Skip to content

"Sign in with" permission abuse

In plain terms

"Sign in with Google" or "with Facebook" grants a service access to your account. That access stays open long after you've stopped using the service — sometimes for years.

Definition

Third-party sign-in permission abuse means obtaining, through the legitimate "Sign in with…" mechanism, access to data or functions on your main account that goes beyond what the requesting service needs to know. The access granted is long-lasting, and it survives after you stop using the service.

How it works

The mechanism itself is sound, and has a real advantage: the third-party service never receives your password. What it receives is a permission, whose scope is described on the consent screen — the one you approve without reading, because it appears in the middle of a sign-up and looks like a formality. Yet the difference is significant between "know your email and name" and "read and send your email," "access your files," or "post on your behalf." Two properties make this a case apart. The first is duration: the permission stays active until you revoke it, and uninstalling the app isn't enough. The second is independence from the password: changing your main account's password doesn't revoke access already granted. If the third-party service is later sold, abandoned, or compromised, the access it holds on your account stays exactly what it was.

Warning signs

  • Consent screen asking to read your email, access your files, or post on your behalf, for an unrelated service
  • A minor app or site offering third-party sign-in as the only option
  • Messages or posts made in your name that you didn't write
  • A long list of authorized apps in your main account's settings, many of them unfamiliar
  • An inactive or acquired service whose permission stays active

How to verify

Read the consent screen before approving it and compare what's being asked to what the service does — an image-editing tool has no need for your email or address book. Review the list of authorized apps in your main accounts' security settings once a year: that's where the buildup shows.

What to do

Prefer creating a dedicated account when the service doesn't need your data, and grant only what its function justifies. Remove permissions for services you no longer use, without waiting for an incident.

If it already happened

Revoke the permission from your main account's security settings — that's the action that cuts off access, uninstalling doesn't. Then change your password and check your open sessions, knowing that changing the password alone wouldn't have been enough. Review your email account's auto-forwarding rules, since write access can be used to create one. Report the incident to the relevant authority.

Frequently asked questions

Is this riskier than creating an account with a password?
In one respect it's safer: the third-party service never learns your password, so a breach there doesn't expose it. In another it commits you more: you grant lasting access to your main account. The risk depends on the scope of what you grant, and on the forgetting that follows.
I changed my password — is the access cut off?
No, and that's the most counter-intuitive point in this fiche. A permission is independent from the password: it's revoked in the list of authorized apps on your account, and nowhere else.

Official sources

This article is part of the Data and digital identity family. Last updated: 2026-09-03.