14 ms·
Why do they argue with privacy? If Google decides to lock your account for any reason, all your third party accounts using Google's SSO are mostly fubar, as it
by sys42590 4y ago
Why do they argue with privacy?
If Google decides to lock your account for any reason, all your third party accounts using Google's SSO are mostly fubar, as it's currently almost impossible to get your Google account back.
- gs17 4y agoNot just Google themselves, I still use my old university email and they decided recently ("for security") to block using it to log in to other sites, along with a million other things, so their own staff can't even open Search Console. Fortunately, a lot of them allow "forgot my password" to go to email if you can't login through Google, but a few required new accounts.
- llanowarelves 4y agoI have the same problem with Tailscale only supporting providers
- emodendroket 4y agoI judge the likelihood of this happening rather low and, anyway, considering how many services don't let you change your e-mail address, what's the difference?
- tlogan 4y agoThis website does not have any information about owners or legal entity behind it. Who is running this? What is their physical address? Where are they registered? Honest question: how do I know and verify they really care about privacy and they are not one doing shady things? This is really honest question. How can anybody trust that company x care about privacy without even know anything about company x?
- jchw 4y agoWhen it comes to SaaSes, absolutely nothing. It's all social. Even knowing the owners doesn't give you much more assurance that it's legit, unless they're very well known. That said, most liars are really really bad at lying. "We care about your privacy! Now let us load 1000 tracking libraries, kthxbai" is pretty easy to spot. I think the scarier case is when dealing with a government adversary. They're simply not as stupid, and you never know when it could happen: https://archive.ph/rI8mE https://archive.ph/rI8mE For those cases, I get unnerved when things seem too good to be true. If I didn't know former Mullvad employee(s), I'd be deeply concerned about them, too.
- BlueTemplar 4y agoThankfully, most people shouldn't consider "government adversary" high in their "threat assessment".
- jchw 4y agoI think "targeted government adversary" shouldn't be. But government in general? https://www.pcmag.com/news/fbi-sold-criminals-fake-encrypted-phones-that-actually-copied-their-messages https://www.pcmag.com/news/fbi-sold-criminals-fake-encrypted... Maybe.
- BlueTemplar 4y agoI mean, "government in general" is kind of meaningless, some governments are much more of a threat to some people than others. Also, while your example is great (and I think I have seen it predicted !), criminal organizations aren't "most" nor "people" (more like businesses ?).
- tlogan 4y agoIt is not about liar. The owner of the web site is probably nice and all these things. Some social proof (LinkedIn, address etc) is really needed. I always check LinkedIn’s to see where that person worked, what does it do, etc. Not a good test but it is better than nothing. But on the other hand, the owner can be NK. Or what if it gets taken over by NK? Or what if somebody starts claiming that they were running this business and it was hijacked?
- yucky 4y ago> This website does not have any information about owners or legal entity behind it. Yes it does. It's all over their TOS.
- deleted 4y ago[deleted]
- tlogan 4y agoI searched for Sensor Station LLC. That points to this company: https://www.sensorstation.co/ https://www.sensorstation.co/ This company seems to be making embedded software for sensors. Now I’m concern.
- trynewideas 4y agoIt's a digital agency. https://clients.sensorstation.co/ https://clients.sensorstation.co/ > We specialize in custom software projects above and beyond the typical web agency: realtime interactive experiences, high-concurrency backends, and everything in between. Appears to be a husband-and-wife team whose personal projects include tech to support their permaculture lifestyle, but whose portfolio appears to be mostly brand related. Took about five minutes of reading, but I know that's not the point you're trying to make, you just don't want to say Slimvoice is an unprofessionally run service.
- bloomingeek 4y agoF-ing Google locked me out of my account and my email because I broke my cell, and then traded it in for a new one but Google kept sending the verification to my broken cell. There's no one to call for assistance!
- k12sosse 4y agoI hate to be that guy but this seems like a user problem
- hsbauauvhabzb 4y agoThe inability to recover an account is bullshit regardless. It’d be like if you lost your bank card, and the bank didn’t have a service desk. Just because google is free, doesn’t mean they don’t have a responsibility to users. Savings accounts where I live are pretty much free too.
- Ferret7446 4y agoIt is made abundantly clear when you set up 2FA that you need to backup your 2FA or it may not be possible to recover. What did you expect? Personal responsibility is important.
- hsbauauvhabzb 4y agoYes and what I’m saying is that is not an okay solution. If you lost absolutely all your proof of ID and bank cards, there is still ways to sufficiently prove your identity and recover access to your assets and bank accounts. An email address is an asset.
- deleted 4y ago[deleted]
- Ferret7446 4y agoThat is just your opinion. Those "ways to sufficiently prove your identity" are also ways that identity theft happen every single day. Some people prefer to take personal responsibility over opening themselves up to compromise. In any case, if you thought that is not acceptable to you, you should not have set up 2FA because the conditions were clearly communicated.
- jchw 4y agoIf you use SSO with the account you were going to use your e-mail address with, it makes little difference whether you used OAuth2 vs traditional e-mail based authentication. You're locked out. If something happens, like OAuth2 stops working, most websites allow password reset to the e-mail address connected to the account, and then can log-in without OAuth2. The concern here is probably related to some Log-in with Google scripts that run on the frontend, although if they were just using normal OAuth2, then I think they are wasting their time: whatever sensitive information Google gets via OAuth2 they also get via the unencrypted e-mails you're sending to them anyways...
- giancarlostoro 4y agoArguably if you can prove to the provider that the email is FUBAR and you own the account, it might be easier for them to change out the email on you. Maybe a good reason to support login via email and / or phone number. If you lose both, you're screwed.
- codazoda 4y agoI use a custom domain and forward all mail to a web based email provider for this reason. If my provider drops me, I can move to another and update my forwarding. There’s still a risk I could lose the domain somehow, but I don’t hear about that happening nearly as often.
- jhot 4y agoI do this as well but with anonaddy.com which acts more like a proxy than forwarding. The yearly price is low (something like $12) to use your own domain and much lower than paid email plans.
- dwheeler 4y agoI do this as well. I encourage people to own their own domain and use that for email; it is more complex to set up, but you have far more control long term.
- derwiki 4y agoI have a Gmail rule set up to forward all of my mail to a Protonmail account as a back up. So I can still perform password resets, etc
- itake 4y agoThis is true for most email addresses as well. If you use a domain name for your email that is owned by another company, then you you can be locked out of your email (and any downstream accounts). I work in tech and 99% of my contacts are with @gmail (or some other free email host).
- sys42590 4y agoMost sites that require an email for sign-up only verify the email address once right after sign-up. So if Google ever locks my account, my other website passwords continue to work, while SSO using Google is instantly broken. Of course I won't be able anymore to reset my third party passwords through my Gmail mailbox, but many sites allow to change the email address if you know the password...
- cm2187 4y agoBut what about the privacy of the people not using google at all. All other trackers are (or should) be blocked by my adblocker, but my adblocker can't block the google sign-in button because some people use that. So another way to defeat anti-tracking software. Plus those google sign-in buttons have recently become extra-obnoxious, opening a modal window over every page I visit to invite me to sign-in with google. This is really back to the 90s!
- emodendroket 4y agoI don't care. I don't want to maintain a bunch of passwords for rarely-used Web sites.