Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

121–130 of 544 posts

Re: Don't use third party auth to sign in

#121
post #51

Earlier quoted context omitted.

This is such excellent advice that I wrote a detailed step-by-step instruction guide for people that don't know how to do precisely that: https://sneak.berlin/20201029/stop-emailing-like-a-rube/ It even has special instructions about how to secure the domain registration and DNS accounts. :) (Don't use G Suite, though.)

Thx for that. Great help for many of us. But why referring to Protonmail and using Fastmail for yourself?

I use different services for different things. I have 3 email accounts at FastMail and 6 at ProtonMail. Also, some of it is inertia: I've hosted the MX for sneak.berlin at FastMail for several years (and have prepaid some time into the future), and have only been using ProtonMail for about one year (and the HOWTO article is recent).

The fact that FastMail might be subject to the new Australian crypto key escrow law[1] is a little bit worrisome, and I may not continue to use them in the future depending on how that plays out.

For things where surveillance is less of an issue, I prefer being able to use a plain IMAP client, which ProtonMail does not support. Their current iOS client is pretty lame, for example (although their web client is better, and I understand that their next major release will improve things a lot across the board). I mention the IMAP issue in the article.

[1]: https://parlinfo.aph.gov.au/parlInfo/download/legislation/bi...

Re: Don't use third party auth to sign in

#122

> Every respectable service allows you to create accounts using your email address This way I should maintain my own email server, because I can be locked out of my email by any of cloud providers as easy.

You just have to use your own domain. No need to run an email server.

Of course most people don't have their own domain and linking a domain to a cloud email service is either expensive (Google, Microsoft, Fastmail, etc) or impossible (iCloud).

Re: Don't use third party auth to sign in

#123

Earlier quoted context omitted.

Really, I think OpenID died because it didn’t see significant enough adoption. I remember the user flows being a bit clunky, which certainly didn’t help. With OpenID, basically everyone used a third party ID provider, and so you were just as dependent on that provider as with OAuth. Did you actually self host OpenID? If so, that’s a lot to ask of each person in the world. If you didn’t self host OpenID, I don’t think…

> Did you actually self host OpenID? If so, that’s a lot to ask of each person in the world. You could pay someone to host it with reasonable guarantees they won't delete your account on a whim and no recourse. Or you can use a free service that you somewhat trust with your own domain, so you can point the domain to another provider if you need to. Almost no technical knowledge required for that. > If you didn’t self…

> You could pay someone to host it with reasonable guarantees they won't delete your account on a whim.

Each user having to find a hosting provider and pay them... it seems like a non-starter. Think about the non-technical people in your life. That solution would only help the very few people who both understand the details of OpenID, and care about the possibility of losing account access at a deep level. Most people have other important stuff going on in life, so good luck convincing them to adopt self-hosted OpenID at greater cost (and effort) to themselves.

This is even assuming that the hosting provider also acts as a domain registrar so each person doesn’t also have to figure out how to buy and own a domain name, to truly own their OpenID, because that would either make this solution much less meaningful in terms of control (with no custom domain), or make it that much harder.

> Same for email, which is what identity relies on instead of OpenID.

I’m not here to argue for self hosted email. There are many email hosting providers that make it relatively easy for you to bring your own domain name... but this is irrelevant. Signing in with an email and password continues to work even if the email account has been suspended. So, it’s not the existential threat that the article is concerned about.

I think the more realistic solution for users is the new FIDO2 standard that will hopefully see adoption soon.

I think Google has done a similar thing on Android, but Apple has for sure made every (up to date) iPhone, iPad, and Mac able to act as a FIDO2 Platform Authenticator.

Even if the user signs up via OAUTH, websites can give the user the choice to sign in via FIDO2 on each device. At that point, users could sign in from those devices even if their Google account were suspended, giving the website a chance to help the user migrate their account authentication.

The FIDO2 flows seem very user friendly, but... the standard is so new, broad adoption remains to be seen.

Re: Don't use third party auth to sign in

#124

Remember OpenID? Yes, that's what it was for, OAuth wasn't never meant for signing in other websites who just want your mail or something... Of course, all these big tech corps quickly dropped OpenID, they don't want people to control their online credentials or identity...

Sadly everyone wanted to be an OpenID provider, very few wanted to be a consumer of OpenID.

Neither Google, Facebook nor any of the other major Internet sites where ever going to allow you to authenticate using a 3rd party.

Re: Don't use third party auth to sign in

#125
I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire.

If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated to the relevant authority, namely the "justice" system to make such considerations.

If your house could be removed at a whim because a bot decided you were a bad person it would likely cause an uproar, it wouldn't be tolerated.

Yet here it is. Google can offer their services and the legal system seemingly doesn't want to be involved.

Why?

Re: Don't use third party auth to sign in

#127

We also offer multiple third-party signup solutions for our service in addition to "traditional" e-mail based signup. For every service we retrieve and store the users' e-mail address on our server (we also need that to e.g. send out invoices) and enable e-mail based login and password reset/generation by default (you can disable it or add 2FA), so your account will not be lost just because your OAuth provider blocks…

Won't the password reset link of a blocked Google user get emailed to their inaccessible gmail inbox?

I think it's to protect against the Identity Provider revoking access to the service you're dealing with rather than them blocking your account.

We saw this recently with "Sign in with Apple" and Epic Games, where Apple denied access to Epic and the accounts that did not share their actual email were effectively lost.

Re: Don't use third party auth to sign in

#129
post #51
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

This is such excellent advice that I wrote a detailed step-by-step instruction guide for people that don't know how to do precisely that: https://sneak.berlin/20201029/stop-emailing-like-a-rube/ It even has special instructions about how to secure the domain registration and DNS accounts. :) (Don't use G Suite, though.)

Really good article, could you share it as a hn submission by itself? Would love to see a discussion around it

Re: Don't use third party auth to sign in

#130
Isn’t this grounds for a class action lawsuit? Google and friends have the right to lock you from use of their services, but when such services encroach in your use of other services unrelated to google, that you may even have paid for, should google have the right to blanket block? Is it technically difficult to exempt google signin from account locks? Can we maybe also legally claim that if a company hosts your identify, that it has no right to hold it hostage? I mean, if I’m arrested, my identity automatically erased.

Finally, is it not possible to require that all such block critical to someone’s data require some form of govt approved appeals process?

I’m asking these questions so maybe someone can enlighten me on why they were not yet attempted, or if they where, why they failed? Is it legal complexity? Cost? Lack of large scale support, as in, is it only a niche concern that only the HN crowd is complaining about?

Post reply on HN