3 ms·
Firm agree on mixing work/personal contexts. However, in practice, using "Sign in with Google" by default dramatically increases resilience to most failure mod
by twright0 5y ago
Firm agree on mixing work/personal contexts.
However, in practice, using "Sign in with Google" by default dramatically increases resilience to most failure modes for almost everyone without a sophisticated threat model.
> To save what? An additional password?
The average person does not manage their passwords in a sophisticated way; if someone is signing up for many different services, they are probably using the same password everywhere, or some simple enumeration scheme. Then, when some random forum or web service gets compromised (as they inevitably are), their password to everything is compromised - including Google! On the opposite end of the spectrum, if Google is the only service with a password, and everything else is driven by Google-owned SSO, that person is essentially immune to compromise; whatever I think about the company, I do believe in Google's security team to keep passwords safe and block dictionary attacks more than any other service on the internet.
And while we can evangelize setting up password managers and using strong random passwords everywhere, the truth of the matter is that many people simply cannot accomplish this. "Sign in with {Google, Facebook, Microsoft}" gets them 95% of the benefit at much higher reliability.
- ximeng 5y agoUsing Google SSO is fine unless Google arbitrarily closes your account with no recourse.
- twright0 5y agoStrongly agree! And if Google closing your account is a big part of your threat model, that's something to hedge against. But I suspect that for the average consumer - people using their gmail to send and receive emails, and doing stuff like watching Youtube and installing Android apps - the odds of that are quite small, especially if they don't have a business or developer context associated with their personal gmail. Account loss/takeover due to password re-use is a much bigger threat for the average person.
- numpad0 5y ago> if someone is signing up for many different services, they are probably using the same password everywhere, or ... This is completely the case, and at least from my experience the reality is worse than what is often believed: people don’t have distinctions between websites. i.e. if a layman registers john@cool-website.invalid:correctStaple, and then they open another-sitename.invalid the other day, and presented with login screen, his intuition will be “john@.:correctStaple has to work”, because that’s what he “entered” yesterday. Federated sign-in solves this by allowing users to use coherent id:password string for any login page without having to have distinctions between domains.