Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

291–300 of 544 posts

Re: Don't use third party auth to sign in

#291
post #281

Earlier quoted context omitted.

Because we were making money . When I got started programming full time, tons of people in the software industry were getting their rocks off on how simple it is to install an Oauth library, making it easy as pie for people to sign in to a web service, thus encouraging more sign ups and making more money. Maybe we've forgotten just how much of a hard-on we and the entire world once had for the likes of Google. 8 year…

Your generation might be guilty. But those that came before and after knew better. This is the generation who thought using their real names online was a good idea. That's where things went wrong. Never in my life did I see an Oauth libruary and think this is easy as pie. Overcomplicated perhaps.

[deleted]

Re: Don't use third party auth to sign in

#292

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

The speed of technological development is faster than the speed of societal or legal development. So yes, right now we've woken up in a world that is not so much cyberpunk as it is techno-feudalism: more and more do you need a presence on the Internet to do things in meatspace... And that presence is by the grace of several feudal lords (Google foremost) - woe betide you should you ever displease them. You do not rea…

Not wrong.

But even a little plutonium is too dangerous to let my kid play with it.

Email? Not quite as much.

Re: Don't use third party auth to sign in

#293

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

> which proves that this is possible.

How does it prove that?

Re: Don't use third party auth to sign in

#294
post #230

Earlier quoted context omitted.

> I'm honestly not sure where we went so wrong as a society so as to reach this point... Why? The answer is actually very simple: spam. AFAIK pretty much all disabled Google accounts come from Google believing they are part of a spam-sending (or malware-spreading) network. The ability to sign up for free Google accounts means this is a prime target for spammers to use and abuse -- signing up for free Gmail/Drive acco…

>"It's like worrying about being struck by lightning." If lightning strikes there is not much to be done. Google however can and must have reasonable process to restore the status.

Yeah, the fact that it’s like being hit by lightning is exactly the issue.

Re: Don't use third party auth to sign in

#295

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

[deleted]

Re: Don't use third party auth to sign in

#297
post #269

Earlier quoted context omitted.

I don’t see what’s lost if Google disabled my account. Yeah, photos, emails and similar but that is not really life changing. I’m not saying it’s an unworthy cause to advocate a change but I’m just not seeing the moral weight compared to factory farming, and other hard industries that have an effect on societies and the planet.

You're setting a very high bar there, and then claiming that losing access to your gmail account isn't worse than that therefore it's not life changing. Email ends up being the form of online identity for a lot of people, myself included, so that almost every service that I sign for has my email address as ID. If that email address isn't the ID, it's the preferred way of resetting passwords. I wouldn't be super happy…

I do have a lot of stuff that I’d be sad about if lost on Google. And yes, I would be inconvenienced to contact all the services for an email change. But when talking about how our society got to where it is now, I just can’t see the moral weight of these kinds of monopolies in the context of just losing access.

Re: Don't use third party auth to sign in

#298

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

> I'm honestly not sure where we went so wrong as a society so as to reach this point... Why? The answer is actually very simple: spam. AFAIK pretty much all disabled Google accounts come from Google believing they are part of a spam-sending (or malware-spreading) network. The ability to sign up for free Google accounts means this is a prime target for spammers to use and abuse -- signing up for free Gmail/Drive acco…

Would be good if Google just published the stats on their transparency report:

https://transparencyreport.google.com/

Re: Don't use third party auth to sign in

#299
post #281

Earlier quoted context omitted.

Because we were making money . When I got started programming full time, tons of people in the software industry were getting their rocks off on how simple it is to install an Oauth library, making it easy as pie for people to sign in to a web service, thus encouraging more sign ups and making more money. Maybe we've forgotten just how much of a hard-on we and the entire world once had for the likes of Google. 8 year…

Your generation might be guilty. But those that came before and after knew better. This is the generation who thought using their real names online was a good idea. That's where things went wrong. Never in my life did I see an Oauth libruary and think this is easy as pie. Overcomplicated perhaps.

There is no generation that has a great track record with security.

Re: Don't use third party auth to sign in

#300
post #286

Earlier quoted context omitted.

See also: Kindle books; movies "purchased" from Amazon, Apple, et al; Tesla upgrades you paid extra for; I could go on....

I have yet to hear about the first amazon account ban. I don’t think they’re really interested in that, since the accounts are almost by definition making them a bunch of money.

https://www.cnet.com/news/amazon-banned-this-shopper-then-he... talks about it - the primary reason is for excessive returns. Alternatively, there are sellers as well that are more in danger.
Post reply on HN