• thejml@sh.itjust.works
    link
    fedilink
    arrow-up
    35
    ·
    3 hours ago

    Google and youtube are the same login though…

    Honestly i like these buttons from a user/security POV as oauth only passes back a “login successful” reply and an identifier to associate an account with. Less PII to spread around the internet.

    • clb92@feddit.dk
      link
      fedilink
      English
      arrow-up
      1
      ·
      20 minutes ago

      I hate it when it afterwards still prompts me to create a full account, on some badly made sites. Why even allow oauth login if I still have to give you all my personal data…

    • bus_factor@lemmy.world
      link
      fedilink
      arrow-up
      22
      ·
      3 hours ago

      This is fine for stuff I don’t care that much about, like an account with your hairdresser or a pizza place, but if you tie all your actually important stuff to the same account and you get locked out for whatever reason, now you’re locked out of your whole life.

      I prefer unique passwords and a password manager. But you do have to back up the password manager data as well as any data you have with cloud providers.

      • valar@lemmy.ca
        link
        fedilink
        arrow-up
        18
        ·
        2 hours ago

        For me the bigger issue is privacy. If you’re using Google to log into everything, Google gets to add all of that activity to their profile on you, and track you as you use every website you go to. No thanks. Google doesn’t need to know I’m buying a pizza tonight.

        • bus_factor@lemmy.world
          link
          fedilink
          arrow-up
          3
          ·
          1 hour ago

          That is also a concern and why I always default to a separate account even for those things, but I wouldn’t assume that data doesn’t get sold to Google regardless.

          • valar@lemmy.ca
            link
            fedilink
            arrow-up
            1
            ·
            58 minutes ago

            I prefer to use different email aliases for everything to mitigate that

  • allywilson@lemmy.ml
    link
    fedilink
    arrow-up
    7
    arrow-down
    2
    ·
    2 hours ago

    If you host your own DB of users and passwords you are a target. Offloading it to as many wide-spread oauth providers as possible is a smart move.

    • refalo@programming.dev
      link
      fedilink
      arrow-up
      9
      ·
      2 hours ago

      Tell that to all the people whose google accounts of 20+ years got locked out with zero recourse or warning.