Live data from Hacker News

What Do You Think about This Seamless “Registering/Login” User Experience?

community.vanila.io

51–54 of 54 posts

Re: What Do You Think about This Seamless “Registering/Login” User Experience?

#51
post #42

Earlier quoted context omitted.

> Although I'm just a sample size of one, but I've had zero success in convincing any friends or relatives to use a password manager. > They either don't trust password managers, or don't want to change their current workflow. I used to memorize all my passwords but now I just use my browser's 'remember password' feature. In both Firefox & Chrome it syncs between devices, and is usable on both the desktop and mobile…

Firefox has a separate password manager app - Lockwise[1]. [1]: https://www.mozilla.org/en-US/firefox/lockwise/

Good to know. It's already fully integrated into the browser, so not sure what the point of having a separate app is...

Re: What Do You Think about This Seamless “Registering/Login” User Experience?

#52
post #50

Earlier quoted context omitted.

Huh, new idea, Google already prompts me on my phone when I log in to Google on a new device, why isn't there a service where instead of having to open my email and find that darned Medium email, it can push a question to one of my devices (also on PC) and I can just press "Yes that was me, let me in"? It can be some third party so I don't need a different software for each site..

Isn’t that basically logging in with Google? I mean Google isn’t asking you if you logged into Medium with a push but by the time you’re doing that Google already knows it’s you and pushed you a notification to log you in initially.

Almost, but what if I'm uncomfortable with Medium having my real name and profile pic (which Google's SSO will share)?

I'd imagine Medium would offer "authentication through X", and I can either enter my id for X, or go to the X app and generate a new ID for use for Medium, and paste it on Medium. So next time I want to login to Medium, after entering my username, Medium's backend talks to X's backend (saying user with this ID wishes to login) X can prompt me on one of my devices. Medium can display a unique number on their page for me, and I can compare that to the number my X app is showing me to confirm it's me I'm letting myself in.

This is a 1 minute concept without considering creative ways it can be attacked. But I guess there wouldn't be any money to be made...

Re: What Do You Think about This Seamless “Registering/Login” User Experience?

#53

Given that this is a website for medical use, I'm surprised they are allowing account creation with google oauth. I'm 95% sure it's not HIPAA compliant.

https://cloud.google.com/security/compliance/hipaa/identity-... - looks like, at least for Cloud Identity (for employees accessing the internal records and databases themselves) - it's HIPPA compliant when the people implementing it do their DD. Since GSuite and Gmail logins are fairly tightly integrated, I would bet the regular auth system and oauth system for Google accounts is HIPPA-complaint.

If you are using a service like google oauth you need to sign a business associate agreement with them before using any of their services in a HIPAA compliant manner. I've searched for how to sign this contract pretty unsuccessfully.

Re: What Do You Think about This Seamless “Registering/Login” User Experience?

#54
post #44

Earlier quoted context omitted.

God, Medium has the worst login experience of any site I use. What makes them think they are too clever to be usable with a password manager like the rest of the damn internet? I usually just reopen the article in an incognito tab instead of going through their stupid “send me an email!” bullshit login.

For every user like you who is using unique, securely generated passwords in a manager, there’s 10,000 people who are using the same, easily compromised password on every website they’re registered on. You’re not the target audience for these features - not only are you the tiny minority, but no matter what system they give you, you’ll find a way to interact with it safely, so for that interaction you simply don’t ma…

I don't care. All they have to do is not ruin the experience for me, not make everyone else use it.
Post reply on HN