1. People may wish to not have activity on multiple services connected or associated. This was certainly true for me when I found that G+ and YouTube accounts, independently created, though sharing a common email address, were conjoined.
2. Google is put in a position of advantage as regards online identity. This persists across several dimensions:
a). Google apps and services share an authenticator with the browser itself. Other parties must implement their own authentication schemes, unless ...
b). Third-party applications utilise the Google Chrome authenticator, in which case
i). Those third parties leak user identity, activity, and all but certainly fraud and abuse detection, including both false negative and false positive determinations, to Google.
ii). Other browser venders, including Mozilla, Apple, Microsoft, Amazon, Opea, and others, are rendered as second-class citizens from an authentication standpoint.
iii). Consequences of a loss or freeze of an account now extend to multiple third-party services.
c). Loss or freeze of an account locks people out of their own web browser and all that entails; cookies, bookmarks, history, extensions, configurations, extensions-related data (say; Zotero).
3. The centralisation, stakes, and attractiveness of attacking people's Google identities rises yet higher. Data exfiltration, access to browser and local system state, denial-of-access attacks, and more.
The privacy, anti-trust, security, conflict-of-interest, general risk, and other implications simple boggle the mind. That this was quietly rolled out with no apparent announcement or consideration tremendously reduces my already greatly-diminished trust in Google, its leadership, and its stewardship of critical Web infrastructure and protocols.
Chromium is likewise affected.
What were they thinking?
Were they thinking?