use a single account for more than one purpose. Create a separate account at the same company for the other purpose. This should really go without saying. I’m sometimes shocked at the extent to which it has become normalized to mix up one’s personal accounts with work. I can’t count the number of times a colleague accidentally sent me an email using their personal account, or tex…
Firm agree on mixing work/personal contexts. However, in practice, using "Sign in with Google" by default dramatically increases resilience to most failure modes for almost everyone without a sophisticated threat model. > To save what? An additional password? The average person does not manage their passwords in a sophisticated way; if someone is signing up for many different services, they are probably using the sam…
This is completely the case, and at least from my experience the reality is worse than what is often believed: people don’t have distinctions between websites.
i.e. if a layman registers john@cool-website.invalid:correctStaple, and then they open another-sitename.invalid the other day, and presented with login screen, his intuition will be “john@.:correctStaple has to work”, because that’s what he “entered” yesterday.
Federated sign-in solves this by allowing users to use coherent id:password string for any login page without having to have distinctions between domains.