Hacker News new | ask | show | jobs
by markx2 672 days ago
I use Bitwarden but have used LastPass and 1Password before.

I always, without exception, will sign up with a username & password. I would never use a"Log in with". To me, if I am logging in through a different company then it is that company who has control, not me. There are tales here and elsewhere when Google has nuked someone's account. That's bad, but if you logged in with Google on other sites then you are completely screwed. Same applies to other companies.

I won't be using the Apple Passwords app.

2 comments

I've read some of these tales here as well. I'm thinking more about how to migrate from "log in with" to a un/pwd
surely you can just reset your password with the same email and regain access to your account?
If I log into Acme Widgets website via “login with Google,” then I don’t necessarily have an email or password with Acme, I have a delegated (SSO) account. In many auth systems you cannot use “forgot password” to convert SSO access to username and password. You have to actually log in and change it there. But of course if Google has locked you out, you can’t log in with Google.

And anyway… if Google has locked you out, you can’t access your Gmail to reset your password, even if Acme auth lets you.

In contrast: if you log into Acme with username and password, you can authenticate with Acme at any time, even if Google has locked you out. Acme does not need to check with Google to log you in… even if your username is a Gmail address.

If you’re going to use a password manager anyway, just do a fresh username / password whenever possible for each new service. It’s the most resilient and future-proof way to go.

i have found mostly you can reset password to get away from google sso on many sites. no empirical evidence of course, and all sites are different.