Skip to main content

I find it a little ironic that my little test firebase project that uses Firebase Auth and Microsoft and Google single signin got flagged by Google as being a suspicious phishing site and flashed a bright red screen on the browser right when I was demonstrating it to a customer.

Whereas the single Google SignIn on this “security” forum shows a seemingly unrelated company called insided.com on the Signin pop up… I’m sure the badly written AI phishing identifier program will take care of this in dure course.

Hi ​@ChrisMICDUP Thanks for your post. And appreciate you mentioning this. Our new platform is on Gainsight Insided. Gainsight actually acquired Insided back in 2022. You can read the article here. We chose this platform for it’s features, capabilities and ease of use so we could bring you a more centralized hub for cloud security learning and Q&A support, among many other programs we’re offering and coming soon to Community 😀 

If you have more questions feel free to ask. Happy to get the answers for you. Hope this helps. And happy you’re here in the Community!


Thanks Matthew, Yes I visited the insided.com site and thought this was the case. However you’re sort of missing the point. My not very veiled dig at Google  Cloud Compliance (which in hindsight, probably wasn’t suited to this forum) was that the your Sign in with Google popup on security.googlecloudcommunity.com says “to continue to insided.com”. For my own site, Google support advised me that my own test web site (where the signin URL on the OAuth Consent popup) did not match the domain) was an indicator that the site was maybe a phishing scam.

 

I note that the  Sign in with Google pop up on the Google Developer forums has a Google domain.

Although on further investigation google.dev has a SSL cert issued by Amazon, not Google Trust Services, which continues to raise red flags in my newly paranoid mind