[HN Gopher] Ask HN: Anyone else constantly forget which SSO serv...
___________________________________________________________________
Ask HN: Anyone else constantly forget which SSO service they signed
up with?
Curious if anyone else finds it increasingly difficult to play "SSO
roulette" when logging into the long tail of infrequently-used
services: did I use GitHub? Facebook? G Suite? Twitter? Or the
secondary problem: "if I used Google SSO, which of my gmail
accounts did I use?" I definitely have my own heuristics (g suite
for everything possible, github for "technical" sites, facebook as
a throwaway, etc), but I've found myself increasingly "getting it
wrong." Not to mention this is worsened by the fact that some sites
automatically create a new account for you if you log in with a
non-existing account: this means you often end up creating a NEW
account, further screwing yourself over. Anyone have any good
hacks to solve this? I've started resorting to storing a blank
1Password entry even for sites I SSO with, simply stating the SSO
account and email I used.
Author : lordofmoria
Score : 6 points
Date : 2022-03-02 21:07 UTC (1 hours ago)
| edoggie wrote:
| I try not to use SSO accounts as much as possible, especially
| Facebook, since I have no idea what those accounts are sharing
| with the vendor. But I do find my self wishing for solution to
| remember which provide I used when I originally signed up if I
| did sign up with SSO.
| drudoo wrote:
| I always sign up directly and store the information in 1password.
| With a custom domain I always use <website>@myDomain.com.
|
| What if your twitter/fb/google account gets suspended for
| whatever reason? All of a sudden you can't login to a plethora of
| sites.
| lordofmoria wrote:
| Yes, but that's more of a general argument against all SSO -
| besides, does your concern hold even for things like Sign In
| with Google / Apple? I assume losing access to iCloud / Gmail
| (if you've opted into these ecosystems) is an existential
| threat anyway, and SSO is the least of your worries at that
| point, and the question still stands.
| mtmail wrote:
| We see that with our SaaS users. They use Google-auth, next day
| try to use the 'forgot password' feature. Or end up with two
| accounts because they have several aliases. On the one hand a
| best security practice is never to give a hint that an email is
| registered ("if an account is registered, we will send you an
| email") but for this scenario we made an exception and give a
| hint.
___________________________________________________________________
(page generated 2022-03-02 23:02 UTC)