Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

151–160 of 544 posts

Re: Don't use third party auth to sign in

#151
post #107

Remember OpenID? Yes, that's what it was for, OAuth wasn't never meant for signing in other websites who just want your mail or something... Of course, all these big tech corps quickly dropped OpenID, they don't want people to control their online credentials or identity...

Has there been any retrospectives or published thoughts around why OpenID failed? Ideally a extensive, impartial report would be nice to read through. While it's easy to blame big technology companies for the failure of open standards, there might be other reasons behind it (as well as companies trying to prevent it from succeeding)

OpenID failed because you had to sign up to an OpenID provider and then copy and paste some weird URL from there into websites you wanted to use.

Why would anyone bother with that hassle when you can just put in your email address (that you already have & know) and a password.

In contrast, OAuth succeeded because most people already have a Facebook / Gmail / Github account, which meant that sign up just becomes clicking a single button which is easier than email signup.

OpenID was more difficult than email signup, whereas OAuth is easier.

Re: Don't use third party auth to sign in

#152
post #64

Good point, but if Google suspends my account I've got bigger things to worry about than the dozens of sites I've used once or twice a year. Paying for your own domain also comes with its own troubles. If you're not using Google (or some other service) as your mail forwarder, good luck being able to email anyone. Stealing you custom domain is also a real possibility, and negates your investment in Gmail 2FA.

How could my domain be stolen? :O

If anything happens to you which prevents you from renewing your domain, e.g. you are detained or in a coma, then it's probably gone as well unless you have a lot of credit on your registrar account.

Re: Don't use third party auth to sign in

#153

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

Legal services can get involved just fine if you file suit. You'll just have to establish that Google owed a duty to you (by contract or otherwise) and that you were harmed by their breach of that duty. (Roughly. I am not a lawyer.)

The point of the comments here is that $BIGCO is outside of the law from a risk measured standpoint (ie: they’ll bankrupt you if you fight them given their bigger bankroll).

Re: Don't use third party auth to sign in

#154
post #116
post #6

Has anyone else noticed random popups on 3rd party websites asking for google sign in? I even used firefox when it happened: https://imgur.com/a/JC52lBV (lequipe.fr) https://imgur.com/a/VSM3Uk9 (reddit.com) https://imgur.com/a/KpVCYBL (medium.com)

You can disable these annoying prompts by going to https://myaccount.google.com/permissions and disabling "Google Account sign-in prompts". Ideally it should have been user opt in but Google followed dark pattern here.

At the risk of stating the obvious -

This implies that Google already knows that it's you when it shows the sign-in prompt on some 3rd party website and they are already tracking you there even though you are not signed in. Lovely. Not that you'd expected anything else from Google.

Re: Don't use third party auth to sign in

#155

Earlier quoted context omitted.

Legal services can get involved just fine if you file suit. You'll just have to establish that Google owed a duty to you (by contract or otherwise) and that you were harmed by their breach of that duty. (Roughly. I am not a lawyer.)

Has this ever been done successfully in this situation?

[deleted]

Re: Don't use third party auth to sign in

#156
post #91
post #6

Has anyone else noticed random popups on 3rd party websites asking for google sign in? I even used firefox when it happened: https://imgur.com/a/JC52lBV (lequipe.fr) https://imgur.com/a/VSM3Uk9 (reddit.com) https://imgur.com/a/KpVCYBL (medium.com)

I use Firefox containers at work but I was postponing doing the same at home because it takes a bit of work to create the containers, assign sites, troubleshoot some minimal issues, etc; and THIS made me finally do it. I knew that I was being tracked, but that was a bit too "in my face" to ignore it.

There's a ready made extension for Google.

https://github.com/containers-everywhere/contain-google

Installable from the Firefox extension "store".

Re: Don't use third party auth to sign in

#157
post #152
post #64

Earlier quoted context omitted.

How could my domain be stolen? :O

If anything happens to you which prevents you from renewing your domain, e.g. you are detained or in a coma, then it's probably gone as well unless you have a lot of credit on your registrar account.

Most domain registrars support autorenew with a credit card.

Re: Don't use third party auth to sign in

#158
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

My problem with the get your own domain and DNS is its far more likely I become incapacitated and become unable to pay or manage it than getting locked out of gmail or outlook mailboxes.

Is it? You can register for 10 years at a time and then keep that topped up, as well as setup autopay pointed at a bank account with as many years of funds as you'd like. At some point the likely limiting factors shift to other things. Even the most reliable longest lasting registrars could in principle go out of business or get bought, but then again Google could decide to radically alter or discontinue services at some point too (as they indeed frequently have), or get broken up or who knows. 10 years is quite a while. And while nothing about business dealings is completely certain, someone paying for a domain a revenue generator with potential for more, so even if a registrar was acquired they'd have strong incentive to try to roll over existing accounts barring active objection.

I don't know your personal circumstances of course, different people may very reasonably make different calculations. But I have more trust in a quality registrar and my bank then in Google under the most likely scenarios where I'd still care (long comas aren't impossible to come out of, even multi-year, but chances of just partial recovery plummet after even a month or two let alone full recovery). I think Google being capricious or making a mistake is a bigger concern, if only because there is almost zero chance of recovering from it (basically have to know a well placed Googler or manage to go viral or be a big enough presence to get their attention). Domains and finance in contrast are both full of competition and portability.

Re: Don't use third party auth to sign in

#159

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

US national politics. One party is in bed with the copyright owners, the other doesn’t believe that the government should govern.

Google fills the gap.

Re: Don't use third party auth to sign in

#160
post #116

Earlier quoted context omitted.

You can disable these annoying prompts by going to https://myaccount.google.com/permissions and disabling "Google Account sign-in prompts". Ideally it should have been user opt in but Google followed dark pattern here.

At the risk of stating the obvious - This implies that Google already knows that it's you when it shows the sign-in prompt on some 3rd party website and they are already tracking you there even though you are not signed in. Lovely. Not that you'd expected anything else from Google.

Yes, the pop-up is for signing into the site with your already-signed-in Google account. If you're not logged in then you use the site's default login mechanism.
Post reply on HN