If Google decides to lock your account for any reason, all your third party accounts using Google's SSO are mostly fubar, as it's currently almost impossible to get your Google account back.
If Google decides to lock your account for any reason, all your third party accounts using Google's SSO are mostly fubar, as it's currently almost impossible to get your Google account back.
If something happens, like OAuth2 stops working, most websites allow password reset to the e-mail address connected to the account, and then can log-in without OAuth2.
The concern here is probably related to some Log-in with Google scripts that run on the frontend, although if they were just using normal OAuth2, then I think they are wasting their time: whatever sensitive information Google gets via OAuth2 they also get via the unencrypted e-mails you're sending to them anyways...
Also I have a custom domain, so I don’t consider this a gamble—more of a backup.
They just didn't want to support it and found some reason to justify the removal, that's as much as you can get from the given facts
Just because google is free, doesn’t mean they don’t have a responsibility to users. Savings accounts where I live are pretty much free too.
The world will be a better place when legislation requires these evilcorps to at least have some baseline responsibilities to the people who they are supposedly helping while making trillions in revenue.
In any case, if you thought that is not acceptable to you, you should not have set up 2FA because the conditions were clearly communicated.
Honest question: how do I know and verify they really care about privacy and they are not one doing shady things?
This is really honest question. How can anybody trust that company x care about privacy without even know anything about company x?
That said, most liars are really really bad at lying. "We care about your privacy! Now let us load 1000 tracking libraries, kthxbai" is pretty easy to spot.
I think the scarier case is when dealing with a government adversary. They're simply not as stupid, and you never know when it could happen: https://archive.ph/rI8mE
For those cases, I get unnerved when things seem too good to be true. If I didn't know former Mullvad employee(s), I'd be deeply concerned about them, too.
But on the other hand, the owner can be NK. Or what if it gets taken over by NK? Or what if somebody starts claiming that they were running this business and it was hijacked?
https://www.pcmag.com/news/fbi-sold-criminals-fake-encrypted...
Maybe.
Also, while your example is great (and I think I have seen it predicted !), criminal organizations aren't "most" nor "people" (more like businesses ?).
> This website does not have any information about owners or legal entity behind it.
Yes it does. It's all over their TOS.This company seems to be making embedded software for sensors. Now I’m concern.
> We specialize in custom software projects above and beyond the typical web agency: realtime interactive experiences, high-concurrency backends, and everything in between.
Appears to be a husband-and-wife team whose personal projects include tech to support their permaculture lifestyle, but whose portfolio appears to be mostly brand related.
Took about five minutes of reading, but I know that's not the point you're trying to make, you just don't want to say Slimvoice is an unprofessionally run service.
Plus those google sign-in buttons have recently become extra-obnoxious, opening a modal window over every page I visit to invite me to sign-in with google. This is really back to the 90s!
I work in tech and 99% of my contacts are with @gmail (or some other free email host).
So if Google ever locks my account, my other website passwords continue to work, while SSO using Google is instantly broken.
Of course I won't be able anymore to reset my third party passwords through my Gmail mailbox, but many sites allow to change the email address if you know the password...