Live data from Hacker News

Start ups, please don't force me to log in with Facebook

news.ycombinator.com

211–220 of 279 posts

Re: Start ups, please don't force me to log in with Facebook

#211
post #205
post #193

Earlier quoted context omitted.

How do you know if the app requests access to your friends? Even if FB warns you about this behavior (I dont think it does) how can you trust that they won't change their policy in the future without alerting you?

You explicitly grant access for each new set of permissions - accessing a friends list (and thus their publicly available information) is one of those sets. If the site changes their policy, they have to go back to the user and request permission.

This is false - accessing the friends list only requires "basic" permissions.

Re: Start ups, please don't force me to log in with Facebook

#212
post #19
post #16

Earlier quoted context omitted.

I feel that's a flawed attitude. It's like reverse entitlement. Were I a startup founder, I would make it my goal to ensure that EVERY. single. potential customer can use my site, within my capabilities. (edit: I don't know why you're getting downvoted; you stated your philosophy as part of the discussion, which I don't think is a good reason to get downvoted.)

It is my goal. But not right now.

I think you have the right goal, FWIW. For now. Because it's about priorities. Especially for a startup.

When you're building a startup, in my experience you want to advance on the narrowest front you can, as you build out the feature set and reach the market. Don't provide 5 ways to do X if you can just provide 4. Or just provide 1. Etc. There'll always be room in the future to iterate and add support for additional use cases, additional integration points, and additional polish. But you generally want to get to market fast, get real users, real customers, validate your market assumptions and business model assumptions, and slow or stop your burn rate before your runway runs out.

Saying NO to some things frees up additional time/money to say YES to others. So you should prioritize.

Re: Start ups, please don't force me to log in with Facebook

#213
post #154
post #69

Earlier quoted context omitted.

Sorry if I wasn't clear. I'm not saying that forcing Facebook will 100% eliminate fraud. But forcing Facebook can reduce fraud, by several orders of magnitude. Authentication isn't -- and shouldn't be -- a one-size-fits-all problem. For us, Facebook has worked extremely well. (We originally supported Twitter and OpenID but dropped them when it turned out that 100% of our fraud incidents had authenticated with one of…

The accounts have nothing in common - not IP address, nor cookies nor names nor friends or anything. With the fake accounts I just added fake friends (Facebook was so kind to suggest them) and they approved me. I even wrote 'whats up' on some peoples walls and they replied. No idea who they are, seems people just need somebody to talk to. I am a bit of a privacy nut (multiple browsers, incognito, proxy servers, VPN's…

> So as interesting as it would be for you to test my accounts, it means I would have to kill you :)

There needs to be a term for that level of secrecy/strictness when it comes to online identity/authentication. A level so strict that if an identity gets exposed or authentication mechanism is bypassed that somebody, somewhere, will have to be killed.

Now I await eagerly for an HN reader from a three-letter organization to chime in. ;)

Re: Start ups, please don't force me to log in with Facebook

#214

I have a fake FB account for this reason. It is amazing how many people will friend someone who doesn't exist

Especially if your fake FB account is for a lonely young female "nearby" and/or in Russia and looking for a traditional marriage overseas. ;)

Re: Start ups, please don't force me to log in with Facebook

#215
post #198

Earlier quoted context omitted.

So I start a SaaS business and put "Please login with your OpenIDv2a+OAuth compatible login below." prominently on my front page. And then I have no users because nobody knows what that means.

You should probably put "Please login with your Facebook or Gmail account below" on your front page instead. Modify the services named based on expected clients. Choose one or more from the following: AOL, BBC, Facebook, Google, IBM, MySpace, Orange, PayPal, VeriSign, LiveJournal, Yandex, Ustream and Yahoo!. * On the sign-up page, put in smaller text "You can sign up/log in with any compatible OpenID service" for the…

A problem with asking someone for their gmail password to sign into malwarenet.org is that it seems very suspicious. Why does malwarenet.org want my password? I bet I can guess - they want to steal my email, find my bank account numbers and identity fraud me. Oh, it doesn't work that way, right right, but how can any one without exceptional technical skills know that for sure? Lots of site spoofing out there.

Hell, opendns is giving me a spoofed ip address for google right now. What is that about, I thought they were secure. What else on my DNS service has been hacked? Bank sites? Probably.

Re: Start ups, please don't force me to log in with Facebook

#216
post #67

Earlier quoted context omitted.

What's impractical about it ? I'm very comfortable with separate identities per-site. If your site isn't worth a separate identity, why am I interacting with it in the first place?

I'm comfortable with separate identities per site, but it is impractical for most people. You have three general choices: - Maintain a separate login and password for every site. This requires a lot of memorization and is a pain in the ass when you find yourself trying four passwords because you forgot which you used. - Use password management software or a naming system that lets you keep track. This is effective bu…

Option 4: use an address book, spreadsheet, or database to list passwords.

Re: Start ups, please don't force me to log in with Facebook

#218

Earlier quoted context omitted.

Sounds good, but what happens when you reinstall your OS, or change your OS or browser? Not saying it's not possible - not trying to shoot this down at all - just I think it's a major issue.

One could use a cloud service like Xmarks which already syncs bookmarks and browser passwords. Just because it's built into the browser doesn't mean that you can store the information in the cloud and sync it between browsers. The difference is that you control the connection and your information directly. With OpenID or Facebook the connection is directly between those entities and site you are visiting. With a brow…

Xmarks is shutting down in 90 days, apparently. =\

Re: Start ups, please don't force me to log in with Facebook

#219

Earlier quoted context omitted.

Because normal users' innate pathological copy-reading avoidance make the login page ( http://skitch.com/dasil003/d2ac8/change-openid-stack-overflo... ) a usability clusterfuck.

That's not an issue with OpenID. That's an issue with the decision to not use OpenID exclusively and applies to every authentication service on the list in that screenshot, by virtue of that list being a list.

Btw, if you login on another site using Google or Yahoo, you are using OpenID.

Re: Start ups, please don't force me to log in with Facebook

#220

We have two separate clients that spend big $$$ on AdSense driving new customer acquisition that used single fb connect for login. After the API issue last week both saw their 8+ LP scores dive down to 1! Lost commerce for both over the past few days equals multiple tens of thousands, still not seeing the scores recover.

LP?
Post reply on HN