🥳 Oh joy, another techie telling us how they courageously battled the evil Google OAuth with their trusty sidekick: Immich! 🤖 Because who doesn't want to spend their Saturday night self-hosting photos instead of, you know, using any of the gazillion cloud services available? 📸
https://michael.stapelberg.ch/posts/2025-11-29-self-hosting-photos-with-immich/ #technews #selfhosting #GoogleOAuth #Immich #photography #cloudservices #HackerNews #ngated
Self-hosting my photos with Immich

For every cloud service I use, I want to have a local copy of my data for backup purposes and independence. Unfortunately, the gphotos-sync tool stopped working in March 2025 when Google restricted the OAuth scopes, so I needed an alternative for my existing Google Photos setup. In this post, I describe how I have set up Immich, a self-hostable photo manager.

Michael Stapelberg

Master #GoogleOAuth Setup! A simple guide to secure your app with Google Sign-In in just 7 steps. Improve user experience and security today! #OAuth #GoogleSignIN #WebDev

https://teguhteja.id/seo-title-master-google-oauth-setup-a-powerful-guide-to-secure-sign-in-in-7-easy-steps/?utm_source=mastodon&utm_medium=jetpack_social

SEO Title: Master Google OAuth Setup: A Powerful Guide to Secure Sign-In in 7 Easy Steps - teguhteja.id

Master Google OAuth Setup: A Powerful Guide to Secure Sign-In in 7 Easy Steps Integrating “Sign in with Google” into your web or mobile application is a game-changer for user experience. It simplifies the login process, reduces friction for new users, and leverages Google’s robust security infrastructure. However, successfully implementing this requires a precise Google… <a href="https://teguhteja.id/seo-title-master-google-oauth-setup-a-powerful-guide-to-secure-sign-in-in-7-easy-steps/" rel="bookmark">Read More »<span class="screen-reader-text">SEO Title: Master Google OAuth Setup: A Powerful Guide to Secure Sign-In in 7 Easy Steps</span></a>

teguhteja
🚨Cybersecurity Alert! Hackers are now exploiting Google OAuth to mimic Google in a DKIM replay attack. They use phony alerts that successfully pass verification, pilfering login details in the process. Stay vigilant!💻🔒 #CyberSecurity #GoogleOAuth #DKIMReplayAttack #StaySafeOnline
https://www.squaredtech.co/hackers-abuse-google-oauth-to-spoof-google?fsp_sid=2088
Hackers Abuse Google OAuth To Spoof Google In Attack In 2025

Hackers abuse Google OAuth to spoof Google in DKIM replay attack using fake alerts that pass verification and steal login credentials.

SquaredTech

Imagine getting a Google alert that's anything but real. Hackers are reusing DKIM-signed emails via Google OAuth to bypass security—are our inboxes truly safe? Read on to uncover how this crafty loophole is exploited.

https://thedefendopsdiaries.com/exploiting-google-oauth-the-dkim-replay-attack-threat/

#dkim
#emailsecurity
#phishing
#googleoauth
#cybersecurity

Giselle’s dev team tackled Google OAuth verification using Vercel Custom Environments.

By leveraging custom domains, feature flags, and Stripe test mode, they ensured a smooth verification process without disrupting production.

Check out their elegant solution for adding OAuth login!

https://giselles.ai/blog/vercel-custom-environments-google-verification

#Vercel #GoogleOAuth #Development

Streamline Submission for Google OAuth Verification with Vercel Custom Environments

Learn how to leverage Vercel Custom Environments for Google OAuth verification while keeping your features unreleased—a practical guide based on real case

Google OAuth flaw lets attackers gain access to abandoned accounts

A weakness in Google's OAuth "Sign in with Google" feature could enable attackers that register domains of defunct startups to access sensitive data of former employee accounts linked to various software-as-a-service (SaaS) platforms.

BleepingComputer

Keep getting contacted about issues with service accounts not having access to peoples drive account. Remember service accounts need to be preauthorized.

I put up a YouTube Short to show how to do it. 54 seconds its that easy

https://www.youtube.com/watch?v=ykJQzEe_2dM

#googledevelopers #gde #googleoauth #programming #development #googledrive #googleapi

Quick and easy grant service account access to Google drive

YouTube