15 ms·
Sign in with Google has been removed for your privacy
- jensenbox 4y agonit: on their reasoning page: - non-existant should be non-existent
- exabrial 4y ago> We wanted to prove that it was possible to deliver an amazing user experience while bucking the trend of JavaScript-heavy bullshit web apps. Preach
- phendrenad2 4y agoIf the goal is protecting users from themselves, the owner should go the extra mile and reject signups with @gmail/@outlook emails, to gently encourage them not use services that don't value their privacy.
- ectospheno 4y agoI left google. After half a year I have received dmarc reports from a site other than google just once. So did it matter if 99% of people I email are still using google? They have every email I have sent anyway.
- mayankkaizen 4y agoThis post gives me an opportunity to ask a question. What if I am locked out of my gmail id? Would I be able to use services, such as Github or Pocket, which I log in through gmail id?
- Sunspark 4y agoIt depends on the service. Github lets you add a backup email address to manage password resets, etc.
- emodendroket 4y agoI can take care of myself, thanks.
- robomartin 4y agoNever use Google anything for --including login-- for anything important. The company continues to cause damage to people and businesses through their customer-no-service stance regarding accounts, their suspension or cancellation. I know people who's small businesses suffered a great deal of damage because of this. Talk about a need for a congressional hearing! Besides, single sign-on is a security disaster. In an ideal world every single login you have should have a different user ID and password. I do my best to approach this. Of course, you have to rely on password management software to be able to do this. There is no such thing as absolute security. However, making every login ID and pwd different goes a long way towards ensuring you don't experience a chain reaction of breaches because someone hacked into one account. Yes, the password manager could be considered to be the weak point then. Encryption and a long and secure password are the keys there. And, if you can, one that is accessible online.
- robomartin 4y agoCorrection: is not accessible online
- ams92 4y agoCouldn't disagree more. Password managers have the same single point of failure that an SSO would. The only difference is that you can't automate onboarding/offboarding of an employee's SaAS applications.
- deleted 4y ago[deleted]
- system2 4y agoWho is slimvoice.co and why do we even care about their opinions or reasonings?
- scarmig 4y agoEncouraging worse security practices (dumping SSO for password logins) for an ideological goal that helps no one's privacy.
- elric 4y ago* There is nothing wrong with password logins if they are used properly. * Google does not have a good track record of customer service, not putting all your eggs in their unreliable basket seems like a good idea from a security point of view. * The privacy argument is a bit of a hot take in this case, and is probably not as valid as a reason to dump Google SSO as eggs-in-unreliable-basket argument.
- toomuchtodo 4y agoPasskeys becoming prevalent makes dropping BigTech SSO for personal use more palatable. Google will still store and sync the keys for users of Android and Chrome, but their code won’t run on sites who opt out of Login with Google. It’s an evolution of the security model. This is arguably superior considering the ability to migrate passkeys elsewhere. You have improved sovereignty over your auth story (versus “haha google locked you out of everything and you have no recourse”). TLDR PKI > consumer federated identity
- jefftk 4y agoI use a hardware security token to log into my Google account and then use that to log in to several other services. If I were to lose my token, I would still have my backup tokens, and could update this account to use a new token and unenroll the old token. If instead, every site I had ever logged into kept track of my tokens I would need to visit each of them and do the same thing. (It's already messier than that because some accounts I have--GitHub and Facebook--don't accept SSO but are important enough to be worth protecting with hardware tokens. But I don't want to go farther in this direction!)
- toomuchtodo 4y agoWe’re not talking a loss of a hardware authenticator, we’re talking the loss of access to your Google account. Worst case with passkeys is you lose access to the cloud corpus of your keys due to loss of account access while still having them on your device (and/or a passkey manager).
- sys42590 4y agoWhy do they argue with privacy? If Google decides to lock your account for any reason, all your third party accounts using Google's SSO are mostly fubar, as it's currently almost impossible to get your Google account back.
- gs17 4y agoNot just Google themselves, I still use my old university email and they decided recently ("for security") to block using it to log in to other sites, along with a million other things, so their own staff can't even open Search Console. Fortunately, a lot of them allow "forgot my password" to go to email if you can't login through Google, but a few required new accounts.
- llanowarelves 4y agoI have the same problem with Tailscale only supporting providers
- emodendroket 4y agoI judge the likelihood of this happening rather low and, anyway, considering how many services don't let you change your e-mail address, what's the difference?
- tlogan 4y agoThis website does not have any information about owners or legal entity behind it. Who is running this? What is their physical address? Where are they registered? Honest question: how do I know and verify they really care about privacy and they are not one doing shady things? This is really honest question. How can anybody trust that company x care about privacy without even know anything about company x?
- jchw 4y agoWhen it comes to SaaSes, absolutely nothing. It's all social. Even knowing the owners doesn't give you much more assurance that it's legit, unless they're very well known. That said, most liars are really really bad at lying. "We care about your privacy! Now let us load 1000 tracking libraries, kthxbai" is pretty easy to spot. I think the scarier case is when dealing with a government adversary. They're simply not as stupid, and you never know when it could happen: https://archive.ph/rI8mE https://archive.ph/rI8mE For those cases, I get unnerved when things seem too good to be true. If I didn't know former Mullvad employee(s), I'd be deeply concerned about them, too.
- jefftk 4y agoI'm curious what happened for people who had existing accounts configured with Google SSO...
- chrisbolt 4y agoIt says on the page: Sign in with Google has been removed for your privacy. Click here to create a password for your account.
- jgalt212 4y agoHow many sites are out there with a "Sign In with Google" form that solely exists to harvest peoples' Google credentials?
- HaZeust 4y agoThat's not how OAuth works, which is what "Sign In with Google" utilizes. In order to Sign In with Google through a third-party software, Google and the third-party software must both agree to the arrangement. In the event they do, the third-party software adds a Google Sign In flow to their software, whereas their users can press a call-to-action for signing in with Google, which would trigger an opening of a separate Google-owned domain in a new min-browser window that the third-party software cannot access (and therefore not harvest information from). This min-window then sends the user back to the third-party software domain upon completion with an authentication token - which could be in the form of a URL query string, an HTTP method, a cookie, or even collection of arbitrary browser information for fingerprinting. The third-party site then sends that authentication token back to Google via their API, and Google sends back ONLY what that authentication token is permitted to grant access to - which would not be Google credentials.
- jgalt212 4y agoYes, that's the way it works. But what's stopping a bad actor from putting up a bogus "Sign in with Google" form on their website solely to harvest credentials?
- joshuamorton 4y agoWhat credentials could they harvest? If I'm asked to sign in with google via oauth, I never type in my password (or username!).
- funstuff007 4y agotrue, but that's only the case if you're currently authenticated with Google. Not true after deleting cookies and/or local storage. But more importantly, less savy tech folks might not be aware that they should not have to re-enter credentials if they have recently logged into gmail or other google owned services.
- tagawa 4y agoAside from the privacy improvement, what a beautifully functional site.
- flas9sd 4y agoindeed, the about page also is not your usual legal boilerplate either
- Crono 4y agoThe developer made a nice article on how he did it with almost none javascript. Interesting read: https://javascript.works-hub.com/learn/a-javascript-free-frontend-61275 https://javascript.works-hub.com/learn/a-javascript-free-fro...
- b0afc375b5 4y agoThanks for the link. I read it and I too desire for minimal/javascript-less world. However, > The Checkbox/Label Trick I'm hesitant to use this. It just doesn't feel right to use this hack. Also somewhat related to the <details>/<summary>, I try using native html elements as much as possible. One time I used the <meter> element for a meter bar, but it was called out immediately by QA because the design doesn't match the one created by the UI/UX team. I really wish html elements were more customizable.
- charcircuit 4y agoThis doesn't increase anyone's privacy Before: When signing up with Google the owner gets your name, email, and profile picture After: When signing up without Google the owner gets your name and email, but the owner can make an API request to get your profile picture. In both scenarios the same amount of information is accessible by the site.
- svnpenn 4y ago
- CharlesW 4y agoWhat does that have to do with this site?
- Barrin92 4y agoThat is literal misinformation. (https://support.google.com/mail/answer/6603?hl=en https://support.google.com/mail/answer/6603?hl=en) "When you open Gmail, you'll see ads that were selected to show you the most useful and relevant ads. The process of selecting and showing personalized ads in Gmail is fully automated. These ads are shown to you based on your online activity while you're signed into Google. We will not scan or read your Gmail messages to show you ads." Also assuming it was true, if you deny people the Google Sign-in they will simply use their Gmail address next, so you'd have actually increased usage of the service. Brilliantly thought out strategy.
- ratorx 4y agoThis used to be the case, but is explicitly mentioned as untrue now: https://support.google.com/mail/answer/6603?hl=en-GB https://support.google.com/mail/answer/6603?hl=en-GB
- azornathogron 4y agoThey stopped doing that in 2017 or so. https://support.google.com/mail/answer/6603?hl=en-GB https://support.google.com/mail/answer/6603?hl=en-GB https://www.theverge.com/2017/6/23/15862492/google-gmail-advertising-targeting-privacy-cloud-business https://www.theverge.com/2017/6/23/15862492/google-gmail-adv... https://www.nytimes.com/2017/06/23/technology/gmail-ads.html https://www.nytimes.com/2017/06/23/technology/gmail-ads.html
- stickfigure 4y ago"Your 2FA authentication has been downgraded to email/password for ideological reasons."
- ajross 4y agoThat's exactly my impression too. Authentication is hard. And this isn't some random site wanting to store user data, they're doing invoice management! (So... not quite handling money on behalf of users, but pretty darn close in terms of liability.) Regardless of your feelings on Big Tech and Privacy and whatnot, this absolutely looks like a security downgrade to me. If I were someone looking for para-financial services like this to phish with fake users for fraud purposes, I'd probably start with a site like Slimvoice. Personally I think there's a good argument to be made about the benefits and tradeoffs to allowing giant cloud companies to control the idea of "identity" on the internet. But if there's any market segment where big companies with deep pockets and extensive technical resources bring value, it's this one.
- catiopatio 4y ago> Authentication is hard. No, it’s not. It’s certainly not harder or more complicated than the OAuth protocol used support Google-based sign-in. Exactly what unique value do you believe these big companies bring, exactly?
- rattlesnakedave 4y agoIt actually is very hard. There’s a long tail of concerns that make it difficult to do authentication as well as a major player in the space.
- catiopatio 4y agoWhat exactly about it is hard?
- ajross 4y ago
- intelVISA 4y agoCan't wait for the rise of libre hardware keys so more people can escape to FIDO instead of being chained to adtech.
- cmdli 4y agoIf you want something now and don't mind a virtual FIDO device, you could try out my solution Bulwark Passkey (https://bulwark.id https://bulwark.id). It's open source and allows you to export your credentials, so it's pretty user-freedom friendly.
- CuriousCosmic 4y agoYou might want to check out https://solokeys.com/ https://solokeys.com/ then. They're pretty new (shipping for about a year) but they do full FOSS firmware & software as well as most hardware being FOSS as well.
- nmeagent 4y agoI have a couple of these and they work well. Unfortunately it seems like most sites that I use (with a few notable exceptions) don't bother to support hardware tokens for 2FA, I suspect because of the ubiquity of phone-based methods.
- ilyt 4y ago"Google will no longer know you use our app! Hooray for privacy" "... but you still send me app related mails to my gmail account, what does this change". "...... FREEEDOM!!!"
- Retric 4y agoThat’s hardly the only information Google gets from managing logins. Trivially they can get time stamps for actual logins, that could be very valuable information for stock brokers for example.
- jahnu 4y agoDon’t let the perfect become the enemy of the good.
- deleted 4y ago[deleted]
- cm2187 4y agoIt may be surprising, but there are people who live outside of the google ecosystem too.
- ilyt 4y agoNobody was discussing replacing plain old login with google, just having an option. Try understanding the thread before answering next time please, this is a very low effort bait
- cm2187 4y agoExcept that now they have an unblockable google tracking beacon wherever they go. So my question is what about their privacy?
- crunchyfrog 4y agoOkay, then. That was always allowed.
- tlogan 4y agoThis website does not have any information about owners or legal entity behind it. Who is running this? What is their physical address? Where are they registered? Meaning they are managing invoices: the above informantion is very important. This seems more like Google ban them than they did something about “privacy”.
- alin23 4y agoTheir company "Sensor Station LLC" is mentioned multiple times in the Terms: https://slimvoice.co/terms https://slimvoice.co/terms Data on that company can be found here: https://opengovus.com/virginia-business/S8451587 https://opengovus.com/virginia-business/S8451587
- tlogan 4y agoThis should be listed in about page and privacy page. Note that GDPR requires physical address also to be listed on privacy page: but I guess they do not care about that stupid GDPR privacy thing.