Is "Sign in with Google" or "Sign in with Apple" Actually Safe?

Author: Özgür ÖZALP

You're about to start a game, and there they are: "Continue with Google" and "Continue with Apple." For a lot of people, the cursor hovers there a second too long. Is this site about to get my Google password? What happens to my account if this goes wrong? It's a fair instinct — handing your identity to some website you barely know feels risky. But the mechanism behind that button is almost the opposite of what it feels like.

The one thing that never happens: your password never leaves Google or Apple

When you tap "Continue with Google," your password is never sent to, seen by, or stored by the site you're signing into — full stop. This isn't a policy promise you have to trust; it's how the underlying protocol, called OAuth, is built. It's the same standard used by an enormous share of the web, and the spec itself is public at oauth.net if you want to read exactly how the handshake works.

Here's the part that surprises people: the login screen you type your password into is still Google's or Apple's own screen, not the website's. Here's the actual sequence:

  1. You tap "Continue with Google."
  2. A Google (or Apple) login window opens — same URL bar, same page, as if you'd gone straight to google.com.
  3. You type your password into that window, which belongs to Google, never to the site you started from.
  4. Google checks your credentials on its own servers and, if they're correct, hands the site a short-lived, single-purpose token — not your password, just a note that says "this person is verified, here's their email."
  5. The site uses that token to log you in.

Think of it like a hotel valet key. You hand the valet a special key that only starts the car and only opens the driver's door — it can't open the trunk, glove box, or unlock your house. The valet can move your car, and that's it. A login token works the same way: it proves who you are and lets one specific site log you in, and it can't be used to reset your password, see your other accounts, or do anything else with your Google or Apple identity.

What the site actually receives

Realistically, an app using "Sign in with Google" or "Sign in with Apple" gets a small, fixed slice of data: your email address, your display name, and optionally a profile photo. That's the entire payload. No access to your contacts, your files, your other logins, or your payment methods — those categories of data simply aren't part of what a basic sign-in token carries.

Apple goes a step further with Hide My Email: instead of sharing your real address, it generates a random, app-specific forwarding address. The site can still reach your inbox through it, but never actually learns your real email.

You don't even have to sign in

Worth saying plainly: on TKM, signing in is entirely optional. You can open a room, send a friend the link or a room code, and play a full match without creating any account or sharing anything. Signing in only unlocks extras — saved stats, a leaderboard spot, a friends list. If the safest option is "share nothing at all," that option is always available here, no compromise on the actual game. For every way to invite someone — link, code, or random match — see How to Play Rock Paper Scissors Online With Friends.

Why this beats a plain password signup

The traditional "pick an email and a password" signup is, ironically, the riskier default:

  • Most people reuse passwords across sites. If any one of those sites gets breached, attackers try that same email/password pair everywhere else — a technique called credential stuffing, and it's one of the most common ways accounts actually get taken over.
  • Every site that stores its own passwords is a site that could eventually mishandle, misconfigure, or leak them, no matter how well-intentioned.
  • Google and Apple pour resources into account security — anomaly detection, two-factor authentication, device verification — at a scale no individual small site can match. Signing in through them means you're borrowing that infrastructure for free.

A site using Google or Apple sign-in never has a password database for your account, because it never had a password to begin with. There's nothing there to steal.

Checking or revoking access takes about 30 seconds

Both platforms give you a dashboard listing every app connected to your account, with a one-tap way to disconnect any of them:

Revoke access there at any time, and the site's connection to your account ends immediately — no need to email anyone or wait on support.

Frequently asked questions

If my Google account gets hacked, is my TKM account compromised too? TKM never had a password of its own to steal, so your real line of defense is your Google or Apple account's own security. Keep two-factor authentication turned on there, and every app signed in through it — TKM included — inherits that protection.

How do I spot a fake "Sign in with Google" screen? Check the address bar before you type anything. A genuine screen always loads on accounts.google.com or appleid.apple.com. If any other domain is asking for your Google or Apple password, close it — that's not how a real sign-in works.

What happens to my account if I disconnect Google or Apple access? You'll just be unable to sign back in with that method until you reconnect it; your stats and match history stay exactly as they were. If you want the account itself gone entirely, you can delete it anytime from your profile settings.

Does TKM sell or share my email address? No. It's used solely to identify your account and, if you opt in, for account-related notifications — never shared with or sold to third parties.

Bottom line

Tapping "Continue with Google" or "Continue with Apple" doesn't hand your password to a stranger — it does the opposite, letting you prove who you are without your password ever leaving Google or Apple's own servers. You can skip it entirely and play anonymously, and if you do sign in, you can pull the plug on that access whenever you want.

Open rock.paperscissors.online and start a room — signed in or not, the choice is entirely yours. Türkçe versiyon: Google veya Apple ile Giriş Yapmak Güvenli mi?

Read this article in Turkish