Urgent.News

What's breaking now, across thousands of outlets.

Tech

"Sign in with Google": Why It Bounces You Out and Back

You click "Sign in with Google." The page jumps away, jumps back a second later, and you are in. So why the round trip — why not just type something on this page? Because the safe way is to never hand over your password . The old way: hand over your password Twenty years ago, if a site wanted to read your data somewhere else, you gave it your password. Convenient — and costly: It stored your…

Clicking the "Sign in with Google" button takes you to Google's site for approval, then back to the original site with a one-time authorization code. This passcode allows the original site to access your Google account without knowing your password, creating a secure single-use ticket. The original site is not storing your password and can only use the passcode to access your account under specific conditions and for a limited time.

This system was introduced to replace older methods where passwords were shared with third-party sites, which was risky as passwords were often stored in plain text and could potentially be misused. The new system maintains your password's security while still allowing third-party services to access your account.

The approval step is crucial as it gives you a clear view of what permissions you are granting. However, people often make mistakes when approving these requests, such as not fully reading the consent prompt or not realizing that the third-party app can access various parts of their Google account like email and calendar.

While "Sign in with X" doesn't guarantee the security of the third-party site, it does ensure that your password isn't shared. OAuth is an authorization protocol, not a login protocol, and its latest version includes mandatory Proof Key for Code Exchange (PKCE) for enhanced security.

You can revoke access to third-party apps under 'authorized apps' at any time. So even if a malicious app gets your passcode, it can't be used indefinitely and you have the ability to limit its access.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

SSH Connection Reset by Peer: Trace the Failure Before Changing Config

An SSH connection that resets is different from one that is refused or simply times out. The TCP connection may have started successfully, only for the server—or something between you and it—to…

  • Connection resets by peer occur before password/key prompt
  • Verify TCP port reachability with tools like nc or Test-NetConnection
  • Check server SSH service logs for bans or connection limits

Gas Optimization Audit: Poloniex

Gas Optimization Audit: Poloniex Target Protocol : Poloniex (TVL: $1648.2M) Poloniex – Gas‑Optimization Audit Prepared by: Senior DeFi Security Researcher – [Your Name] Date: 11 Oct 2026 1.

  • Poloniex commissioned gas optimization audit of on-chain components.
  • Audit found 28 gas inefficiency patterns, causing 12% higher transaction costs.
  • Implementing top fixes could save $1.2 million per quarter.

Restrict SSH Logins with AllowUsers Without Locking Yourself Out

A valid SSH key or password does not guarantee that an account can log in. OpenSSH can apply an additional server-side filter: AllowUsers lists which accounts are eligible to connect.

  • AllowUsers restricts SSH logins to specified users.
  • Multiple users can be allowed by separating names with spaces.
  • Incorrectly configured AllowUsers can lock out legitimate users.

More from Sunday 11 October →