CYBER WELFARE

Protect your Digital Privacy

Social login risks: what you share when you sign in with one click

Helen has just downloaded an app to organise the family’s recipes. On the first screen she can create an account with an email address and a password, or tap “Sign in with” and use the social media profile she opens every evening. She chooses the second, as she almost always does: one tap, one confirmation, and she’s in.

That button is called social login: it’s the system that lets you sign in to a service using a social media account instead of a new password. It’s convenient, and there’s nothing wrong with having used it. But each time, two things happen that you don’t see: the app receives part of the data in your profile, and your social media account becomes the key to one more service.

So the more useful question isn’t “is it safe or not?” but a different one: if that connection were misused, or if that key were lost, what would be touched?

This post answers it by looking at the three aspects by which the security of any information is measured: that it stays private, that it stays correct, and that it stays available. They are the practical translation of three technical words — confidentiality, integrity, availability — and they help you see that social login risks go well beyond “someone knows I use that app”.

It expands on the recommendation about limiting social login to the services where it genuinely helps, and keeping the important ones separate.

Three questions to measure an impact

Before getting into the details, it’s worth having the right questions at hand. For any service you sign in to with your social media profile — and not only when something seems odd — they are these:

  1. What has this app been able to see in my profile, and what can it still see? — this is the confidentiality question.
  2. What can it do in my name, on the social network or in the service itself? — this is the integrity question.
  3. What would I no longer be able to use if I lost access to my social media account? — this is the availability question.

Applied to a game you tried once, these questions produce a modest answer. Applied to all the services linked to the same profile — recipes, online shop, photos, courses — the answer changes. That is exactly where social login changes the maths: the impact is no longer measured on the single app, but on the social media account that acts as its key, and on everything that key opens.

1. Confidentiality: your data stays with the people you chose to give it to

Confidentiality is the guarantee that information can be read only by those who are authorised to read it. Social login puts it to the test because, at the moment you connect, you give a third-party app — an outside service that doesn’t belong to the social network — permission to read part of your profile.

A practical example

When Helen confirms the sign-in, the window lists what the app will receive: name, profile photo, email address. Sometimes the list is longer: date of birth, town, pages followed, friends list. These are the app’s permissions — the parts of your profile that the social network agrees to share on your behalf. They take a few seconds to read, but hardly anyone does.

What the incident looks like

Nobody “breaks into” Helen’s profile. The data she agreed to share now also sits on the app’s servers, which keep it according to their own rules. If that app suffers a data breach, or is sold to another company, the information goes down paths Helen never chose. In the past, some quiz apps collected data not only from the people who used them but also from their friends; social networks’ rules are stricter today, but the principle stands: what you share with an app can concern other people too.

What to watch for

  • services you don’t remember authorising appear in the connected apps section of your profile;
  • an app with a simple purpose asked for access to your contacts, friends or messages;
  • you receive welcome emails or newsletters from services you don’t remember signing up to.

What to do

Before tapping “Sign in with”, look at the data being requested: if a recipe app wants your friends list, a separate account is the better choice. For the apps you’ve already connected, open your social network’s settings and check what each one can still read. The mechanism behind that consent window is explained in the post on how social login works.

2. Integrity: only what you decide happens on your profile

Integrity is the guarantee that data and actions aren’t altered by anyone without the right to do so. Here, social login weighs in a different way: it’s no longer about what an app can see, but about what it can do in your name.

A practical example

Some apps, besides reading, ask for permission to post: share a result, invite friends, send messages. To do so they use a token — a kind of digital pass that the social network gives the app after you consent, letting it act without asking for your password each time. As long as the token is valid, the app can do everything you allowed, even months after you last opened it.

What the incident looks like

The quiz app Helen tried two years ago passes to a new owner, or is breached. Overnight, a post promoting an unlikely discount appears on her profile, and some friends receive a message with a link. Nobody stole her password: the app was using the posting permission it had been given. And the people who receive the message trust it, because it comes from Helen. How these connections get exploited is the subject of the post on attacks through connected apps.

What to watch for

  • posts, comments or likes on your profile that you don’t remember making;
  • friends asking you about strange messages sent from your account;
  • invitations to games or apps sent to your contacts without you sending them;
  • apps in your settings with posting or management permissions you don’t need.

What to do

Grant permission to post only when there’s a clear reason for it. Remember that uninstalling an app from your phone doesn’t revoke its access: the authorisation lives on the social network’s servers and has to be removed from there. And if you’ve changed your profile password, check your connected apps anyway: a token already granted may keep working.

3. Availability: you can get in when you need to

Availability is the guarantee of being able to use your data and your services at the moment you need them. It’s the easiest impact to recognise, and with social login it takes a particular form: one locked door that locks many others.

A practical example

Helen signs in with her social media profile to the recipe app, the shop where she buys the children’s clothes, the service that prints her photos and an online course. In none of them does she have a password of her own. Her social media account has become a single point of failure: one element that all the others depend on.

What the incident looks like

One morning the social network suspends Helen’s profile for a security check, or someone takes it over. For days she can’t get in — and not only there: the recipe app, the shop and the course all ask her to sign in “with” that profile. Some of them hold open orders and materials she has already paid for. And if one day she decided to close the profile, she would first have to remember every service that relies on it.

What to watch for

  • you can no longer remember how you signed in to a service: email and password, or social media profile;
  • some services you use often have no password of your own;
  • your social media account has no second sign-in factor and no up-to-date recovery number or email;
  • you receive sign-in alerts for your social media profile from places or devices you don’t recognise.

What to do

Protect your social media account as you would your main email: a password used only there and a second factor switched on, as the recommendation on protecting accounts with a second factor explains. For important services — where there are payments, documents or work — choose an account with its own credentials. Many services let you add an email address and password even to an account that started with social login.

AspectWhat can happen with social loginWhy it matters
ConfidentialityThe app receives profile data, sometimes about friends and contacts too, and keeps itThe data leaves your control and can share the app’s fate
IntegrityAn app with posting permissions can write, share or send messages in your nameThe harm reaches your contacts, who trust the message because it comes from you
AvailabilityIf your social media account is locked or hacked, you lose access to every linked serviceOne locked door locks many others, including important ones

One scenario that brings them together

In 2021 Helen uses her social media profile to sign in to a quiz app, which asks for her name, photo, friends list and permission to post her results. She also uses it for the online shop and for her English course.

In 2023 the quiz app passes to another company. Helen uninstalled it long ago, but the authorisation is still there.

From there, in sequence: her data and her friends’ data end up in the new owner’s archive (confidentiality); the posting permission is used to share a misleading link in her name (integrity); the social network notices the unusual activity and suspends the profile, and for a week Helen can get into neither the shop nor the course (availability). Three different impacts, a single cause: a connection granted in a minute and left active for years.

The concrete fallout is the subject of the post on the consequences of a hacked social account.

The impacts that show up later

Not every effect appears right away. Some develop over time, which is why “nothing has ever happened” isn’t a reliable check.

  • Authorisations that outlive their use. An app you no longer open can stay connected for years. Some social networks let inactive access expire, but not all of them, and not always.
  • Data already copied. Revoking an app stops it reading new data, but doesn’t delete what it has already received: for that, you need to ask the service itself to erase it.
  • Apps that change hands. A connected service can be sold together with its users and the authorisations it has collected.
  • A profile that tells a lot. Every connection tells the social network which services you use and when. This is profiling — building up a picture of your habits.

To notice when one of these effects is already under way, there’s the post on the signs of suspicious connected apps.

This isn’t a reason to treat every “Sign in with” button with suspicion. It’s the reason protection has to be a deliberate choice: using social login only where it helps, and reviewing your connected apps now and then, reduces all four of these effects, including the ones you’ll never see.

Not all services weigh the same

The impact depends on what a service holds and on what the app can do with your profile.

Type of linked serviceMain impactWhy
Services with payments or a saved cardIntegrity and availabilityPurchases possible in your name, orders stuck if you lose access
Cloud storage, photo and document archivesConfidentiality and availabilityYears of memories and files, often other people’s too
Work toolsAll three, with effects on othersThey involve clients and colleagues, and a lockout stops your work
Health, wellbeing or dating appsConfidentialityVery personal information, tied to your public profile
Apps that post or invite friendsIntegrityThey have permission to write in your name on the social network
Games and quizzes tried onceLow on their own, high with broad permissionsForgotten for years, often with access to friends or posting

Social login isn’t a mistake in itself: it becomes one when it’s used for services that deserve a key of their own. For an occasional service without broad permissions, it may well be the sensible choice.

Why “harmless” connections matter too

The reasons for tapping “Sign in with” are almost always good ones. They don’t always stand up to scrutiny.

What we tell ourselvesWhy it doesn’t hold
“That way I don’t have to remember another password”There are ways to avoid remembering them all without tying every service to your social profile: that’s what storing passwords safely is about
“It only asks for my public profile”The permissions list may include your email, friends or posting: it needs reading, not guessing
“I deleted the app, so that’s the end of it”The authorisation stays on the social network until you revoke it there
“I can always disconnect it later”True, but the data already shared stays with the app, and meanwhile the connection has stayed active

If the answer to “why does this app need to know my profile?” is a hesitation, that’s usually an answer in itself.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessRecognising that every “Sign in with” shares data, delegates actions and creates a dependency on a single account
SkillsBeing able to read confidentiality, integrity and availability as three questions to ask before connecting an app
Secure BehaviourRegularly reviewing connected apps, revoking what isn’t needed and keeping separate credentials for important services

Reference level: FL2 — Beginner. This is the level at which you move from “I know social login is convenient” to “I understand what happens when I use it.” To see where you stand on your other digital habits as well, you can take the digital resilience self-assessment.

Summary

  • Confidentiality is about what gets shared: profile data, sometimes friends and contacts, and the list of services you use.
  • Integrity is about what an app can do in your name: post, invite, send messages, even long after you consented.
  • Availability is about what you lose if your social media account is locked: every service that relies on it.

Social login doesn’t produce just one impact: it opens the door to all three, on your profile and on every service you’ve linked to it.

One thing to do today. Open the settings of the social network you use most and find the section for connected apps and websites. Check three things: which apps are there, what permissions they have, and which ones you use to sign in to important services. It takes about ten minutes, and it covers all three impacts at once.

Related content

Related resources

Short pieces from the Resources section, for anyone who wants to focus on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.