Lesson 5.5

5.5: The Audit Nobody Does

9 minutes

The Audit Nobody Does

Every “Sign in with Google” you’ve clicked since 2015. Every quiz app that asked to see your profile. Every device you’ve ever stayed logged in on. In all likelihood, every bit of it is still authorized right now, because access granted online has a birthday but no funeral. This closing lesson is the audit of everything you’ve quietly said yes to, and the habit of purging it.

Part 1: Third-party grants

When you signed in to some app “with Google” (or Apple, or Facebook), you granted it standing access to parts of your account: profile at minimum, sometimes contacts, calendar, or full mailbox access for tools that promised to organize your inbox. Then two things happened. You forgot within the week, and the grant lived on. Years later it’s still active, held by a company that may have been sold, abandoned, or breached since. Module 1 taught you that leaked passwords get merged and replayed. A stale OAuth grant is the same shape of problem, except what leaked is standing access.

The audit goes one master-key account at a time. Google → security settings → third-party apps with account access. Apple ID → Sign in with Apple. Facebook → apps and websites. The rule is the same as the extension audit in 4.4, because it’s the same disease: don’t recognize it, or don’t use it anymore → revoke. Be ruthless. Revoking costs nothing but a re-authorization if you’re wrong, while every kept grant is a standing door whose key sits with someone else’s security team. Give special scrutiny to anything with mail access. That grant is your master key, delegated.

Part 2: Sessions and devices

You met per-site session checks in the 5.3 drill; this is the standing version. Your master-key accounts each show every device currently signed in, and the list is usually archaeology: the 2019 laptop you traded in, the ex’s tablet from a shared streaming login, a browser session at an address you don’t recognize. Every stale entry is a live credential on hardware you no longer control. Google, Apple, and Microsoft all keep this under security → devices. Sign out anything you can’t name, and let the phones and laptops you actually hold sign back in. Then do the same pass inside your password manager’s account settings. The vault’s own sessions deserve the shortest leash of all.

Part 3: The annual purge

The last piece goes back to Module 1’s oldest lesson. Every dormant account you still technically own is a future breach entry with your name in it: the forum from 2013, the food-delivery app from one vacation, the store you bought a single gift from. You can’t be leaked by a database you’re not in. So once a year, spend thirty minutes shrinking your footprint. Your password manager is now, conveniently, a complete inventory of every account you have. Sort by oldest, and for anything you haven’t touched in years, log in one last time and find delete account (search “[site] delete account” when it’s buried — services like justdeleteme.xyz index the paths). Delete rather than abandon: an orphaned account keeps your data on someone else’s server forever, while a deleted one leaves the pool before the pool leaks.

The shape of the habit

None of this is daily work. Grants and sessions become a quarterly glance once the first big cleaning is done, and the purge is annual. Which is exactly why it all feeds the next page: the checklist that turns five modules of one-time setup into fifteen minutes of maintenance a quarter. That’s the last lesson. Go collect your one-pager.