back
527 comments
The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in.

But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication?

Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again. If we had something open source, that would allow you to sign in to all the sites you use, while completely protecting your privacy, so none of them know who you are.

This dream can come true. Technically at least. I've taken the the first baby steps with https://promiseauthentication.org which proves that this is possible.

But, for this to become a reality, we really need to start running in the same direction. A collective movement towards a sane, privacy-first Single Sign-On provider that's easy to use for everybody.

It's a step in the right direction, but it's still centralized. A lot of the work done by the Indie Web community around IndieAuth[1] is really attractive. Your identity is your domain, and you can change how your domain says you're allowed to authenticate. Now you can even use sign-in with google without getting locked out should you loose your google account.

Aligns really well with using your own domain for email instead of gmail.

[1] https://indieauth.net/

I was my own OpenID Provider for a while, but quit because nobody supports it anymore. It was great for power users but super confusing for laypeople.
There's been a W3C standard that meets all those requirements for a couple years now: https://www.w3.org/TR/webauthn/

Only problem is there aren't any password managers that implement it, so it's not actually practical to use as a primary authentication factor yet.

There is so much fragmentation in authorization and authentication that it is hard to see how we can “run in the same direction”. Facebook, google, etc have zero incentive to change anything.
There is TLS client authentication, unfortunately it never catched on, probably due to not good and uniform UX in browsers. Imagine if web-browsers have automatically generated password-protected self-signed certificates that could be used to authenticate to web services without need of any third-party.
> which proves that this is possible.

How does it prove that?

Cool demo. I couldn’t figure out how to make an account though.

I think this would need serious widespread adoption until we saw benefits too. And you’d need some big names...like Google. Which probably will never happen.

I see it as a stepping stone for global “real id”. In this case centralization is a feature, not a bug.
There's another privacy-focused SSO solution from SimpleLogin that creates a different email address for each relying party.
To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world.

Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email account, so make sure these are companies your trust and your access to these accounts is as secure as possible (ie strong unique passwords and app-based, not SMS-based two-factor authentication)

There does seem to be a need for Google to clarify their rules for "banning" an email used for sign-in.

It seems like things should be more granular, such that being banned on YouTube doesn't make your thermostat quit working, ruin your phone contacts/photos/etc, or cut you off from your unspent AdWords funds.

Remember OpenID? Yes, that's what it was for, OAuth wasn't never meant for signing in other websites who just want your mail or something... Of course, all these big tech corps quickly dropped OpenID, they don't want people to control their online credentials or identity...
Perhaps the courts could be helpful here. A long-established Google account has significant value to the user. If Google terminates such an account, value is destroyed and damages are incurred. You should be able to demonstrate the value of the lost account to a court and demand restitution from the host.

If successful, this would impose a cost to Google for shutting down accounts capriciously and incentivize them to do better.

This would be a challenging lawsuit to win. You’d probably need support from an organization like EFF to manage it.

I recently got locked out of my Amazon account. While trying to get it unlocked, I faced one of the worst experiences with Amazon customer team. I even reached to Jeff's email, but no reply. Finally, I have to file an official complaint in the consumer court to get my account unlock. All of these event took around 14-15 days. During these days, I was suddenly unable to use my Echo, Prime video, Kindle books, readwise, and prime now services. I never really tried any other competitor service before, and was solely reliant on Amazon's offering. That time I realized the amount of power such single sign-in yielded. I can only imagine what happens when you use it for every service via a third party and use it daily, only to suddenly see it lock you out. I hope there's a better way to login in the future, maybe something like trusona or magic

PS: I did not do anything wrong but still suffered lot of psychological pain due to this mistake by Amazon's internal security.

We also offer multiple third-party signup solutions for our service in addition to "traditional" e-mail based signup. For every service we retrieve and store the users' e-mail address on our server (we also need that to e.g. send out invoices) and enable e-mail based login and password reset/generation by default (you can disable it or add 2FA), so your account will not be lost just because your OAuth provider blocks your credentials.
I had a similar problem. I used Google to sign in on digitalocean, then I changed the main domain in google apps and readded the original domain seperately on Google Apps. But probably because some kind of ID mismatch, I was now unable to sign-in on Digitalocean with the original e-mail address recreated in Google Apps. Password recovery didn't work either, for some reason digitalocean doesn't do password reset for accounts that were created using Google sign-in. I was forced to create a support ticket with digitalocean and wait.
For the average user, with poor password hygiene, I'd advise them to use a federated identity option that is more likely to have a decent password - they are more likely to have a good password for an account they care about.

I think the conclusion of the article is flawed. I think the risk of getting locked out is far lower than the odds of any single, or even all of, other (non-major tech co) website you might join getting breached. It's fair to argue the impact might be less also - and I'm happy to have this debate.

In my experience, typical users aren't the ones that get their google accounts banned - they are always banned for doing something significantly more sophisticated.

The truth is you should not use Google login to Google services either. You get the service promise you pay for, none. If their secret algorithms decide that you are in breach of whatever ToS, they will lock you out. Not very likely for the average user. But more likely for HN reader who might experiment with programmatic access to the services or do other atypical stuff.

Yes, I need to move away from gmail...

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire.

If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated to the relevant authority, namely the "justice" system to make such considerations.

If your house could be removed at a whim because a bot decided you were a bad person it would likely cause an uproar, it wouldn't be tolerated.

Yet here it is. Google can offer their services and the legal system seemingly doesn't want to be involved.

Why?

<Unpopular :penguin:>

You can get also locked out of your phone

You can get also locked out of the email that you actually use for signing in because you can never remember the password and they stupidly ask you to change it every 6 months with bizarre constraints

You can get locked out of your password manager

You can get hijacked

The business you're signing into can go under

The odds of these things happening are to be weighted against each other

Yes you shouldn't use third-party sign-in for the bank account that holds all your money (though most consumer bank 2-factor authentication mechanisms, sadly, rely on third parties such as phone and email provider)

Yes it's also ok to use third party sign-in for the odd website that you don't care about which somehow insists on asking you to create an account

There are no absolutes in security risk management </>

"Never Use Google to Sign-In" he says it as he offers Google Sign-In through Disqus comment section on his blog.
I'd argue, never use a third party service to log in, if you can.

I always use my email to sign up. If I can't register by email, there's a good chance I won't use that service.

> Every respectable service allows you to create accounts using your email address, so please use that method to create your accounts.

Although using e-mail sign-up actually provides a number of privacy-related benefits over using the Google account way, it still doesn't solve the main problem - because the e-mail usually is GMail anyway (and when it's not - you can get blocked by Microsoft, Yahoo or anything else too, and you can also loose your own domain).

"Every respectable service" should let and recommend (but not require) you set a secondary e-mail and/or another way to contact you but they usually don't.

Whats the issue here?

The alternative would have been to use email, which, presumably would have been a gmail.com address.

If Google locked you out of your account, you wouldn't be able to access your email account either.

I only ever use "sign in with" for throaway stuff I don't care enough about to register an account - if it's in any way important I setup an account, and add whatever form of 2FA I can.
Isn’t this grounds for a class action lawsuit? Google and friends have the right to lock you from use of their services, but when such services encroach in your use of other services unrelated to google, that you may even have paid for, should google have the right to blanket block? Is it technically difficult to exempt google signin from account locks? Can we maybe also legally claim that if a company hosts your identify, that it has no right to hold it hostage? I mean, if I’m arrested, my identity automatically erased.

Finally, is it not possible to require that all such block critical to someone’s data require some form of govt approved appeals process?

I’m asking these questions so maybe someone can enlighten me on why they were not yet attempted, or if they where, why they failed? Is it legal complexity? Cost? Lack of large scale support, as in, is it only a niche concern that only the HN crowd is complaining about?

This is a strong and succinct argument. I'm disturbed it never really occurred to me, probably because I am in part naive and take certain things for granted, like that I will never have a dispute with Google wherein they disable my account. But of course that is possible even at "no fault" on my part, and of course Google is judge/jury/executioner when it comes to their services. Yikes.

One thing I don't understand is: the author suggests a remedy is using your email address instead of third party sign in. But what if your email address is Gmail? For example, I just went to my Stack Overflow account and added my email address as a sign in method. But then of course I realized: my email address is Gmail. So what's the difference? How are we supposed to put this into practice without running our own email? Email is just another form of third party auth.

Sort of seems like everyone is going off. When this article doesnt really give any examples. It just says there are lots of examples.

I have around 8 gmails. Theyre all connected to various things via OAuth2 and I have never once had any of them locked.

Maybe im ignorant to some detail here, but, this sounds like a spammer retaliating because they got caught.

I agree with the general premise of this article that gmail/outlook/facebook owns too much power being able to lock you down with no due process.

However, for random sites, entering an email/password worries me because I have no idea how this password is handled server side, is it stored in plaintext or with a weak algorithm? The vast majority here don't care that much because they use a password manager but I'm worried about the ones that don't, they can be impacted if there is a database leak or if the site owner is shady and starts looking through its database for passwords that look reusable and try them on other important website. How easy would it be to set a nice honeypot website that requires a username/password?

A properly set up google sign in makes it impossible to do that at least. Thoughts?

I realized that recently after Gmail locked my account for using email outreach software.

I restored it but automatically had to start thinking about a backup plan where I’d have to point my MX records away from Gmail to something else immediately in order to prevent email downtime.

What annoys me is that when I do chose to login with A third party service and the app still makes me create an account and put it a password. They treat third parties as a fancy way to auto fill the email address field.
> Every respectable service allows you to create accounts using your email address

This way I should maintain my own email server, because I can be locked out of my email by any of cloud providers as easy.

A thing which I try to practice since I switched to DDG a year ago is to not say “google” but instead “search”. They don’t deserve their own verb, let’s take it back!
Good point, but if Google suspends my account I've got bigger things to worry about than the dozens of sites I've used once or twice a year.

Paying for your own domain also comes with its own troubles. If you're not using Google (or some other service) as your mail forwarder, good luck being able to email anyone. Stealing you custom domain is also a real possibility, and negates your investment in Gmail 2FA.

Even when some service allow registering using good 'ol email, some still refuses to accept any non gmail/outlook address. Met a service that wouldn't allow me to register using my own domain email address a week ago. Baffled me staring at the google, fb and twitter sso button with the form for email address giving error of "please use an email address from a reputable provider".
Another alternative to prevent such a situation from happening is connecting not just Google sign-in but combine with facebook or email as well.
> "if Google (or third-party of your choice) locks your account for some reason, you will be locked out of all the services where you signed into using Google."

But if the account I'd use to sign in is my Gmail account, and they had locked that account, wouldn't I be locked out anyway?

Please explain it to me if I'm wrong (cause that happens often).

This is not an easy issue. It boils down to responsive customer service at the end. Even if you host your email, your hosting provider can suspend your account if, let's say, your credit card rebilling fails. There should be a better and more resilient way to identify people online in 2020!
I was forced to use sign in with google for dnd beyond as they don't support byo-email address (!), only google, twitch, apple, and yahoo.

We need a name and shame site for websites that can't be bothered to write a back end database for the 3 columns needed to store emails, salts, and hashes.

When you use Google or FB or others to sign in, you just get some data, that you can trust.

Internally, on my website, i may have an account, that i then link to this Google or FB account.

1) If Google shuts down an account, authorization might still work for the purpose of logging in somewhere else. Your email might not work anymore, like any other services within Google. But authorization does. That it does not, is an implementation detail.

2) Since internally i have created an account, that is only linked to your Google account, i can always allow you to also login via any other method. Maybe with your facebook account.

3) I think, things will become better. You use your devices to authorize yourself. And i then trust your device. Then there is no 3rd party involved anymore.

We went through a process of changing email domains recently and we use Google Sign In for many of our services. Switching emails over varied greatly between services. Sometimes it all just worked and my new email would sign in to my account and my email address on the service was updated automatically. Some allowed me to sign in fine, but I had to contact them directly to update the email address. A number of times I ended up having to go through recovery processes.

I guess at least if you’re using your own domain, you’d be able to repoint mx records to do the recovery.

I tend not to use it for my personal accounts, but honestly, Google Sign In for our work systems has generally been a good experience. Works well for our small team, anyway.

Technically email becomes the skeleton key regardless. And that is dependent upon at least one third party: domain registrars. And possibly email providers too.

Though the post does have a good point on that non-email auth providers add more risk to the equation.

You can use Handshake [1] to third party auth without risk of losing your credentials. Simply authenticate against the public key associated with your name!

[1] https://handshake.org

The original HN post was titled Never Use Google to Sign In. Did HN change the title?
Isn't that obvious? Convenience always hat some kind of price tag, particularly a security related one.

I would have canceled my facebook account long ago if I had not chosen their login for a (unknown) number of service.

What would be a better alternative? Use same credentials everywhere? No, because it is just a matter of time it would leak out of one service. Use unique credentials for each service in local password manager? Nay, because most of us at least want to sync between desktop an mobile. Use something like Chrome's password manager? That bears similar dangers like those the article points out.

1. This isn't a clear cut, though some services don't allow using both Oauth 2.0 and email / username login, most do. So if the service provider allows both, create a simple user + link your account.

2. Developers should always allow restoring passwords for SSO only users, it is ridiculous for it to even be an issue.

3. As a user, refrain fro using free email accounts to identify on a platform, as others already said, buy a domain not an expensive one, and stick to it, remember to renew, and setup your email address with a reliable service, there are good providers for $1 a month.

Update: line separation...