3 ms·
I quite like the "phone as hardware token" via Webauthn as 2FA. However, I've never used "Sign in with Google" and the likes because I don't want all the sites
by bertman 4y ago
I quite like the "phone as hardware token" via Webauthn as 2FA.
However, I've never used "Sign in with Google" and the likes because I don't want all the sites I'm using to get my "real" email address.
So I really hope Google et. al. will offer some kind of email address cloaking like Apple do with their private relay stuff.
Knowing Google, they sure as heck won't, though.
- matja 4y agoIt's depends on the site that uses OpenID Connect federated sign-in if they ask for your email address from the identity provider. An application/site can optionally request the "email" scope during OpenID Connect sign-in, but if it is not requested (only the "openid" scope instead) then the provider must not return an email address in the ID token, or an OAuth access token which is authorized for an API method which returns the user's email address (OpenID Connect Core 1.0 section 5.4 - "Requesting Claims using Scope Values"). Google implement this (https://developers.google.com/identity/protocols/oauth2/openid-connect#an-id-tokens-payload https://developers.google.com/identity/protocols/oauth2/open...), by returning only a unique numeric user ID in the returned id_token. I haven't checked other OpenID Connect providers.
- bertman 4y agoThanks! This is great info. I didn't know the details about different scopes and had always assumed the sites would obtain at least the name and email address, because all I ever saw was the prompt "To continue, Google will share your name, email address, language preference, and profile picture with <site>."