Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

271–280 of 544 posts

Re: Don't use third party auth to sign in

#272

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

> I'm honestly not sure where we went so wrong as a society so as to reach this point... Why? The answer is actually very simple: spam. AFAIK pretty much all disabled Google accounts come from Google believing they are part of a spam-sending (or malware-spreading) network. The ability to sign up for free Google accounts means this is a prime target for spammers to use and abuse -- signing up for free Gmail/Drive acco…

it's incredibly rare to personally know someone it happened to

I don't know anyone who has a degree in History but that doesn't mean historians are especially unusual. All it means is that my network is quite small.

The same is true here. The fact few people know someone who has been affected by this problem doesn't mean the problem is unusual. It just means there are hundreds of millions of people who use Google and you know a few thousand at most.

Re: Don't use third party auth to sign in

#273
Yeah, I just realized this myself.

Never really thought about it until I started seeing Google, Twitter, Facebook and other large companies, start banning people for political reasons.

Imagine if you signed into some site using your Facebook account, and then some intern at Facebook moderating posts didn't like some political statement you ban, and suspended your account?

Like the article says, you're not just locked out of Facebook, but any other account that uses Facebook to authenticate.

That give these sites an insane amount of power. You can argue these massive companies have a right to ban whoever they want on their own platforms, for whatever reason they want. But they shouldn't have a right to ban people on other platforms.

Even if a ban/suspension is made in error and can be reversed, that could still cause someone a lot of harm, or be used as a political weapon. That's legitimately scary.

Re: Don't use third party auth to sign in

#274

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

The speed of technological development is faster than the speed of societal or legal development. So yes, right now we've woken up in a world that is not so much cyberpunk as it is techno-feudalism: more and more do you need a presence on the Internet to do things in meatspace... And that presence is by the grace of several feudal lords (Google foremost) - woe betide you should you ever displease them. You do not rea…

Techno-feudalism is exactly what cyberpunk novels were describing. They were dystopias. They were warnings about letting corporations control everything.

Re: Don't use third party auth to sign in

#275
The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in.

But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication?

Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again. If we had something open source, that would allow you to sign in to all the sites you use, while completely protecting your privacy, so none of them know who you are.

This dream can come true. Technically at least. I've taken the the first baby steps with https://promiseauthentication.org which proves that this is possible.

But, for this to become a reality, we really need to start running in the same direction. A collective movement towards a sane, privacy-first Single Sign-On provider that's easy to use for everybody.

Re: Don't use third party auth to sign in

#276
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

Yeah but they’ve still got your emails.

There's this thing called principle. It's not that we do something because we believe it's going to work. We do things out of principle because doing the right thing is the only rational alternative; because, if everyone held the same principles, then the problem would be snuffed of oxygen.

Re: Don't use third party auth to sign in

#278

Also. HOW do you know it’s a real Google sign-in instead of a fake password stealing form? We’ve trained generations of users to accept it’s alright to give their Google/Facebook/Twitter credentials to any random site under the sun.

Only type your Google password if the site is accounts.google.com.

https://www.wordfence.com/blog/2017/01/gmail-phishing-data-u...

Better yet, use FIDO.

Re: Don't use third party auth to sign in

#279

Earlier quoted context omitted.

> [...]starts looking through its database for passwords that look reusable and try them on other important website. How easy would it be to set a nice honeypot website that requires a username/password? > A properly set up google sign in makes it impossible to do that at least. Thoughts? Getting a good password manager and using it correctly removes the threat of someone getting your password and abusing it on other…

Absolutely and I have mentioned it in my comment. However, we all know that most of the people reuse passwords, more than often weak ones. That's who I'm worried for.

I understand. I actually tried to read your comment twice and missed it :-D

I guess I have had a busy week.

Post reply on HN