Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Social Login: Single Point Of Failure… Or Opportunity?
Articles

Social Login: Single Point Of Failure… Or Opportunity?

ISBuzz TeamBy ISBuzz TeamOctober 3, 2018Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Social Media
Magnified illustration with the word Social Media on white background.
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The authentication method has been ignored in high-risk use cases. It could pave the way to a safer, easier Internet.

In his excellent Insider Feature about password alternatives and enhancements, Michael Nadeau wrote:

“The big risk with social login is that all sites a user accesses via, say, Google will be compromised if that Google account is compromised. Attackers can take control of a social account in a number of ways: social engineering, creating a fake profile, or buying a user ID and password on the dark web. Users can mitigate this risk if they turn on optional authentication features like 2FA, but many don’t.”

In January, Google software engineer Grzegorz Milka revealed in a presentation at Usenix’s Enigma 2018 security conference that less than 10 percent of active Google accounts use two-step authentication. Why not force 2FA on users? Because, Milka said, “The answer is usability. It’s about how many people would we drive out if we force them to use additional security.”

User adoption of 2FA is low because its most common implementations are cumbersome. I believe 2FA should be so easy that it could be the default setting without estranging 90% of a user base. Social login could be the mechanism to get us there.

Social login hasn’t met its full potential

Federation – of which social login is an example – manages and maps user identities between Identity Providers (IdP) across organizations and security domains via trust relationships. It addresses questions such as “Where are the user’s credentials stored?” and “Can a third party authenticate a user without seeing her login credentials?” Users who authenticate to the IdP can authenticate to other sites and services with relative ease. Social login applies federated login techniques so organizations can authenticate a user’s identity based on the assumed strength of the IdP’s authentication stack.

“Users see [social login] more as a convenience than as added security,” Nadeau wrote. “But websites and web service providers gain a level of secure authentication they might otherwise not have the resources to achieve themselves.”

Those organizations who do have the resources and reasons to create and maintain a high level of secure authentication — financial institutions and insurers, among others — have shied away from social login. They need their own dedicated authentication and authorization (“auth”) strategies. Even though social login is convenient for users and even though the auth market is largely driven by user experience, the organizations I’m describing need to maintain a degree of security and privacy control to be sure that strong auth is in place when money and other sensitive data are in play.

Don’t blame social login for the problems with passwords

Social login is a server-side analogy to the problem of end users’ tendency to re-use passwords across sites.

Whether users log in through a federated mechanism or directly to a site that manages its own auth, password-based authentication will forever be the weakest link. Social login can’t fix that. In fact, federating authentication with passwords across multiple sites simply exacerbates the risks and stakes. The password only has to be compromised once to amplify the attack to all of the sites that the authentication mechanism serves.

Sites that use social login relinquish control over the authentication process. Third parties have no way of enforcing stronger multi-factor authentication or passwordless authentication using biometrics or device recognition. They don’t get to decide when or if to step up to stronger authentication strategies.

With all that in mind, I see an upside. Federated login could make auth a lot stronger for a large part of the Internet if it moved to a passwordless mode. The change ‘just’ has to be easier than passwords; no authentication apps, one-time passwords, or the like.

Replace passwords to elevate social login

To be fair to end users, and to cultivate a more secure era, we – as a profession – have to recognize a fallacy in our control, and another single point of failure: centralized credential storage. By storing usernames and passwords in one target, organizations with large user bases have made attackers’ work easier. This weakness has been a major contributor to the rise in account takeovers.

A major part of the answer is to decentralize credential storage. By removing the target, hackers have no way of stealing and reusing identity information at scale. A mobile multifactor authentication platform that separates the authentication process from the application reduces liability and keeps encrypted credentials – and risk – dispersed on each end-user’s device.

If a federated login provider used passwordless authentication founded upon mobile device possession, facial and fingerprint recognition, and knowledge factors chosen by the end user, and if it were all stored securely on the end user’s device, then sites relying on that IdP would enjoy significantly stronger authentication.

I believe that would accelerate our progress toward a passwordless Internet, one that’s more secure and user friendly.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}