Live data from Hacker News

Sign in with Google in Chrome

underpassapp.com

91–100 of 313 posts

Re: Sign in with Google in Chrome

#91
post #80
post #78

Kinda related to this: I _really_ wish that SSO providers would be better about telling me when my account was already used to log into a service. When I hit "sign in with Google", see my 4 accounts, and have to guess which one I used to sign into the service... Maybe I'm missing some security detail here

The problem is that at that point in the flow, it's owned by the SSO provider. The SSO provider can't know with certainty what account has an active account with the website.

I don't think that's true though? The OAuth provider knows which third parties you have authorized to have access to your account(s) as well as what information or privileges you've approved for each. And when you land on that screen, they know which third party referred you to them.

In other words, they could definitely highlight or otherwise hint to you which of the Google accounts you've already approved/used via one or more of your authenticated Google accounts.

Re: Sign in with Google in Chrome

#92
post #90

Earlier quoted context omitted.

I would never visit a site like pornhub in a profile that I was logged in to anything other than similar sites. note: I'm not excusing the feature but come on! Have some common sense before visiting a site like that? The place I hate the popup the most is mobile. It comes up moments (0.5 to 2 seconds) after the site loads (say tripadvisor) which means it's possible accept it by accident as it appears under your finge…

> I'm not excusing the feature but come on! Have some common sense before visiting a site like that? For sure… but there’s a self-fulfilling element there. If no one with common sense would ever use the feature… why add the feature?

As I said above, the feature is super useful to people who want to "login with Google" so plenty of people with common sense would "use the feature".

The common sense part is it's common sense, at least to the HN crowd, to not visit a site like pornhub using your main profile, or so I would have expected.

Re: Sign in with Google in Chrome

#93
post #12

Does nobody find this intrusive when it appears on sites like pornhub? Of all places where I'd sign in with a Google account... holy heck, I was very surprised they chose to let Google do that nearly-fullscreen popup on their site upon every visit (since you visit in private tab, it's a fresh session every time) Even on reddit it annoys the heck out of me and I was very surprised they let this third party ruin the ex…

their "private" is not private. about a month ago, i searched for some health-related stuff in a chrome incognito window and then immediately afterwards got related sponsored product ads on amazon in a logged in normal window.

Re: Sign in with Google in Chrome

#94
post #63

Earlier quoted context omitted.

…until the user loses access to their Google account with no recourse and you have no secondary way to authenticate them.

Also true if I use my gmail address. I'll confess that for many websites I don't care that much. Depending on a password manager would be better, though. Semi-related anecdote: I lost my Reddit account to a cryptocurrency spammer due to a weak password and had to create another, so I lost my preferred username. Annoying but not a huge deal. (Reddit did freeze the old account but wouldn't give it back.)

No. You just cant password reset if you lose access to email. You can still log in.

Re: Sign in with Google in Chrome

#95
post #33

Earlier quoted context omitted.

Can we block sharing email addresses by default? It seems every time I sign in with Google the site / app starts SPAMming me without my consent. It's pretty much why I don't use it: The SPAM.

That's you/OAuth giving the provider your google account id, which is your @gmail.com email.

I don't generally want any site to have anything they can use that associates me with other sites. If 2 sites get the same email for me or the same GAIA id, or the same anything then I won't use the id system. (with obvious exceptions - see below)

This includes "privacy first" companies like Apple and their Apple Pay system where I went to a restaurant in SF. The bill was a QR code that took me to Toast with the option to pay via Apple Pay. The apple prompts told me my email address would be shared and there was no option to say "no" so I bailed out and paid the waiter directly.

Sometimes I need my real name and address for shipping. In those cases that can't be helped. I also have to give my CC card for a purchase. But there are sites I want to sign up for for which I don't need to give that info. A "one click to sign up" option would be useful if I knew it was giving random data. An example might be medium.com or substack.com. They don't need my real name nor do they need my "real" email. If I was sure this "one click sign up" didn't share a common one I'd consider using it.

Maybe even better, if it was managed similar to subscriptions in iOS where I could trivial revoke any membership at will from a central location, with the understanding that there'd be no recovery since signing up again would get random new data and so no way to associate the new with the old.

Re: Sign in with Google in Chrome

#96
post #12

Does nobody find this intrusive when it appears on sites like pornhub? Of all places where I'd sign in with a Google account... holy heck, I was very surprised they chose to let Google do that nearly-fullscreen popup on their site upon every visit (since you visit in private tab, it's a fresh session every time) Even on reddit it annoys the heck out of me and I was very surprised they let this third party ruin the ex…

I would never visit a site like pornhub in a profile that I was logged in to anything other than similar sites. note: I'm not excusing the feature but come on! Have some common sense before visiting a site like that? The place I hate the popup the most is mobile. It comes up moments (0.5 to 2 seconds) after the site loads (say tripadvisor) which means it's possible accept it by accident as it appears under your finge…

I wouldn't visit it without tails at this point. But I go for the better option than tails. Just dont visit it!

Re: Sign in with Google in Chrome

#97
post #80
post #78

Kinda related to this: I _really_ wish that SSO providers would be better about telling me when my account was already used to log into a service. When I hit "sign in with Google", see my 4 accounts, and have to guess which one I used to sign into the service... Maybe I'm missing some security detail here

The problem is that at that point in the flow, it's owned by the SSO provider. The SSO provider can't know with certainty what account has an active account with the website.

They could thought right? because if you login to a website (that's passed along an ID) then you would have that bit set.

I don't need to know for certain the account on the receiving side exists, just that I have signed in before with it. Facebook does this at least!

Like "has an account" isn't possible without leakage, but "has logged in through this flow before" (hell, stick timestamps in there too!) does.

One thought though: your SSO provider has that account list, but often prompts a re-login. So it could be that your SSO provider account picker _doesn't have access to your account information fully either_.

Re: Sign in with Google in Chrome

#98
post #81

Earlier quoted context omitted.

> Name and Email Yes, both are PII, which is highly regulated in EU and CA (among others I'm sure). If these knowingly "leaked" in a data breach, the company which leaked them would be legally obligated to notify me. Sounds pretty serious to me.

[flagged]

> inarguably much more impactful a privacy issue

Except, you know, the volume of users impacted.

Tea had a few tens of thousands of users. Google has billions.

Re: Sign in with Google in Chrome

#99
post #12

Does nobody find this intrusive when it appears on sites like pornhub? Of all places where I'd sign in with a Google account... holy heck, I was very surprised they chose to let Google do that nearly-fullscreen popup on their site upon every visit (since you visit in private tab, it's a fresh session every time) Even on reddit it annoys the heck out of me and I was very surprised they let this third party ruin the ex…

There's a big upside to Google One Tap. It makes users sign up for your product like crazy. I recently added it to a SaaS web app I'm working on, and the number of new sign ups went up 8x overnight. You don't necessarily have to create an account to use the minimal functionalty of our app, but after signing up you do get some perks, and we get a way to communicate with the user through email. So I think it can be ben…

Do they pay for anything? I'm all for reducing login friction. But that popup is like people that accost you in the street trying to enlist you into their cult.

Re: Sign in with Google in Chrome

#100

Earlier quoted context omitted.

Also true if I use my gmail address. I'll confess that for many websites I don't care that much. Depending on a password manager would be better, though. Semi-related anecdote: I lost my Reddit account to a cryptocurrency spammer due to a weak password and had to create another, so I lost my preferred username. Annoying but not a huge deal. (Reddit did freeze the old account but wouldn't give it back.)

No. You just cant password reset if you lose access to email. You can still log in.

The email is ultimately the second factor that lets you make important changes to the account in many cases. For example, changing your password. It's more important than the password in nearly every security critical account I have.
Post reply on HN