April 20, 2024, 7:08 am | Read time: 3 minutes
Anyone who shops online frequently knows this: Before making a first purchase at an online store, you must first create an account with your personal information. Some providers offer a convenient solution for this. However, according to consumer advocates, it’s better not to choose this option.
When shopping online, you often come across providers you haven’t purchased from before. It’s convenient when they offer login with a Google or Facebook account. This saves the hassle of creating an account. However, consumer advocates warn against the so-called Single Sign-on.
What is Single Sign-on and what are the risks?
Instead of having to register with your name and address for different services and providers each time, Single Sign-on (SSO) allows the use of already stored login data. “Continue with Google” or “Continue with Facebook” is often offered as an alternative to registering with an email. When users choose this option, they authenticate with the data stored in their Google, Amazon, or Facebook account. These platforms serve as so-called identity providers.
The feature was introduced to allow users quick and convenient access to portals without re-registering. The existing account with stored data serves as a kind of master key, which in many cases can also be used for payment. As convenient as the offer is, it also carries many risks, warn consumer advocates. If the original account is hacked, criminals gain access not only to it but also to all portals offering Single Sign-on for the hacked account.
Read also: Amazon changes login in the online store and app
Consumer advocates also cite another specific case where Single Sign-on was misused. In October 2022, Facebook reported that fraudsters managed to capture users’ login data with more than 400 apps for Android and iOS. All these apps offered login via Single Sign-on, but the input screen was fake. Instead, it led to a phishing form that directly sent the login data to the fraudsters.
Personal data doesn’t just end up with the online store
Another risk of Single Sign-on, according to consumer advocates, is the data transmitted. When you log in to an online store with your Google account, for example, you transmit not only your name and address but also other data stored in the account. This can include preferences, habits, and shopping behavior information, according to experts.
With the data collected in this way, detailed profiles of a person can be created, which may be forwarded to third-party providers. These providers can then use the data sets for personalized advertising and offers. Therefore, users should be well-informed about what data is requested, whether it is stored encrypted, and with which providers it might be exchanged before using Single Sign-on.
It’s even better to create your own customer account with the store–with a unique username, password, and, if available, two-factor authentication (2FA). While this is more cumbersome, it significantly increases security. If you can’t or don’t want to remember all the logins, you can use password managers.