You can't compel a company to provide you with a service. That's a little too close to slavery for society's taste. If a company doesn't provide you with a service you agreed to, you can get damages from a court, but you have to use such services as your contract agreed. It stinks to end up on the wrong end, but that's part of the cost of getting such massive benefits for free. If you want something more reliable or…
Ask HN: Should we own the free stuff we pay for?
261–270 of 309 posts
Re: Ask HN: Should we own the free stuff we pay for?
#262Earlier quoted context omitted.
Social logins only carry your information and a token, and you can enter to your profile and add a password too (99% of the time). So, you can use social login (OpenID Connect in reailty), as an automated form filler and add your password, so your account will be effectively won't depend on that provider anymore. I use a lot of services like that.
>> Social logins only carry your information and a token, and you can enter to your profile and add a password too (99% of the time). I think the whole point is not having to create yet another password. One solution to all of this is to have some kind of durable identity verification that the user controls and can use everywhere. There are serious challenges with that of course, which is why we don't have it yet.
That's the fallacy. You're always creating a new password. Only its storage location is changing. You can store a password in a variety of ways and places. When you use a social login, you're using a time limited password stored in the OIDC provider. And if you lose your account there, you lose all your passwords.
Also, you can store your passwords in OS key chains (Linux, macOS), browser password managers (Mozilla Lockwise/Firefox), in myriad of other online/offline password managers, on a text file or paper.
Many sites allow you to "reset" your password for an account created with a social login. However, if you created an account with Google OIDC and lose access to your GMail account, that's another matter.
Re: Ask HN: Should we own the free stuff we pay for?
#263Earlier quoted context omitted.
Social logins only carry your information and a token, and you can enter to your profile and add a password too (99% of the time). So, you can use social login (OpenID Connect in reailty), as an automated form filler and add your password, so your account will be effectively won't depend on that provider anymore. I use a lot of services like that.
How do people remember which social login they used for any given site? There are usually multiple and they overlap between sites and none work with every site.
However, I always sign-up with an e-mail directly if possible, and don't use OIDC login pathways. If I had to use or was lazy during registration, I change my password immediately, so I can use an e-mail/password/2FA path.
Re: Ask HN: Should we own the free stuff we pay for?
#264Earlier quoted context omitted.
Social logins only carry your information and a token, and you can enter to your profile and add a password too (99% of the time). So, you can use social login (OpenID Connect in reailty), as an automated form filler and add your password, so your account will be effectively won't depend on that provider anymore. I use a lot of services like that.
Finding the place to enter and save and confirm a password sounds a lot harder than just putting in my first name, last name, email and a password in the first place.
Re: Ask HN: Should we own the free stuff we pay for?
#265Google is simply not a very reliable business partner for tech. I have a decade worth of experience in the Danish public sector, where I’ve had plenty of great experiences with both Amazon and Microsoft. I know that a lot of people would prefer things to be open source, but part of what you pay for in an Enterprise Organisation is availability of support. When AWS first entered the European market, most of what they…
Re: Ask HN: Should we own the free stuff we pay for?
#266Earlier quoted context omitted.
We have email porting already. With a custom domain, you can point it at any mail host you like. It costs a few bucks a year. There's no reason for a complicated legal structure to ensure mail forwarding (which just begs for abuse). Users already have the power. Use it.
Are you volunteering to call my grandma and walk her through setting that up? Are you also going to pay the yearly domain fees? No? The legal framework needs some work.
If you think there's real demand for email portability, go into business! A service that lets you buy a domain and route to different email providers is well within the abilities of a single programmer. Make the UI idiot proof and charge a few bucks more than the registration fee.
Re: Ask HN: Should we own the free stuff we pay for?
#267Google’s aversion to paying humans to provide customer service is actually a plus in most cases, as that means the nonexistent humans cannot be social-engineered into hijacking your account as is all too easy at cellular carriers. But having dependencies on as arrogant and high-handed a company as Google (or Apple for that matter) is asking for trouble.
Hosting your own email means getting a domain name from a DNS hosting provider, sadly that is also a weak point of vulnerability. I’ve been doing this for 20 years now, but I wouldn’t be confident that a determined attacker couldn’t take me out despite U2F 2FA with my DNS provider.
Re: Ask HN: Should we own the free stuff we pay for?
#268Earlier quoted context omitted.
Finding the place to enter and save and confirm a password sounds a lot harder than just putting in my first name, last name, email and a password in the first place.
Yeah, most new services allow sign-up with e-mail. However, there was a brief period which made it almost impossible to register without a social registration path.
Re: Ask HN: Should we own the free stuff we pay for?
#269Earlier quoted context omitted.
I would imagine it takes the form of a government "porting server", where anyone can query an email address and receive back a different target email address. All people sending email will be required by law to first consult the porting server to determine where to send email. It could be as simple as an http endpoint. Total development costs and running costs could be pretty low - low enough that the government can…
Having the government having information about everyone’s email address… What could possibly go wrong?
Re: Ask HN: Should we own the free stuff we pay for?
#270Earlier quoted context omitted.
Good to hear that you have protections around this in the UK. I know that in Sweden several political, and even ideological organisations have had their accounts frozen because of things they said or held true. Entirely legal things I should add.
Could you provide links? We have similar rules so I'm a bit surprised...