Live data from Hacker News

Sign in with Google in Chrome

underpassapp.com

81–90 of 313 posts

Re: Sign in with Google in Chrome

#81
post #11

Earlier quoted context omitted.

[flagged]

> Name and Email Yes, both are PII, which is highly regulated in EU and CA (among others I'm sure). If these knowingly "leaked" in a data breach, the company which leaked them would be legally obligated to notify me. Sounds pretty serious to me.

[flagged]

Re: Sign in with Google in Chrome

#82
post #12

Does nobody find this intrusive when it appears on sites like pornhub? Of all places where I'd sign in with a Google account... holy heck, I was very surprised they chose to let Google do that nearly-fullscreen popup on their site upon every visit (since you visit in private tab, it's a fresh session every time) Even on reddit it annoys the heck out of me and I was very surprised they let this third party ruin the ex…

I would never visit a site like pornhub in a profile that I was logged in to anything other than similar sites.

note: I'm not excusing the feature but come on! Have some common sense before visiting a site like that?

The place I hate the popup the most is mobile. It comes up moments (0.5 to 2 seconds) after the site loads (say tripadvisor) which means it's possible accept it by accident as it appears under your finger. Your info is immediately shared so there is no way to recover. You're effed.

I means sure, I hate it on desktop too, but on mobile it's directly on top of the content and so more likely to be accepted by accident. IIRC you can turn this off in your Google account (or maybe only Google Workspace?)

Note that I hate it for other reasons too. There's no reason Apple/Firefox/Microsoft/Meta and any other major id providers couldn't offer this too. But if they did, then you'd see 5 of these show up [Sign in with Google], [Sign in with Apple], [Sign in with Facebook], [Sign in with Microsoft], [Sign in with Firefox]. So in other words, this seems like a tragedy of the commons in progress.

To steelman the feature though, easily sign up and easy login would be super convenient if that's what I wanted. It might be nice for a Web API that made this more privacy focused (or maybe that already exists). But yes, I'd like to see Google's specific popup disappear - be banned.

Re: Sign in with Google in Chrome

#83
I get why Google finds this advantageous, but I don’t understand why so many brands want to willingly diminish the impression and reputation of their web properties by adding “Sign in with Google.”

Re: Sign in with Google in Chrome

#84
post #80
post #78

Kinda related to this: I _really_ wish that SSO providers would be better about telling me when my account was already used to log into a service. When I hit "sign in with Google", see my 4 accounts, and have to guess which one I used to sign into the service... Maybe I'm missing some security detail here

The problem is that at that point in the flow, it's owned by the SSO provider. The SSO provider can't know with certainty what account has an active account with the website.

And I don't think it makes sense for the SSO provider to leak a list of all your accounts to the website either. That being said, I think the SSO provider could maybe track that information maybe?

Re: Sign in with Google in Chrome

#85
post #21

The Chrome experience is actually part of a new standard, Federated Credential Management (or FedCM for short). The idea is to create a browser mediated login experience that gives the identity provider and web app what they need without being able to correlate requests across the Internet. I am working on an article on this topic. If you are interested in learning more, here's a video from a recent auth focused conf…

Is this a successor to Mozilla's old Persona project, or similar in anyway?

Re: Sign in with Google in Chrome

#86
post #5

This popup should be criminal. Ive misclicked the signin button multiple times, causing PII to be sent to a third party I dont trust without my authorization.

Don't worry about misclicks, Google already tracked your visit when the webpage was loaded. Google One Tap works via a script tag from Google servers: https://developers.google.com/identity/gsi/web/guides/displa...

[deleted]

Re: Sign in with Google in Chrome

#87
post #63

Earlier quoted context omitted.

There's a big upside to Google One Tap. It makes users sign up for your product like crazy. I recently added it to a SaaS web app I'm working on, and the number of new sign ups went up 8x overnight. You don't necessarily have to create an account to use the minimal functionalty of our app, but after signing up you do get some perks, and we get a way to communicate with the user through email. So I think it can be ben…

…until the user loses access to their Google account with no recourse and you have no secondary way to authenticate them.

Also true if I use my gmail address. I'll confess that for many websites I don't care that much. Depending on a password manager would be better, though.

Semi-related anecdote: I lost my Reddit account to a cryptocurrency spammer due to a weak password and had to create another, so I lost my preferred username. Annoying but not a huge deal. (Reddit did freeze the old account but wouldn't give it back.)

Re: Sign in with Google in Chrome

#88
post #63

Earlier quoted context omitted.

…until the user loses access to their Google account with no recourse and you have no secondary way to authenticate them.

I personally have my personal email as Google account email, so even when I lose my access to google I am still in control of my domain (and email).

And still couldn't sign-in-with-google. On an email linked that way, so no password recovery. Would likely be a new account - with bonus "that address is already in use" problem.

Re: Sign in with Google in Chrome

#89
post #83

I get why Google finds this advantageous, but I don’t understand why so many brands want to willingly diminish the impression and reputation of their web properties by adding “Sign in with Google.”

>want to willingly diminish the impression and reputation of their web properties

because that's not what happening. The average Chrome user finds that feature useful, and personally I have to agree because having a sign-in option through the browser chrome (the non-content portion of the application, bad name in this case) is significantly more sane from a security standpoint than trusting the webpage operator.

why are these threads always full of performative indignation by people who know perfectly well that 99% of people aren't going to be upset

Re: Sign in with Google in Chrome

#90
post #12

Does nobody find this intrusive when it appears on sites like pornhub? Of all places where I'd sign in with a Google account... holy heck, I was very surprised they chose to let Google do that nearly-fullscreen popup on their site upon every visit (since you visit in private tab, it's a fresh session every time) Even on reddit it annoys the heck out of me and I was very surprised they let this third party ruin the ex…

I would never visit a site like pornhub in a profile that I was logged in to anything other than similar sites. note: I'm not excusing the feature but come on! Have some common sense before visiting a site like that? The place I hate the popup the most is mobile. It comes up moments (0.5 to 2 seconds) after the site loads (say tripadvisor) which means it's possible accept it by accident as it appears under your finge…

> I'm not excusing the feature but come on! Have some common sense before visiting a site like that?

For sure… but there’s a self-fulfilling element there. If no one with common sense would ever use the feature… why add the feature?

Post reply on HN