Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

81–90 of 544 posts

Re: Don't use third party auth to sign in

#81
post #64

Good point, but if Google suspends my account I've got bigger things to worry about than the dozens of sites I've used once or twice a year. Paying for your own domain also comes with its own troubles. If you're not using Google (or some other service) as your mail forwarder, good luck being able to email anyone. Stealing you custom domain is also a real possibility, and negates your investment in Gmail 2FA.

How could my domain be stolen? :O

- does you registrar have physical office? is it in a country with legislation friendly towards the country you're based in?

- does your registrar send Auth-Info code over email in plain text?

- did you enter real contact and residence data when registering the domain including public WHOIS database?

This is only a fraction of the attack vector.

Re: Don't use third party auth to sign in

#82

Earlier quoted context omitted.

I pay for gsuite for myself and a couple of my domains. Call it $12/month, because you'll want to setup two accounts: * The admin-user. * The daily/real-user. In my case I have my real account "steve@steve..", and "admin@steve" which is the gsuite administrator. I only login to make changes to the domain setup, never to send/receive email. It's annoying to have to pay for that second user, but I feel happier with the…

Why not me@steve, iam@steve, thisis@steve, thereal@steve or any of the other variants?

I find it strange to send someone an email and address it to "me". Autocompletion may also help when typing steve instead of "thereal".

Re: Don't use third party auth to sign in

#83

Good point, but if Google suspends my account I've got bigger things to worry about than the dozens of sites I've used once or twice a year. Paying for your own domain also comes with its own troubles. If you're not using Google (or some other service) as your mail forwarder, good luck being able to email anyone. Stealing you custom domain is also a real possibility, and negates your investment in Gmail 2FA.

Running a mailserver is something that doesn't just work out of the box, but it's not true that it's impossible to run a relatively reliable email service. Takes a bit of work, for sure. But it's the best and biggest federated network we have at the moment. Your custom domain can be secured by 2FA as well, if one is using a reputable registrar, and you can legally own it. So even if it's stolen, there is recourse.

I really don't enjoy this giving up on online sovereignty, just because of the convenience and some quasi-monopolists.

And I say that as someone who has very few accounts at any online-services (if avoidable, I'm not a fundamentalist, after all I am posting here right now) and runs mailserver (and cloudstorage and more). So I'm aware it's not all rainbows and unicorns, and I appreciate this is something that takes the skills and time that not everyone is willing to invest. Nor should they.

But one's own "domain" (in the DNS and also the territorial sense) is something that enables some freedom in a world where power is increasingly being concentrated und surveillance is becoming so ubuquitous.

Re: Don't use third party auth to sign in

#84
post #64

Good point, but if Google suspends my account I've got bigger things to worry about than the dozens of sites I've used once or twice a year. Paying for your own domain also comes with its own troubles. If you're not using Google (or some other service) as your mail forwarder, good luck being able to email anyone. Stealing you custom domain is also a real possibility, and negates your investment in Gmail 2FA.

How could my domain be stolen? :O

Phishing or bribing an employee at a domain registrar. Phishing you to get your password and then bribing or social-engineering someone at the phone company to forward your SMS-based 2FA codes to them. Waiting for you to forget to renew your domain and then registering it.

Re: Don't use third party auth to sign in

#85

Earlier quoted context omitted.

I pay for gsuite for myself and a couple of my domains. Call it $12/month, because you'll want to setup two accounts: * The admin-user. * The daily/real-user. In my case I have my real account "steve@steve..", and "admin@steve" which is the gsuite administrator. I only login to make changes to the domain setup, never to send/receive email. It's annoying to have to pay for that second user, but I feel happier with the…

Are you actually the owner of steve.com? Because I've been ordering Dominos pizza with the email steve@steve.com for years. Edit: nevermind. I see you own the .net tld. I've definitely used that to order pizza too. Sorry about that.

I registered steve.org.uk in 1999, and steve.fi last year.

(I moved from UK to Finland, so I checked the .fi version on a whim. Luckily it was due to expire a few months after I checked, so I setup a script to register it the moment it became available.)

Re: Don't use third party auth to sign in

#86
post #6

Has anyone else noticed random popups on 3rd party websites asking for google sign in? I even used firefox when it happened: https://imgur.com/a/JC52lBV (lequipe.fr) https://imgur.com/a/VSM3Uk9 (reddit.com) https://imgur.com/a/KpVCYBL (medium.com)

I never see these. I wonder if it’s because I have ublock properly configured or because I block third party cookies or because I never sign in to Google on my main browsing profile.

Re: Don't use third party auth to sign in

#87
post #72

Earlier quoted context omitted.

Are you actually the owner of steve.com? Because I've been ordering Dominos pizza with the email steve@steve.com for years. Edit: nevermind. I see you own the .net tld. I've definitely used that to order pizza too. Sorry about that.

Couldn't you use @example.com?

That's a really good idea! I'll try it next time.

Re: Don't use third party auth to sign in

#88
post #65

Earlier quoted context omitted.

The only thing worse I can think than having Google read your email is having Yandex read it.

The issue here isn't privacy but independence from a specific provider. If privacy is an issue as well then you should be using encryption as emails are not private.

It doesn't have to be fully trusting or not at all, there's different levels. I think using a provider you trust more (In my case Fastmail vs. Google) is a fair tradeoff. Fastmail has a pretty straight forward business model that makes sense to me so I feel like they don't have a reason to scan my emails for ad purposes or else.

Of course if you are worried about some nation state looking into your emails you should encrypt them and use whatever provider.

Re: Don't use third party auth to sign in

#89

Earlier quoted context omitted.

Yeah but they’ve still got your emails.

There are alternatives to GSuite -- for instance, Fastmail. Or even the old PObox.com service which has been around since the 90s and is really cheap (Fastmail have bought it now, I notice).

Also, many registrars offer a managed email service.

Re: Don't use third party auth to sign in

#90
post #51

Earlier quoted context omitted.

This is such excellent advice that I wrote a detailed step-by-step instruction guide for people that don't know how to do precisely that: https://sneak.berlin/20201029/stop-emailing-like-a-rube/ It even has special instructions about how to secure the domain registration and DNS accounts. :) (Don't use G Suite, though.)

I have attempted to read two articles on your site. As I am a privacy-focused person the articles were of interest to me. Both times I haven't gotten past reading the opening sentences when an obnoxious pop-up appeared asking for my email address. It seems ironic that someone publishing articles on privacy advocacy would be so keen to collect my email address. This practice also creates a real miserable experience an…

[deleted]
Post reply on HN