Hello!
I would like to secure my accounts better, and after reading many articles I still struggle with one decision.
Context
Gmail account, with long and strong password + 2fa with security key (Yubikey).
And now, for other websites (shops, social media, etc) is it better to?:
1. Use Google SSO if available
2. Use email/password login stored in the password manager (password manager secured with Yubikey too).
What do you suggest? Why?
Now, as far as Google vs. Password manager on sites that do support it: Google can be convenient, but there is the infrequent, but apparently very real risk of Google locking your account, and through that also locking these other accounts. I'm not very concerned about that risk personally, but I also would be very reluctant to put important accounts like banks and bills on a Google SSO.
To be clear: I'm not a big "google is evil" guy, but "I'm locked out of google" seems to be a regularly recurring story, but it clearly is low frequency. I do know that when things go wrong, Google is often a black box with little recourse or even any way to contact someone there, especially, I imagine, if your account is locked.
I, personally, almost always use a password manager rather than a Google SSO, just because I have it set up an it's almost as easy as the SSO.