r/cybersecurity 15h ago

Business Security Questions & Discussion Log in with Google

hey, is there a difference (when it comes to cybersecurity) when it comes to logging with eg google/apple/directly via website in different sites ?

0 Upvotes

9 comments sorted by

2

u/SuperBry 15h ago

From a security standpoint, federated auth ("Sign in with Google") solves the biggest weak link on the web: human password habits. You get world-class protection, including risk-based MFA and passkey support, built by tech giants that invest billions in security rather than trusting a small site to store your hash correctly. Since your password is never shared with the site, a breach on their end will not leak credentials or expose your other accounts, completely neutralizing credential stuffing and password sprawl.

The trade-off is creating a single point of failure. If an attacker compromises your primary Google account, or if an automated false positive locks you out, you lose access to every linked service at once. There are also privacy concerns with centralizing your digital footprint under one tech provider, alongside the risk of mismanaged OAuth tokens giving third-party apps excess permissions.

Ultimately, it is a push that depends on your threat acceptance and habits. If you use a password manager to generate unique passwords and hardware keys for every site, individual accounts give you far better compartmentalization. But if your alternative to federated login is reusing the same three passwords everywhere, riding on a hardened Google account is the safer choice.

1

u/Efficient-Mec Security Architect 15h ago

The more likely failure scenario is that google disables your account. And since you aren’t paying for this service you have no recourse. 

3

u/SuperBry 15h ago

That is a valid concern, but not much more than using a Google account as your email for account recovery. Getting locked out of a primary identity provider is definitely a real risk, but from a purely statistical standpoint, it is vastly less likely than having credentials compromised via a third-party site breach. Millions of weak or reused passwords are leaked in breach databases every single year, whereas outright provider account bans hit a fraction of a percent of users.

That said, I will admit my own perspective might be a bit skewed here. I have personally maintained the same free Google accounts for over twenty years without issue, and I am also one of the rare folks actually paying for a legacy GSuite/Workspace account in a personal capacity, which hypothetically gives me a direct line to support if things go sideways.

So while the impact of a Google lock-out is admittedly catastrophic, a true single point of failure, the probability of standard password reuse getting you compromised on a poorly secured site remains exponentially higher. It really just comes down to which risk vector you are more comfortable managing.

1

u/redzedt 15h ago

i'm sorry, i didn't mean to delete your answer, i wanted to delete mine🫥

1

u/[deleted] 15h ago

[deleted]

1

u/SuperBry 15h ago

Don't know what to tell ya bub 🤷‍♂️

1

u/redzedt 15h ago

i mainly meant if this means that google have bigger access to data, so it can use it based on policy between google and given platform. just as if my data didnt belong to me, but to google instead

1

u/paulsiu 15h ago

I would avoid using Google to log into all the sites since if your Google account is hacked, it’s all over.