Maybe I'm missing some security detail here
Maybe I'm missing some security detail here
I expect that by sometime next year I'll hit 10 accounts with them.
In other words, they could definitely highlight or otherwise hint to you which of the Google accounts you've already approved/used via one or more of your authenticated Google accounts.
So, yes, they could do more to highlight _potential_ accounts but it's not the case that they have any visibility into the actual state of accounts.
I don't need to know for certain the account on the receiving side exists, just that I have signed in before with it. Facebook does this at least!
Like "has an account" isn't possible without leakage, but "has logged in through this flow before" (hell, stick timestamps in there too!) does.
One thought though: your SSO provider has that account list, but often prompts a re-login. So it could be that your SSO provider account picker _doesn't have access to your account information fully either_.
I started adding them to my password manager as a quick reference, but the irony is that this makes the SSO slower than a typical standard login. I almost never use these SSO options anymore as a result.