Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

321–330 of 544 posts

Re: Don't use third party auth to sign in

#321
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

Related to your warning, the story of that guy who lost his @n Twitter account because of that[1] (even though I think it still reduces the impact radius because until your password gets reset you can still access the service)

[1]: https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...

Re: Don't use third party auth to sign in

#323

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

> I'm honestly not sure where we went so wrong as a society so as to reach this point... Why? The answer is actually very simple: spam. AFAIK pretty much all disabled Google accounts come from Google believing they are part of a spam-sending (or malware-spreading) network. The ability to sign up for free Google accounts means this is a prime target for spammers to use and abuse -- signing up for free Gmail/Drive acco…

Is this speculation, or the comprehensive, objective explanation?

Re: Don't use third party auth to sign in

#324

Technically email becomes the skeleton key regardless. And that is dependent upon at least one third party: domain registrars. And possibly email providers too. Though the post does have a good point on that non-email auth providers add more risk to the equation.

> that is dependent upon at least one third party: domain registrars Kind of. You will have a bad day (or month) if your domain registrar is screwing you. But you do own the domain. So you should be able to get it back. With Google/Facebook and similar you have no right to your account.

> But you do own the domain.

Be careful not to overstate here -- this is only true for restricted definitions of "own".

However, your point remains valid. Control of a domain name is much more predictable and defensible than control of a Google/etc account.

Choose the TLD and the registrar carefully, and do not fail to pay registration fees.

Re: Don't use third party auth to sign in

#325

Who has changed the the title of the HN submission? It was "Never use Google to sign in" and it's still that when following the link. According to submission rules it should not redacted.

I had to goto the second page to find someone asking this same question I had, and now when I come back to reply to it I find it's been downvoted even further into grey.

What is actually going on @dang ? He asked a legit question and even the OP isn't sure what's up.

Re: Don't use third party auth to sign in

#327
post #320

When you use Google or FB or others to sign in, you just get some data, that you can trust. Internally, on my website, i may have an account, that i then link to this Google or FB account. 1) If Google shuts down an account, authorization might still work for the purpose of logging in somewhere else. Your email might not work anymore, like any other services within Google. But authorization does. That it does not, is…

Regarding point 3, the trend is in the direction of making your devices a lot less "yours", and a lot more hooked into 3rd (4th, etc) party services.

Re: Don't use third party auth to sign in

#328

Earlier quoted context omitted.

See also: Kindle books; movies "purchased" from Amazon, Apple, et al; Tesla upgrades you paid extra for; I could go on....

Kindle books were actually pretty good, back when they could reliably be liberated. Unfortunately, that's no longer the case. In general, I think that's also a point we can draw from the cyberpunk genre, or maybe from Harry Harrison's old-school prefiguration of it in the Stainless Steel Rat series - the eponymous creature being one well suited to thrive "within the walls" of a society increasingly sclerotized with t…

Off-topic, but legitimately purchased Kindle ebooks can still be quickly and easily liberated for the purposes of DRM-free personal backups of owned content. I won't comment on whether Amazon find this acceptable, or if it is legal in any given jurisdiction, but it is definitely possible.

Re: Don't use third party auth to sign in

#329
post #307

Earlier quoted context omitted.

Put simply, one's house is literally on their own property, and one's Gmail account is literally on Google's property. If someone owned a vast amount of land, more than needed for everyone on earth to build a house, and the owner told people they could freely build structures but you lose it if you break the rules and the rules can change any time...

Land is a weak analogy here, because land is scarce.

I've had a recruitment consultant suggest I use a gmail e-mail address on my CV, because it looks weird to have an address at a domain (my own, and not anything strange btw) that people haven't heard of. Sounds crazy. But try dictating an e-mail address over the phone to a hotel or whatever and see that if you say 'Fred Bloggs seventy six at gmail dot com' or whatever, you never have to repeat yourself, whereas anything less usual you'll be spelling it out all day.

On the technical side, one hears about individuals' domains being marked (blamelessly) as possible-spammers by the big e-mail services, and finding it hard to get messages through. There is effectively some scarcity in legible, desirable gmail addresses.

Re: Don't use third party auth to sign in

#330

Earlier quoted context omitted.

Yeah. Reddit is especially really intrusive and annoying. I feel like they just don't want people to use their site anymore. Whenever I open new Reddit, my memory and CPU usage goes up so badly.

Reddit website unusable on mobile, it cuts all images in half for me (Nokia 3.1 and Samsung A51), and it's just laggy. I use RedReader from F-Droid instead.

Yes, it also loads forever, hides half the comments, constant pop-ups telling you to use the app instead, cannot read some (non-quarantined) subs without logging in, no NSFW without logging in, back button is broken, frequent error in loading pages...

On the desktop it still usable with old.reddit.com.

But honestly it's probably for the best, less time wasted.

Post reply on HN