Live data from Hacker News

Ask HN: Should we own the free stuff we pay for?

news.ycombinator.com

261–270 of 309 posts

Re: Ask HN: Should we own the free stuff we pay for?

#261

You can't compel a company to provide you with a service. That's a little too close to slavery for society's taste. If a company doesn't provide you with a service you agreed to, you can get damages from a court, but you have to use such services as your contract agreed. It stinks to end up on the wrong end, but that's part of the cost of getting such massive benefits for free. If you want something more reliable or…

That concept of slavery doesn't apply to companies. Companies are imaginary entities.

Re: Ask HN: Should we own the free stuff we pay for?

#262

Earlier quoted context omitted.

Social logins only carry your information and a token, and you can enter to your profile and add a password too (99% of the time). So, you can use social login (OpenID Connect in reailty), as an automated form filler and add your password, so your account will be effectively won't depend on that provider anymore. I use a lot of services like that.

>> Social logins only carry your information and a token, and you can enter to your profile and add a password too (99% of the time). I think the whole point is not having to create yet another password. One solution to all of this is to have some kind of durable identity verification that the user controls and can use everywhere. There are serious challenges with that of course, which is why we don't have it yet.

> I think the whole point is not having to create yet another password.

That's the fallacy. You're always creating a new password. Only its storage location is changing. You can store a password in a variety of ways and places. When you use a social login, you're using a time limited password stored in the OIDC provider. And if you lose your account there, you lose all your passwords.

Also, you can store your passwords in OS key chains (Linux, macOS), browser password managers (Mozilla Lockwise/Firefox), in myriad of other online/offline password managers, on a text file or paper.

Many sites allow you to "reset" your password for an account created with a social login. However, if you created an account with Google OIDC and lose access to your GMail account, that's another matter.

Re: Ask HN: Should we own the free stuff we pay for?

#263

Earlier quoted context omitted.

Social logins only carry your information and a token, and you can enter to your profile and add a password too (99% of the time). So, you can use social login (OpenID Connect in reailty), as an automated form filler and add your password, so your account will be effectively won't depend on that provider anymore. I use a lot of services like that.

How do people remember which social login they used for any given site? There are usually multiple and they overlap between sites and none work with every site.

People generally tend to use one of them, mostly Google.

However, I always sign-up with an e-mail directly if possible, and don't use OIDC login pathways. If I had to use or was lazy during registration, I change my password immediately, so I can use an e-mail/password/2FA path.

Re: Ask HN: Should we own the free stuff we pay for?

#264

Earlier quoted context omitted.

Social logins only carry your information and a token, and you can enter to your profile and add a password too (99% of the time). So, you can use social login (OpenID Connect in reailty), as an automated form filler and add your password, so your account will be effectively won't depend on that provider anymore. I use a lot of services like that.

Finding the place to enter and save and confirm a password sounds a lot harder than just putting in my first name, last name, email and a password in the first place.

Yeah, most new services allow sign-up with e-mail. However, there was a brief period which made it almost impossible to register without a social registration path.

Re: Ask HN: Should we own the free stuff we pay for?

#265

Google is simply not a very reliable business partner for tech. I have a decade worth of experience in the Danish public sector, where I’ve had plenty of great experiences with both Amazon and Microsoft. I know that a lot of people would prefer things to be open source, but part of what you pay for in an Enterprise Organisation is availability of support. When AWS first entered the European market, most of what they…

Google is an online advertising monopoly at heart and that breeds the complacency all monopolies instill in their salespeople. That’s why they are an irrelevance in the cloud services market despite arguably superior technology, just like telco monopolies that have the same sense of entitlement.

Re: Ask HN: Should we own the free stuff we pay for?

#266
post #228

Earlier quoted context omitted.

We have email porting already. With a custom domain, you can point it at any mail host you like. It costs a few bucks a year. There's no reason for a complicated legal structure to ensure mail forwarding (which just begs for abuse). Users already have the power. Use it.

Are you volunteering to call my grandma and walk her through setting that up? Are you also going to pay the yearly domain fees? No? The legal framework needs some work.

Are you suggesting that everyone has a legal right to a free email address? Phone numbers aren't free either, a phone line is way more expensive than a domain.

If you think there's real demand for email portability, go into business! A service that lets you buy a domain and route to different email providers is well within the abilities of a single programmer. Make the UI idiot proof and charge a few bucks more than the registration fee.

Re: Ask HN: Should we own the free stuff we pay for?

#267
You are not overreacting.

Google’s aversion to paying humans to provide customer service is actually a plus in most cases, as that means the nonexistent humans cannot be social-engineered into hijacking your account as is all too easy at cellular carriers. But having dependencies on as arrogant and high-handed a company as Google (or Apple for that matter) is asking for trouble.

Hosting your own email means getting a domain name from a DNS hosting provider, sadly that is also a weak point of vulnerability. I’ve been doing this for 20 years now, but I wouldn’t be confident that a determined attacker couldn’t take me out despite U2F 2FA with my DNS provider.

Re: Ask HN: Should we own the free stuff we pay for?

#268

Earlier quoted context omitted.

Finding the place to enter and save and confirm a password sounds a lot harder than just putting in my first name, last name, email and a password in the first place.

Yeah, most new services allow sign-up with e-mail. However, there was a brief period which made it almost impossible to register without a social registration path.

I've run into that a few times, yeah. I walk away if that's the requirement to join.

Re: Ask HN: Should we own the free stuff we pay for?

#269

Earlier quoted context omitted.

I would imagine it takes the form of a government "porting server", where anyone can query an email address and receive back a different target email address. All people sending email will be required by law to first consult the porting server to determine where to send email. It could be as simple as an http endpoint. Total development costs and running costs could be pretty low - low enough that the government can…

Having the government having information about everyone’s email address… What could possibly go wrong?

Probably nothing? They (or we I guess) have phone numbers and addresses as well.

Re: Ask HN: Should we own the free stuff we pay for?

#270
post #53

Earlier quoted context omitted.

Good to hear that you have protections around this in the UK. I know that in Sweden several political, and even ideological organisations have had their accounts frozen because of things they said or held true. Entirely legal things I should add.

Could you provide links? We have similar rules so I'm a bit surprised...

Not really, this is people I know personally. I know some of them have mentioned it publicly but can't find any links. Would be in Swedish anyway. I know two people off the top of my head that had their personal accounts suspended for legal political activity, for organizations it's pretty much any organisation on the right side of the spectrum.
Post reply on HN