#sso

Wiki 3

  • don't sign in with google (the smart ape, 2026) A friend's three-year SaaS dies overnight when Google suspends his account โ€” the thread walks through cascading SaaS lockout, four post-password-reset attack vectors, and a triage rule for when SSO is actually fine
  • Google OAuth domain-takeover flaw (Truffle Security, Jan 2025) Buying a dead startup's domain for $12 lets you re-create old employee emails on Workspace and log into the dead company's Slack/Notion/Zoom via "Sign in with Google" โ€” initially marked won't-fix, $1,337 bounty after public pressure
  • SSO concentration risk SSO trades distributed risk for concentrated risk โ€” same expected loss in theory, dramatically worse failure mode in practice when the IdP terminates the relationship