Live data from Hacker News

Start ups, please don't force me to log in with Facebook

news.ycombinator.com

161–170 of 279 posts

Re: Start ups, please don't force me to log in with Facebook

#161
post #83
post #76

Earlier quoted context omitted.

What makes me nervous about singing into a site through Facebook is I don't know what kind of permissions I'm giving to the site regarding my FB account.

Facebook always displays an allow page with what data the site is requesting.

Unless that site is Yelp. Or Pandora. Or...

"Always" is meaningless for SAAS that you don't pay for.

Re: Start ups, please don't force me to log in with Facebook

#162
post #148

Earlier quoted context omitted.

what happens if you ad-block google?

Lots and lots and lots of sites fail because they depend on jquery hosted by google.

Interesting, that makes their altruistic (CDN) hosting seem slightly more strategic.

Re: Start ups, please don't force me to log in with Facebook

#163
post #149

Earlier quoted context omitted.

Define "something good." You haven't given any reasons on why it sucks.

Something that doesn't require you to be a techie to understand. OpenID is a bit advanced for many users. FB Connect actually does a pretty good job at being "easy to use". Just log into your FB account and you are set. I know it's not fair, but most people havn't posted anything to that openid website. Google or Yahoo logins would work, since there's a recognizable brand name and there's a good chance that the user…

>FB Connect actually does a pretty good job at being "easy to use". Just log into your FB account and you are set.

The only time I used OpenID, it was for StackOverflow. The workflow was exactly as you describe for Facebook Connect, except substituting Gmail for Facebook. I really don't see where there's room to be tripped up, unless you can't handle the idea that you can log in using accounts from multiple places.

Re: Start ups, please don't force me to log in with Facebook

#164
post #161
post #83

Earlier quoted context omitted.

Facebook always displays an allow page with what data the site is requesting.

Unless that site is Yelp. Or Pandora. Or... "Always" is meaningless for SAAS that you don't pay for.

Oh yes. Never write in absolutes on HN.

I don't know about Yelp but Pandora asks permission. http://www.flickr.com/photos/4braham/5030673157/

Re: Start ups, please don't force me to log in with Facebook

#165
post #96
post #83

Earlier quoted context omitted.

Facebook always displays an allow page with what data the site is requesting.

Will it always do that? Are there any implicit allowances? Will there be in the future? For what's true now, I could look it up. But I'd rather not. For what will be in the future, I have no idea. The simplest thing for me to do is use my Facebook account for Facebook only.

Any information you put on Facebook is susceptible to being used in ways you don't know of or have not authorize for. All information on the internet is like this for that matter. At least currently with Facebook Connect sites FB displays an authorize display laying out the information accessible.

Re: Start ups, please don't force me to log in with Facebook

#166

Earlier quoted context omitted.

The only thing I wish for nowadays is for the public to gain a better understanding of OpenID so we can start using it on every site. It's the best thing to ever come out.

It became significantly easier when Google (and Yahoo!, and MySpace) became OpenID providers. If you do something like StackOverflow does (click the Google icon to login with Google), then it's pretty low-effort to use.

Ah, that's true. It's a bit odd to use a dedicated icon to log in to something that is exactly the same as the more general option you offer, but the average user won't know that, so it makes sense.

Do you know the endpoint for Google? I didn't know they supported it natively.

Re: Start ups, please don't force me to log in with Facebook

#167
We have two separate clients that spend big $$$ on AdSense driving new customer acquisition that used single fb connect for login.

After the API issue last week both saw their 8+ LP scores dive down to 1! Lost commerce for both over the past few days equals multiple tens of thousands, still not seeing the scores recover.

Re: Start ups, please don't force me to log in with Facebook

#168
post #163

Earlier quoted context omitted.

Something that doesn't require you to be a techie to understand. OpenID is a bit advanced for many users. FB Connect actually does a pretty good job at being "easy to use". Just log into your FB account and you are set. I know it's not fair, but most people havn't posted anything to that openid website. Google or Yahoo logins would work, since there's a recognizable brand name and there's a good chance that the user…

>FB Connect actually does a pretty good job at being "easy to use". Just log into your FB account and you are set. The only time I used OpenID, it was for StackOverflow. The workflow was exactly as you describe for Facebook Connect, except substituting Gmail for Facebook. I really don't see where there's room to be tripped up, unless you can't handle the idea that you can log in using accounts from multiple places.

Because normal users' innate pathological copy-reading avoidance make the login page (http://skitch.com/dasil003/d2ac8/change-openid-stack-overflo...) a usability clusterfuck.

Re: Start ups, please don't force me to log in with Facebook

#169

Earlier quoted context omitted.

I'm comfortable with separate identities per site, but it is impractical for most people. You have three general choices: - Maintain a separate login and password for every site. This requires a lot of memorization and is a pain in the ass when you find yourself trying four passwords because you forgot which you used. - Use password management software or a naming system that lets you keep track. This is effective bu…

I'm not comfortable using any sort of 3rd party service. I also don't like that I have any kind of connected identity across multiple sites. This sort of authentication system should be built into the browser, entirely under my control, and every site should be given a separate identity token.

Sounds good, but what happens when you reinstall your OS, or change your OS or browser?

Not saying it's not possible - not trying to shoot this down at all - just I think it's a major issue.

Re: Start ups, please don't force me to log in with Facebook

#170

I just came off of a project where we built the entire auth system on facebook. No other regi options - just facebook. I will never do that again. If that was to become the standard, facebook shot themselves in the foot with their crappy APIs anyhow (see http://news.ycombinator.com/item?id=1731427 ) And I have a facebook account, and I'm really hesitiant to like or authorize anything for fear of the author (or hacker…

I'm really hesitiant to like or authorize anything for fear of the author (or hacker) using it for malicious purposes

I'm not quite as fearful for myself. However, if your application requests access to my friends list, you've just struck out with me. Even if I'm inclined to trust you, I don't believe that I have the right to make that decision for my friends. I won't expose them to you, so you can't have my business if you require it.

Post reply on HN