Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

211–220 of 544 posts

Re: Don't use third party auth to sign in

#211
post #205

I might be missing the point here, but I find it quite annoying that I was already logged into my Google account and trying to sign in in a website[1] using the 'Sign in with Google' did not work. I don't take my cellphone to work and that little Google auth system kept asking for in-phone confirmation since "I was trying to log in from an unknown device" but singing in Gmail in that exact same device worked just fin…

You can turn that off by turning off 2 factor authentication, where ever that setting is.

Re: Don't use third party auth to sign in

#212

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

Your google account is not your house by any stretch of the imagination. Blown out of proportion.

Re: Don't use third party auth to sign in

#213

Earlier quoted context omitted.

US national politics. One party is in bed with the copyright owners, the other doesn’t believe that the government should govern. Google fills the gap.

> One party is in bed with the copyright owners, the other doesn’t believe that the government should govern This political model is dated. Republicans are no longer conservative. And Democrats have an ascendant progressive wing that rejects corporate influence wholesale.

An ascendant wing the party is doing everything in its power to stomp out.

Re: Don't use third party auth to sign in

#214
On the other hand if you want to use 2 factor authentication adding and rotating security keys across dozens of sites isn't the best plan either. So we are kinda stuck in a rough spot. I really wish that OpenID stuck around. It would have been fantastic to have the choice of provider including running your own.

I think the saving grace of using Google login is that usually you can still "reset your password" via email and get in that way even if Google locks you out.

Re: Don't use third party auth to sign in

#215

Whats the issue here? The alternative would have been to use email, which, presumably would have been a gmail.com address. If Google locked you out of your account, you wouldn't be able to access your email account either.

Although this isn't practical for everyone, this is one of the reasons I use a personal domain name and then host the MX record with an e-mail service.

That way if, for some reason, that e-mail service were to close my account, I could repoint the MX record elsewhere and still have access to my accounts.

Re: Don't use third party auth to sign in

#216
post #203

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

Google is a profit seeking business entity just like many others and hence will do whatever they can to advance the interest of the company and its shareholders. It would be nice if companies had moral responsibility and societal accountability however that’s seldom the case in USA. The role of taking care of the people belongs to the government. Companies have choices but no obligation to do what’s best for you. If…

When companies acts too amoral we create laws to stop them.

Edit: The point is that it is usually in companies own interest that we don't create laws restricting them, so they typically don't act too amoral. You wont find many companies which goes after every single legal loophole they can abuse, as negative public sentiment builds up laws will form and the company will be much worse off than if they just did the slightly less amoral thing.

Re: Don't use third party auth to sign in

#217
post #72

Earlier quoted context omitted.

Are you actually the owner of steve.com? Because I've been ordering Dominos pizza with the email steve@steve.com for years. Edit: nevermind. I see you own the .net tld. I've definitely used that to order pizza too. Sorry about that.

Couldn't you use @example.com?

example.com is good because it is explicitly reserved for this purpose and has no MX records.

Although very occasionally a service will check for MX records, but that is incredibly uncommon. My go-to email for public WiFi is fuckoff@exmaple.com and have only been denied once (<1%)

Re: Don't use third party auth to sign in

#219

Earlier quoted context omitted.

I pay for gsuite for myself and a couple of my domains. Call it $12/month, because you'll want to setup two accounts: * The admin-user. * The daily/real-user. In my case I have my real account "steve@steve..", and "admin@steve" which is the gsuite administrator. I only login to make changes to the domain setup, never to send/receive email. It's annoying to have to pay for that second user, but I feel happier with the…

Why not me@steve, iam@steve, thisis@steve, thereal@steve or any of the other variants?

I'm a boring person. I even use my full name for kevincox@kevincox.ca

Re: Don't use third party auth to sign in

#220

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

> I'm honestly not sure where we went so wrong as a society so as to reach this point... Why?

The answer is actually very simple: spam.

AFAIK pretty much all disabled Google accounts come from Google believing they are part of a spam-sending (or malware-spreading) network.

The ability to sign up for free Google accounts means this is a prime target for spammers to use and abuse -- signing up for free Gmail/Drive accounts, as well as using stolen credit cars to sign up for paid ones.

As to why the legal system doesn't want to be involved, it's because incorrectly disabled Google accounts are actually incredibly rare -- they make the news and cause uproar when they occur, but precisely because it's so unusual -- it's incredibly rare to personally know someone it happened to. So there isn't any kind of democratic movement against it because in the grand scheme of things it isn't common. It's like worrying about being struck by lightning.

That's why.

Post reply on HN