Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

231–240 of 544 posts

Re: Don't use third party auth to sign in

#231

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

> I'm honestly not sure where we went so wrong as a society so as to reach this point... Why? The answer is actually very simple: spam. AFAIK pretty much all disabled Google accounts come from Google believing they are part of a spam-sending (or malware-spreading) network. The ability to sign up for free Google accounts means this is a prime target for spammers to use and abuse -- signing up for free Gmail/Drive acco…

Hm. Lawyers love lawsuits about folks struck by lightning? So I'm not sure that's the reason this issue is not a lawyer's forte.

I'd suggest its because its hard to prove or prosecute. Because its technical and obscure. A single case, Google just has to say "Oh sorry; its turned back on". There's no money in them capitulating. And a class-action suit enters into the details of the issue, which are impenetrable to a judge?

Re: Don't use third party auth to sign in

#232
Oh, it sounds like this complaint stemmed from a person creating a one-time account use just for some rando site then got angry when google noticed it wasn't be used at all. The fallout of the arguments that follow may have merit but you should follow why the fuse was lit for context.

Re: Don't use third party auth to sign in

#233
This is a strong and succinct argument. I'm disturbed it never really occurred to me, probably because I am in part naive and take certain things for granted, like that I will never have a dispute with Google wherein they disable my account. But of course that is possible even at "no fault" on my part, and of course Google is judge/jury/executioner when it comes to their services. Yikes.

One thing I don't understand is: the author suggests a remedy is using your email address instead of third party sign in. But what if your email address is Gmail? For example, I just went to my Stack Overflow account and added my email address as a sign in method. But then of course I realized: my email address is Gmail. So what's the difference? How are we supposed to put this into practice without running our own email? Email is just another form of third party auth.

Re: Don't use third party auth to sign in

#234

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

It's not quite your scenario yet but we're pretty darn close: https://www.dailydot.com/debug/duplex-demolition-google-maps...

That incident looks like incorrect data in Google Maps but also incorrect behavior by the company tearing down the house. It also was complicated by the fact that this was post-tornado and normal signage was likely not present or reliable.

Re: Don't use third party auth to sign in

#235
Perhaps the courts could be helpful here. A long-established Google account has significant value to the user. If Google terminates such an account, value is destroyed and damages are incurred. You should be able to demonstrate the value of the lost account to a court and demand restitution from the host.

If successful, this would impose a cost to Google for shutting down accounts capriciously and incentivize them to do better.

This would be a challenging lawsuit to win. You’d probably need support from an organization like EFF to manage it.

Re: Don't use third party auth to sign in

#236
post #64

Earlier quoted context omitted.

How could my domain be stolen? :O

- does you registrar have physical office? is it in a country with legislation friendly towards the country you're based in? - does your registrar send Auth-Info code over email in plain text? - did you enter real contact and residence data when registering the domain including public WHOIS database? This is only a fraction of the attack vector.

> does you registrar have physical office?

Yes.

> is it in a country with legislation friendly towards the country you're based in?

It's in the same country.

> does your registrar send Auth-Info code over email in plain text?

Of course not, that would be a big red-flag.

> did you enter real contact and residence data when registering the domain including public WHOIS database?

I have no idea what a public WHOIS database is, never registered anything there. For the registrar I've entered my real contact and residence data, should I've not?

Re: Don't use third party auth to sign in

#237
post #152
post #64

Earlier quoted context omitted.

How could my domain be stolen? :O

If anything happens to you which prevents you from renewing your domain, e.g. you are detained or in a coma, then it's probably gone as well unless you have a lot of credit on your registrar account.

It's auto-renewing.

Re: Don't use third party auth to sign in

#238
I am now at a point where I would rather have the passport office / home office issue certificates for each citizen: 'John Doe number 145, signed by the British Government' You could use that for 2-way SSL with Banks, trusted email providers, etc. At least we would have 1 reliable identity that can obly be messed with by going through the courts.

I wouldn't was to use that identify for every random website, but at least we'd have something reliable.

Re: Don't use third party auth to sign in

#239

Technically email becomes the skeleton key regardless. And that is dependent upon at least one third party: domain registrars. And possibly email providers too. Though the post does have a good point on that non-email auth providers add more risk to the equation.

> that is dependent upon at least one third party: domain registrars

Kind of. You will have a bad day (or month) if your domain registrar is screwing you. But you do own the domain. So you should be able to get it back.

With Google/Facebook and similar you have no right to your account.

Re: Don't use third party auth to sign in

#240

Earlier quoted context omitted.

So what do you propose then? How do you "properly handle your digital identity is the right way"? Do I have 15 emails addresses with 15 different providers? When a form asks for my email address I can only give one, what happens if that provider goes away? What if a government doesn't like $provider and seizes the business? Now I can't get a reset link/change my password/prove my identity...Many government online ser…

Register your own domain and point it at your preferred service, if you lose access to that service you still retain the domain and you still have your email address. If you want to solve this problem you have to spend some money somewhere otherwise you are simply demanding providers give you services, for free, forever, not something that seems realistic?

But can't the same problem happen if you, somehow, lose the ownership of your domain? I mean, I don't know what the actual assurances are, but if there is any chance that you may lose access to your domain (for causes other than forgetting to pay to renew, ofc), even temporarily, that would be the same as being banned from Google. Or even worse, because having your Google account locked means you can't use it but noone can use it either; however, if somebody now has your domain, they could be able to impersonate you.
Post reply on HN