Sign in with Google has been removed for your privacy
slimvoice.co
slimvoice.co
If Google decides to lock your account for any reason, all your third party accounts using Google's SSO are mostly fubar, as it's currently almost impossible to get your Google account back.
Honest question: how do I know and verify they really care about privacy and they are not one doing shady things?
This is really honest question. How can anybody trust that company x care about privacy without even know anything about company x?
That said, most liars are really really bad at lying. "We care about your privacy! Now let us load 1000 tracking libraries, kthxbai" is pretty easy to spot.
I think the scarier case is when dealing with a government adversary. They're simply not as stupid, and you never know when it could happen: https://archive.ph/rI8mE
For those cases, I get unnerved when things seem too good to be true. If I didn't know former Mullvad employee(s), I'd be deeply concerned about them, too.
But on the other hand, the owner can be NK. Or what if it gets taken over by NK? Or what if somebody starts claiming that they were running this business and it was hijacked?
https://www.pcmag.com/news/fbi-sold-criminals-fake-encrypted...
Maybe.
Also, while your example is great (and I think I have seen it predicted !), criminal organizations aren't "most" nor "people" (more like businesses ?).
> This website does not have any information about owners or legal entity behind it.
Yes it does. It's all over their TOS.This company seems to be making embedded software for sensors. Now I’m concern.
> We specialize in custom software projects above and beyond the typical web agency: realtime interactive experiences, high-concurrency backends, and everything in between.
Appears to be a husband-and-wife team whose personal projects include tech to support their permaculture lifestyle, but whose portfolio appears to be mostly brand related.
Took about five minutes of reading, but I know that's not the point you're trying to make, you just don't want to say Slimvoice is an unprofessionally run service.
Just because google is free, doesn’t mean they don’t have a responsibility to users. Savings accounts where I live are pretty much free too.
The world will be a better place when legislation requires these evilcorps to at least have some baseline responsibilities to the people who they are supposedly helping while making trillions in revenue.
In any case, if you thought that is not acceptable to you, you should not have set up 2FA because the conditions were clearly communicated.
If something happens, like OAuth2 stops working, most websites allow password reset to the e-mail address connected to the account, and then can log-in without OAuth2.
The concern here is probably related to some Log-in with Google scripts that run on the frontend, although if they were just using normal OAuth2, then I think they are wasting their time: whatever sensitive information Google gets via OAuth2 they also get via the unencrypted e-mails you're sending to them anyways...
Also I have a custom domain, so I don’t consider this a gamble—more of a backup.
They just didn't want to support it and found some reason to justify the removal, that's as much as you can get from the given facts
I work in tech and 99% of my contacts are with @gmail (or some other free email host).
So if Google ever locks my account, my other website passwords continue to work, while SSO using Google is instantly broken.
Of course I won't be able anymore to reset my third party passwords through my Gmail mailbox, but many sites allow to change the email address if you know the password...
Plus those google sign-in buttons have recently become extra-obnoxious, opening a modal window over every page I visit to invite me to sign-in with google. This is really back to the 90s!
Regardless of your feelings on Big Tech and Privacy and whatnot, this absolutely looks like a security downgrade to me. If I were someone looking for para-financial services like this to phish with fake users for fraud purposes, I'd probably start with a site like Slimvoice.
Personally I think there's a good argument to be made about the benefits and tradeoffs to allowing giant cloud companies to control the idea of "identity" on the internet. But if there's any market segment where big companies with deep pockets and extensive technical resources bring value, it's this one.
No, it’s not.
It’s certainly not harder or more complicated than the OAuth protocol used support Google-based sign-in.
Exactly what unique value do you believe these big companies bring, exactly?
Farming that responsibility off to Google or Facebook and letting them handle the edge cases (for free, I might add) has genuine security value.
That aside, do you have a recommendation for auth that provides good privacy while also having wide adoption and ease of integration similar to Google or Facebook auth? And also 2FA of course.
If there are no options then I think our problem is bigger than this particular dev's ideology.
They also really should switch from bcrypt to something more modern like argon2, but bcrypt is a lot better than the unsalted MD5 I've seen in a lot of places.
Factor #1 - Thing you have: encrypted password vault.
Factor #2 - Thing you know: password to said vault.
Of course, this is only 2FA from the user's perspective. Meddling websites cannot ensure that you didn't memorize their password, or write it down unencrypted.
- Something you know: password.
- Something you have: your phone or a physical key.
- Something you are: Biometrics (finger-print, eye pattern, gait of your walk, etc.)
Using 2 passwords, such as the case of knowing the password to your vault of passwords, is only 1 factor.
The 2 factors are then the vault itself and the vaults password.
It should be noted, though, this is significantly weaker than "real" 2FA, as normally that would involve some sort of challenge, rather than just storing a hard secret.
I too don't like third party sign ups, I think they are bad for privacy and the user.
"... but you still send me app related mails to my gmail account, what does this change".
"...... FREEEDOM!!!"
Try understanding the thread before answering next time please, this is a very low effort bait
> The Checkbox/Label Trick
I'm hesitant to use this. It just doesn't feel right to use this hack.
Also somewhat related to the <details>/<summary>, I try using native html elements as much as possible. One time I used the <meter> element for a meter bar, but it was called out immediately by QA because the design doesn't match the one created by the UI/UX team. I really wish html elements were more customizable.
Besides, single sign-on is a security disaster. In an ideal world every single login you have should have a different user ID and password. I do my best to approach this. Of course, you have to rely on password management software to be able to do this.
There is no such thing as absolute security. However, making every login ID and pwd different goes a long way towards ensuring you don't experience a chain reaction of breaches because someone hacked into one account.
Yes, the password manager could be considered to be the weak point then. Encryption and a long and secure password are the keys there. And, if you can, one that is accessible online.
Sign in with Google has been removed for your privacy.
Click here to create a password for your account.Before: When signing up with Google the owner gets your name, email, and profile picture
After: When signing up without Google the owner gets your name and email, but the owner can make an API request to get your profile picture.
In both scenarios the same amount of information is accessible by the site.
A single tracking cookie shared with their one of their many many partners is enough
https://support.google.com/analytics/answer/9445345?hl=en#zi...
Preach
Meaning they are managing invoices: the above informantion is very important.
This seems more like Google ban them than they did something about “privacy”.
Data on that company can be found here: https://opengovus.com/virginia-business/S8451587
Google will still store and sync the keys for users of Android and Chrome, but their code won’t run on sites who opt out of Login with Google. It’s an evolution of the security model. This is arguably superior considering the ability to migrate passkeys elsewhere. You have improved sovereignty over your auth story (versus “haha google locked you out of everything and you have no recourse”).
TLDR PKI > consumer federated identity
If instead, every site I had ever logged into kept track of my tokens I would need to visit each of them and do the same thing.
(It's already messier than that because some accounts I have--GitHub and Facebook--don't accept SSO but are important enough to be worth protecting with hardware tokens. But I don't want to go farther in this direction!)
https://news.ycombinator.com/item?id=30771057
And that’s just HN participants, not the unknown layman cohort.
In my particular case, I am happy with my 2FA setup for Google (three security keys, across multiple locations) so I think that category of lockout is pretty unlikely.
And I've already lost my keys once in my life, about 20 years ago.
According to dang, there are ~100k monthly active logged-in HN users [1]. In a population that size of 25-54 year-old Americans, you'd expect around 290 to die each year [2].
Getting locked out of my Google account is pretty low on my list of things to worry about.
[1] https://news.ycombinator.com/item?id=9219581 (and that was in 2015 - I assume it's grown since then)
This is not specific about Google, a lot of services/apps/whatever like (and it is probably true) to state how they are in practice error-free, at least with account management, yet when this extremely rare event happens there are no (or extremely complex) ways to fix the problem, short of posting to HN or to a social and hope that some good soul working at that company notices the issue and decides to solve it.
* Securing hardware authenticators is much more within our control than the whims of Google are.
* Most of us aren't ex-Googlers with contacts and reach (which are the only way to get reliable support when one's account does get borked), so that side of the risk is also much higher for normal people than for you.
I don’t expect for us to solve this here, and I’m sure my perspective will differ substantially from those affiliated with Google or tech professionals in general (who don’t fully internalize the layman’s experience). I do believe I’ve provided sufficient evidence this is a real problem, and it’s likely going to require federal statute or FTC guidance to require tech companies to recalibrate their customer service and infosec ops around access and identity.
Regardless, I appreciate the discourse on this topic.
As an aside, I would like to plug my own passkey solution, Bulwark Passkey (https://bulwark.id) which is open source and allows credential exports. Whatever passkey solutions people end up using, managing credentials is going to be the key challenge (pun intended).
It hardly seems reasonable or rational to attack the mere thought of handing out all auth responsibilities to a shady monopoly with a track record of dubious practices and government tie-ins for being "an ideological goal that helps no one's privacy".
1. If you consider the loss of a phone number to be a more likely event than a forgotten password (non-obvious example - if you have no extra money to keep the phone number working).
2. If some powerful contractors can capture the data coming to your phone.
3. Also, if there is some kind of banhammer (Google is famous for banning for no reason) in the "2-factor" and no banhammer in the 1-factor (Bitcoin has no third-parties who might steal or freeze your funds), then your chance of encountering a banhammer in your face is infinitely greater in the first case.
More than 1 factor creates more problems than usefullness tbh if you are enough responsible for never lose your credentials.
That's silly. If you lost your phone number, why would you attempt to log into a service and have it text or call your lost phone number? The provider in question here (along with many others), Google, provides backup codes for this situation. Besides, if you are more likely to constantly lose phone numbers, it's best not to use those for authentication/authorization.
> 2. If some powerful contractors can capture the data coming to your phone.
That doesn't matter to 2-factor. That "powerful contractor" would be in possession of a time-bound pin that can only be used by the device and account that had just had the credentials entered. It is useless to anyone else.
> 3. Also, if there is some kind of banhammer (Google is famous for banning for no reason) in the "2-factor" and no banhammer in the 1-factor (Bitcoin has no third-parties who might steal or freeze your funds), then your chance of encountering a banhammer in your face is infinitely greater in the first case.
This also doesn't apply. Google provides backup codes that can be used in such a case. As do digital ocean and others...
> More than 1 factor creates more problems than usefullness tbh if you are enough responsible for never lose your credentials.
Except that isn't true. I noticed that you placed 2-factor in quotes, showing that you likely do not understand 2-factor is formed from any two out of the three possible security factors. There is also 1.5 factor authentication, which is acceptable to put in quotes, since it is pseudo-2factor.
What you know. What you have. What you are.
> (Bitcoin has no third-parties who might steal or freeze your funds)
I'm not sure your comment was serious... Bitcoin and the entire crypto ecosystem are full of third-parties who steal or freeze funds.
To be more specific, if the implementation of 2 factors requires both factors, then it is indeed more secure. If it's a form of 2 factor that requires only one factor, it's less secure, because now you have more attack surface.
* Google does not have a good track record of customer service, not putting all your eggs in their unreliable basket seems like a good idea from a security point of view.
* The privacy argument is a bit of a hot take in this case, and is probably not as valid as a reason to dump Google SSO as eggs-in-unreliable-basket argument.
In the event they do, the third-party software adds a Google Sign In flow to their software, whereas their users can press a call-to-action for signing in with Google, which would trigger an opening of a separate Google-owned domain in a new min-browser window that the third-party software cannot access (and therefore not harvest information from). This min-window then sends the user back to the third-party software domain upon completion with an authentication token - which could be in the form of a URL query string, an HTTP method, a cookie, or even collection of arbitrary browser information for fingerprinting. The third-party site then sends that authentication token back to Google via their API, and Google sends back ONLY what that authentication token is permitted to grant access to - which would not be Google credentials.
If I'm asked to sign in with google via oauth, I never type in my password (or username!).
Now you're talking about phishing sites.
Can you clarify which kind of websites you're referring to?
It's really as easy as these companies that support Oauth incentivizing third-party devs to use them.