Remix.run Logo
IndianShitbombs 3 days ago

> t. What if you used your Apple account as SSO to other services ?

Your own wrongdoing. Always use a site-specific auth method, i.e. by email. And a separate email for each site.

rationalist 3 days ago | parent | next [-]

Using a separate email address for each site is smart, but creating a separate email account for each site is going to be very tedious, and I imagine Google, Yahoo, etc are going to stop you very quickly after you've opened 20+ accounts with the same phone number.

(Use a catch-all to have different email addresses for different sites, because when one gets hacked, then the damage is limited.)

8cvor6j844qw_d6 3 days ago | parent | next [-]

Using your own domain that you control for emails also comes with the advantage of easily moving providers, should there be any issues.

Hopefully, domain registrars are less prone to locking people out compared to Apple, given cause of the lockout is caused by Apple itself.

Reminds me of the time Namecheap stopped doing business with Russian accounts, even then they still gave some time for them to transfer their domains.

justsomehnguy 3 days ago | parent [-]

Only if you are not locked out of the registrar. Then your only hope is what nobody would squat your domain when it lapses.

Eg: Dynadot decided what my birthdate is a secure pin two years ago. No combination of it works and I'm not even sure if I'm not shadowbanned for the attempts.

tomrod 3 days ago | parent | prev | next [-]

Proton allows you to alias. But a lot of places prevent aliases, which is silly. I shouldn't have to give an email to demo your chatbot.

chias 3 days ago | parent [-]

Then proton becomes your single point of failure.

"But I use my addresses on my own domain" ok your domain registrar, then.

a2fz 3 days ago | parent | prev | next [-]

https://sidebox.net is a nice way to do this as long as the site doesn't restrict to mainstream email domains

zygentoma 3 days ago | parent | prev [-]

Google allows email suffices a la my account+anything@gmail.com.

So you can use different email addresses for different accounts while having only one Gmail account.

sirmarksalot 2 days ago | parent | next [-]

I tried this for a little while but quickly stopped as a critical mass of websites broke when I tried using it to sign in. Special characters in your email address is an edge case that produces inconsistent results even within a single product

Nab443 2 days ago | parent [-]

YMMV, I think I only tried to sign up on 3 websites where it was not working. You can fallback to the original email address in those case.

The funniest part was that for one it work great for the signup part, but they used a third party tool for licences that broke because of my e-mail. For another, only the js code was verifying the e-mail, and I could push it by removing the validation. When the owner had to validate my account, they got a message that the e-mail was incorrect when they tried to submit the form. They called me and had a great discussion about web apps security. We had a good time.

I would point out that it kind of prevents you from checking if your email is in a leak database as you need to test each aliases you used.

rvnx 3 days ago | parent | prev [-]

Little trick: You can also randomly insert dots in your email address, a bit more stealth and compatible with more sites :)

pirates 3 days ago | parent | next [-]

This has worked for me for nearly 20 years (when I made the account I didn’t know that the dots are ignored). The only time it’s been a problem was with one company whose system stripped the dots out.

You need to send them an email to cancel. When I tried they said “you need to cancel from the same email you signed up with.” :/

tomrod 3 days ago | parent | prev [-]

This can become unmanageable if you sign up for more than a few things.

rationalist 3 days ago | parent [-]

2^(username characters - 1) possibilities, but I would hate to try and keep track of which combinations I've used, or what binary sequence I'm up to.

I like using company initials & random numbers @ my domain .tld

2 days ago | parent | prev [-]
[deleted]