With a password manager and careful shepherding of your PII, maybe there's not much risk; if someone takes over the site your account is compromised either way, and nothing else is lost. But most people don't actually use password managers, and lots of sites that accept Google sign-in require lots more data to actually create an account on the site. (Plus, losing password stores is not necessarily the same as losing all control.) Newbies storing creds is a perennial source of leaked credentials that get used to attack more important sites.
Most solo bootstrapped projects are not popular enough initially for someone to spend money / effort to hack them. When they do become somewhat popular though (very small minority of course), I suspect most founders bring experts on board, as they absolutely should.
> just using HTTPOnly and DB backend is not a solution at all
My comment was not meant to be exhaustive and does not list all vulnerabilities. Just in context of some of the suggestions in the article. Using a mature framework like Django can protect you from other vulnerabilities CSRF, XSS, SQL Injection to some extent.
You have way too much faith my friend. How does bringing an authentication and security expert into your organization make you more money? It doesn't. What people like this tell you change is all cost and only hypothetical benifit. I suspect this doesnt happen anywhere near as much as it should.
Strong contender for Most Horrifying Thing I've Read This Morning.
I work in mostly the B2B space where we integrate with their Identity Providers (active directory, Okta, etc) and strongly discourage them from using our internal authentication system so they have to take responsibility for their own security.
If I were working in the consumer space, I would personally use AWS’s Cognito since that’s what I’m familiar with and it integrates with everything - Google, Facebook, Twitter, Apple, Amazon etc.
I’m sure there are other services that serve similar functions.
Thanks for listing some, will look into them!
You now have an auth system that avoids horrible passwords (no passwords).
The downsides are: 1) Cost to send emails for login, 2) People complaining about it being weird.
Worth it in many cases.