Aside from the security/privacy considerations, why the fuck would you do that to a website? SSO from a login page? sure, whatever. a f'ing popup on every page for a SINGLE provider? That is just brain-rot. Do they pay you to do this?
Aside from the security/privacy considerations, why the fuck would you do that to a website? SSO from a login page? sure, whatever. a f'ing popup on every page for a SINGLE provider? That is just brain-rot. Do they pay you to do this?
It does suck for the user.
I don't sites get payed (with money) but it probably improves the ranking in the search results (or at least some SEO guide claims that, so everybody does it)
Setting this up has become an automatic request from marketing people, almost as common as asking us to setup Google Analytics and such.
This is almost the equivalent to them to "have a CI/CD" for us devs: not having such things for them is strange, almost wrong. Of course the end goal is totally different.
Ooh, I've never looked into it, but I would have thought that with this feature the website explicitly does NOT get my email address. Silly me, still believing some features are meant for the user.
https://superuser.com/questions/1414410/how-to-disable-googl...
I can't confirm whether the email is still shared. It used to be the case from late 2010s up to a few years ago.
It would be easy to assume that other oath providers are doing the same but absolutely not.
This is quite visible in User Accounts where I work... while they do cause some issues from time to time (when the user disables the relay address for an active account), it guarantees privacy.
But I don't know if other popular single-sign-on provider do this.
https://meta.stackexchange.com/questions/402813/user-activat...
Apart from Google sponsoring this in some way or the other (by boosting up SEO ranking in sites that display this) I believe that this is a consequence of the third party cookiegeddon and I guess that once your users allow this login their activity is tracked as first party in your website, which would simplify things a lot for, well, tracking user behaviour. Of course Google benefits more.
If someone has searched for gloves on Google, and clicked through to my glove selling website, they're clearly ready to buy some gloves. Why the hell would I put a full screen cookie consent popover in their way? Or a join-our-mailing-list popover? Or require them to complete a captcha to create an account before they can check out? This person wants to give me money, why would I put barriers up in their way?
And yet quite a few sites do precisely those sort of things.
But if everyone dogfooding the site arrives with cookies that hide the popovers, and an account already created - I could believe they just don't realise how bad their website is.
Similar to how in a two party system, politicians will often prefer to lose elections to the other party, rather than lose control inside their own party.
It only looks self-destructive from the outside.. inside a sufficiently large bureaucracy me/us/them all get muddled