As part of an ongoing effort to reduce my reliance on Big Tech services that could disappear at any time, I'm removing single sign-on (SSO) connections between my Google accounts and third-party services. This is one of several high-level goals I made for myself this year and described in Online Accounts 2025 (Premium) in early February.
Since then, most of my initial work revolved around the YouTube drama I documented in great detail in From the Editor’s Desk: Online Accounts, a Cautionary Tale (Premium). More specifically, the fact that I had never formally backed up that data. Here's a quick update on that work.
The initial backup of my Thurrott.com YouTube channel took longer than expected, in part because of the storage requirements, and in part because I made some mistakes early on. But I finally figured that out, and got started on the actual backup, which I calculated would take up about 3.4 TB of storage. I did conclude that download over the subsequent weekend in mid-February, and so that ended quietly. My storage prediction was a little high, but that's fine. The 4 TB external HDD I bought can handle it for now, and when I finally get a NAS, I can move to a more formal backup process (for all my important data).
Meanwhile, there's more to do.
? The problem with SSO
Big Tech online accounts, especially those offered by Google--meaning consumer "Gmail" accounts and commercial Workspace accounts--offer users a convenience nicety in the form of Sign in with Google. This service lets you sign in to a third-party (meaning, in this case, a non-Google) online account using your Google account. Doing so is seamless and easy, and it passes through whatever security and authentication methods you've established with that account.
In my case, I have passkeys associated with my primary Google accounts (one Workspace, one consumer/Gmail) stored in Proton Pass, the password manager (really, identity manager) that I use and strongly recommend. You can learn more about this in Password Management Basics (Premium), but passkeys are the most secure way to authenticate yourself online and they can also be the most convenient, depending on the implementation. In Google's case, I see one of two interfaces when I have to authenticate with a Google account passkey stored in Proton Pass on my PCs. It either pops up right in the browser, which is preferable (it is immediate and seamless), or I have to scan a QR code with my phone, which takes a few seconds.
Google's implementation of passkeys is one of the best out there, so what's my problem? It's secure, it's seamless, and it just works. Why would I work to remove these connections?
My YouTube drama was an unwanted reminder that Big Tech could, at any time, prevent you from accessing your own data and, worse, lock you entirely out of a crucial online account. I'm doing other work to ensure that my most important data is replicated in multiple places to help mitigate some of that...
With technology shaping our everyday lives, how could we not dig deeper?
Thurrott Premium delivers an honest and thorough perspective about the technologies we use and rely on everyday. Discover deeper content as a Premium member.