Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

201–210 of 544 posts

Re: Don't use third party auth to sign in

#201
post #165

Earlier quoted context omitted.

I do not. Becoming dependent on a large e-mail provider is only because of continued willful ignorance. Better education for how digital services work and how to properly handle your digital identity is the right way to handle this. Implementing regulation and cementing the "major" e-mail providers who have the resources to comply will only deepen people's dependence on these corporations.

So what do you propose then? How do you "properly handle your digital identity is the right way"? Do I have 15 emails addresses with 15 different providers? When a form asks for my email address I can only give one, what happens if that provider goes away? What if a government doesn't like $provider and seizes the business? Now I can't get a reset link/change my password/prove my identity...Many government online ser…

You went from dealing with being banned by google to the general case of an e-mail provider disappearing. This is different. In one case you have control ( choosing not to deal with google because of their arbitrary judgments when it comes to account termination ) in the other, you really don't. ( Random calamity that befalls your email provider ).

If your email provider goes away, you're screwed. Nobody accounts for this situation. Doubly so when you used an identity provider that has gone bust. The question is, how do YOU imagine imposing regulations on mail providers will change anything in a case like this?

Store your credentials, make backups of your emails, don't use identity systems. If things really do go bust, you'll retain access until you can get manual changes made to your accounts.

The other obvious solution is to have identity/e-mail built-in as part of citizenship and be gauranteed by your government.

Re: Don't use third party auth to sign in

#202

Earlier quoted context omitted.

At the risk of stating the obvious - This implies that Google already knows that it's you when it shows the sign-in prompt on some 3rd party website and they are already tracking you there even though you are not signed in. Lovely. Not that you'd expected anything else from Google.

Obviously Google knows that you are logged in to Google when you are logged in to Google.

And Google knows that you are not logged in to Google when you are not logged in Google on these web sites.

Re: Don't use third party auth to sign in

#203

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

Google is a profit seeking business entity just like many others and hence will do whatever they can to advance the interest of the company and its shareholders. It would be nice if companies had moral responsibility and societal accountability however that’s seldom the case in USA. The role of taking care of the people belongs to the government. Companies have choices but no obligation to do what’s best for you.

If you are using a free e-mail service ran buy one the worlds largest and most powerful marketing companies as the identity / auth provider for your critical services and applications you should seriously reconsider your choice.

To paraphrase your comment: I'm honestly not sure where we went so wrong as a society so as to reach a point that we get mad when a service we do not pay for, ran by a selfish company decides to shutdown our access.

Re: Don't use third party auth to sign in

#205
I might be missing the point here, but I find it quite annoying that I was already logged into my Google account and trying to sign in in a website[1] using the 'Sign in with Google' did not work. I don't take my cellphone to work and that little Google auth system kept asking for in-phone confirmation since "I was trying to log in from an unknown device" but singing in Gmail in that exact same device worked just fine.

[1] Figma

Re: Don't use third party auth to sign in

#206
post #70

Earlier quoted context omitted.

Use a browser plugin like this to always use the old site: https://addons.mozilla.org/en-US/firefox/addon/old-reddit-re...

Doesn't work on Firefox Android. I never go to Reddit by typing URL; I go to Reddit because I follow a link to it.

There's a rich ecosystem of incredible third party reddit apps on android, as an alternative. Reddit is really unpleasant to use on the mobile web, even without the dark patterns.

Re: Don't use third party auth to sign in

#207

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

If anyone honestly believes that Google can "remove their existence"...with or without due process, I think maybe they need to take a step back from the net. I read all the time the arguments over bitcoins value being real or not, but maybe the better discussion should be on wether or not social media and having a digital presence has any actual "real" value.

Re: Don't use third party auth to sign in

#208
post #121

Earlier quoted context omitted.

I use different services for different things. I have 3 email accounts at FastMail and 6 at ProtonMail. Also, some of it is inertia: I've hosted the MX for sneak.berlin at FastMail for several years (and have prepaid some time into the future), and have only been using ProtonMail for about one year (and the HOWTO article is recent). The fact that FastMail might be subject to the new Australian crypto key escrow law[1…

> The fact that FastMail might be subject to the new Australian crypto key escrow law FM is saying it doesn’t affect them, as they are not a secure provider and can already give any information out upon lawful requests. Do you disagree with that?

This is exactly how I understood it. But maybe I'm wrong?

Re: Don't use third party auth to sign in

#210
post #121

Earlier quoted context omitted.

Thx for that. Great help for many of us. But why referring to Protonmail and using Fastmail for yourself?

I use different services for different things. I have 3 email accounts at FastMail and 6 at ProtonMail. Also, some of it is inertia: I've hosted the MX for sneak.berlin at FastMail for several years (and have prepaid some time into the future), and have only been using ProtonMail for about one year (and the HOWTO article is recent). The fact that FastMail might be subject to the new Australian crypto key escrow law[1…

Thx for your detailed feedback. Appreciate it.

So your advice would be to go with Protonmail all the way, as you wrote it within your blog?

Post reply on HN