Mfa

Sign in with Google or Facebook button and the risk of OAuth 2.0

OAuth 2.0: why you shouldn't sign in with Google or Facebook

That «Sign in with Google» or «with Facebook» button is convenient, but every time you click it you hand over more than you think. Here's what OAuth 2.0 is, where the risk lies and why signing up with your own email is still the safest option.

A USB security key and a phone showing a six-digit verification code on a desk, with an open padlock in the background — multi-factor authentication as a second door

Your password has been compromised: why only MFA truly protects you

When a breach happens, no password — however strong — is safe. The only measure that actually works requires the attacker to have something else you physically hold in your hands: that is multi-factor authentication (MFA). I explain what it is, why SMS is not enough, and how to choose it well.