







Why rely on big tech for your 2FA codes when you can be your own provider?
Top 5 Limitations of Google BeyondCorp | Twingate
Google BeyondCorp pioneered Zero Trust at scale—but it was built for Google. Here are the top 5 limitations for organizations trying to apply it themselves.

Why does Google+ insist on having your real name?
Google+ is the latest social network to demand people's real names. But why do they need them?

Persistent, Sandboxed, Single-Site Browser (firejail and proxychains) - Michael Altfield's Tech Blog
Or how to avoid getting locked-out of another Google Account This guide will describe how to setup a persistent browser (for Evil Corp) that’s isolated in a sandbox (with firejail) and forced to use a SOCKS5 proxy to retain a static IP address (using proxychains) Have you ever been locked out of your own account, and then got an email for your service provider annoyingly letting you know that they’ve “blocked a login attempt — for your protection?“ There’s countless reports of frustrated users who have permanently lost access to their own gmail accounts because of Google’s faulty “fraud protection” systems that locked the account owner out of their own account, due to false-positives. Problem Especially the past 10 years, large corporations have been using machine learning anomaly detection systems on their login pages. Unfortunately, sometimes this is (ab)used to have priority over credential authentication challenges. Even if you enter your username, password, and 2FA credentials correctly on the very first login attempt, you may get locked out of your own account because you “look different” Even if you enter your username, password, and 2FA credentials correctly on the very first login attempt, you may get locked . . . → Read More: Persistent, Sandboxed, Single-Site Browser (firejail and proxychains)

How Google is killing independent sites like ours - HouseFresh
And why you shouldn’t trust product reviews from big media publishers ranking at the top of Google.

Why Did Google Choose To Implement gRPC Using HTTP/2?
Why Did Google Choose To Implement gRPC Using HTTP/2? Understand the story behind the design of gRPC and its mission. Background gRPC is an open-source high-performance RPC framework developed by …

Google accused of ‘predatory conduct’ over Gmail API withdrawal
Google has exploited a regulatory gap to withdraw access to the Gmail API, according to UK startup Gener8.

Startups
Use Google Cloud credits to build and grow your startup business with innovative products and solutions designed for your needs.
Why 83% of organizations reportedly trust open source with their most sensitive assets
There is now an increasing trust in open source alternatives to take organizations where they want to go for their IAM and token requirements.

A Duty of Loyalty for Privacy Law
Data privacy law fails to stop companies from engaging in self-serving, opportunistic behavior at the expense of those who trust them with their data. This is a
A week of not using a search engine
A week or so ago, I wondered if I actually needed to use a search engine as much as I did. Why was I sending so much traffic to a third party service, especially since I can’t seem to find a search engine which aligns with my ethics and delivers good search results?

De-google-ify Internet - Main Page
The web giants centralize our digital lives in exchange for their services The Free Software community offers alternative ethical services The Framasoft network intends to prove itby hosting them

The Technical Feasibility of Divesting Google Chrome – Knight-Georgetown Institute
As the European Commission advances efforts under the Digital Markets Act to require Google to share its search data with competitors, lessons from historic antitrust remedies underscore how data access could be transformational in the AI-powered search market. While the Commission’s proposals represent a novel and comprehensive approach, key improvements to data scope and sharing frequency, privacy protections, and dispute resolution are needed. US courts and enforcers charged with implementing similar provisions should take note.

It's really cool that people are now using Bluesky not only from servers they host themselves, but servers they *wrote* themselves (or someone else here did), adding features the standard one doesn't have ❤️ Like, I now have 2FA again on my PDS because @baileytownsend.dev just went and built it
Matt Kane
Cirrus PDS now support passkey auth. It was a bit of a puzzle adding it to a tool where where the admin is all CLI, but I'm really pleased with the flow I came up with. Give it a go! github.com/ascorbic/cirrus If you don't know what Cirrus is, it's a really easy way to host your own Bluesky data
The question came up today "When will Bluesky support 2FA for things like passkeys", etc besides email. I've talked about it a bit spread out, but thought I'd do a 🧵 on the lay of the land with auth and 2FA in the atmosphere
Felix Schneider
Regarding one question from today's atproto x npmx x svelte meetup: npmx.social already supports 2FA with email thanks to @pds.dad 🥳💐