Live data from Hacker News

Start ups, please don't force me to log in with Facebook

news.ycombinator.com

91–100 of 279 posts

Re: Start ups, please don't force me to log in with Facebook

#93
post #16
post #12

I'm sorry, but its just not worth expending the extra effort to get you signed up to my service. I can get millions of people before it even starts becoming an issue.

I feel that's a flawed attitude. It's like reverse entitlement. Were I a startup founder, I would make it my goal to ensure that EVERY. single. potential customer can use my site, within my capabilities. (edit: I don't know why you're getting downvoted; you stated your philosophy as part of the discussion, which I don't think is a good reason to get downvoted.)

I don't think a philosophy of "I'm going to force people to use the proprietary, closed, run-by-a-weird-company solution instead of the existing proven free & open solutions, because it's slightly more convenient for me" is going to be very well-received. Nor should it be.

Re: Start ups, please don't force me to log in with Facebook

#94
post #7

This is by far my largest complaint with Quora.

Agreed. I've lost track of how many times I've gone to a Quora answer, thought 'I must take a closer look at Quora', gone to the root domain, realised you need a Facebook login, then just navigated away. I even have a Facebook account somewhere - just don't like logging into another site like this for some reason.

The inconvenience of finding/creating a Facebook account to use in joining Quora is, imo, completely worth the value offered by Quora. You have to choose your battles. At a certain point I would rather have access than have my way.

Re: Start ups, please don't force me to log in with Facebook

#95
post #7

This is by far my largest complaint with Quora.

Agreed. I've lost track of how many times I've gone to a Quora answer, thought 'I must take a closer look at Quora', gone to the root domain, realised you need a Facebook login, then just navigated away. I even have a Facebook account somewhere - just don't like logging into another site like this for some reason.

This ie exactly what I do each time... look at a question then think, hmm I wonder whats popular on Quora right night but the homepage is totally locked down...

Re: Start ups, please don't force me to log in with Facebook

#96
post #83
post #76

Earlier quoted context omitted.

What makes me nervous about singing into a site through Facebook is I don't know what kind of permissions I'm giving to the site regarding my FB account.

Facebook always displays an allow page with what data the site is requesting.

Will it always do that? Are there any implicit allowances? Will there be in the future? For what's true now, I could look it up. But I'd rather not. For what will be in the future, I have no idea. The simplest thing for me to do is use my Facebook account for Facebook only.

Re: Start ups, please don't force me to log in with Facebook

#97
post #67
post #50

Maintaining a separate identity for every site across the web gets more impractical by the second. I think most people would agree that a third-party authentication service is a positive thing, but there seems to be a stigma, earned or not, surrounding Facebook that makes people hesitant to assign that responsibility to them. I think ultimately it's going to come down to a paid, independent service. Startups can't of…

What's impractical about it ? I'm very comfortable with separate identities per-site. If your site isn't worth a separate identity, why am I interacting with it in the first place?

Well, for one thing, this becomes a bigger and bigger problem: http://www.xkcd.com/792/

Yes, it's a ridiculous example, but the vast majority of end users keep the same username and password for all of their online services. Obtain one U/P pair and you could conceivably access their identity anywhere. A centralized, specialized authentication provider could maintain multiple levels of authentication depending on what the service demanded. Perhaps your favorite news aggregator only required that you be authenticated with a username and password, but your bank could be using the same authentication service and demand a physical token or one-time password to continue to the service.

The idea is to maintain the convenience we already demand and practice in a manner which is orders of magnitude more secure.

Re: Start ups, please don't force me to log in with Facebook

#98
post #10

Earlier quoted context omitted.

Just as bad, in my mind. But I could be alone on that.

I disagree. All your Twitter data is public* anyway, so it shouldn't be a problem. And twitter makes it so much easier than Facebook to disable/disconnect an app from your account. *Unless you make tweets private. But even then, your followers and followees are still public.

It's not the Twitter data I care about, or what happens to the Twitter data. It's not even the difficulty of creating a throwaway Twitter account. I just personally prefer to keep all of my accounts segregated from each other, each for their own assigned purpose, is all.

Re: Start ups, please don't force me to log in with Facebook

#99
Really the best solution for this is to provide as many options as possible. You should develop your authentication services in a way that allows OAuth to be used just as easily as a "custom login". In addition to that, anyone who says that having "your own" login isnot worth the time to develop it is just plain silly. It takes almost no time to develop and anyone who has been in the web business for longer than 1 website knows this. As a startup I want to make sure that I am not alienating any user from my service.

On that note, It is important to realize that certain sites or services on the web require some sort of social graph integration that require a login with a social networking account. In cases like this, you are developing an app for a user base that is not on FB or Twitter and then (purposely) alienating the rest.

Re: Start ups, please don't force me to log in with Facebook

#100
post #5

What about Twitter?

It always scares me when I go to 'log in with twitter' and it tells me "$APP wants permission to ... update your feed." I always hit DENY and forget the service if that happens.

Maybe I'm being harsh, and the app doesn't actually want to tweet in my name, but twitter doesn't allow it to request read-only access. Still, the permissions as displayed are clearly not what I want to grant, and I don't get to veto only the update ability.

I would rather not use a service than offer it the possibility of spamming in my name, and I have made that choice a few times now.

Post reply on HN