But yes, in 2023 you probably shouldn't use 3rd party authentication. You're much better off combining email/password login with a password manager, which effectively allows you push authentication on a 3rd party while retaining full control.
But yes, in 2023 you probably shouldn't use 3rd party authentication. You're much better off combining email/password login with a password manager, which effectively allows you push authentication on a 3rd party while retaining full control.
I feel like this is part of the reason we need real data protection laws in the US. There doesn't seem to be any downside for a company with lax security practices.
I intentionally don't let the clients integrate with the browser. I let the browser itself cache the unimportant stuff for convenience, and anything important I always paste from the password manager and have to get a code from the totp app also anyway.
I don't think anyone should use a fully 3rd party full featured password manager like lastpass or onepass.
I would say it is NOT better that they use that vs nothing. 'anything is better than nothing' is not true here. Some things are better than nothing, and some are not.
You misspelled "definitely" as "probably" here.
It's getting harder and harder to send email from your domain without being send to spam, bouncing, or the server just discarding your email without notice.
Currently using their lowest paid tier US$10/month, as that's 10k emails a month which is far more than we send. At least at this stage. ;)
Wish they'd occasionally look over the PR's submitted to their GitHub repo's though. ;)