Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

331–340 of 544 posts

Re: Don't use third party auth to sign in

#333

Earlier quoted context omitted.

US national politics. One party is in bed with the copyright owners, the other doesn’t believe that the government should govern. Google fills the gap.

> One party is in bed with the copyright owners, the other doesn’t believe that the government should govern This political model is dated. Republicans are no longer conservative. And Democrats have an ascendant progressive wing that rejects corporate influence wholesale.

> Democrats have an ascendant progressive wing that rejects corporate influence wholesale

Who mostly organise and communicate on giant social media platforms, who they campaign to fact-check things. Not exactly wholesale rejection.

Re: Don't use third party auth to sign in

#334

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

[deleted]

Re: Don't use third party auth to sign in

#335
post #287

Earlier quoted context omitted.

There's no good reason not to use a password manager in 2020. I recommend this one: https://www.passwordstore.org/

No good reason until an exploit comes out that wreaks havoc.

Hard to imagine what sort of exploit could come out that could cause havoc when the encrypted passwords are stored on your device.

Re: Don't use third party auth to sign in

#336
post #289

Earlier quoted context omitted.

> One party is in bed with the copyright owners, the other doesn’t believe that the government should govern This political model is dated. Republicans are no longer conservative. And Democrats have an ascendant progressive wing that rejects corporate influence wholesale.

They will milk you for your vote but when power is won you will be excluded. Look at what happened last week on the leaked conference call. Progressives were blamed for losing so many house/senate races.

Can you provide a link/name for this leaked conference call? I'm interested in listening to it.

Re: Don't use third party auth to sign in

#337

Earlier quoted context omitted.

I'm having trouble understanding your point. Leaving aside simply googling it, surely you can't be saying that because you haven't heard of something, it doesn't exist or isn't a threat or isn't worth any concern.

That exact "logic" is extremely common in journalism, as well as on most social media platforms including this one. If you think about it, this shouldn't be all that surprising - after all, this is exactly how intuition works, and the human mind runs very much on intuition, people just don't realize it (at the object level).

I've never heard of intuition so this must false. I'm sure I'd know about it otherwise.

Re: Don't use third party auth to sign in

#338

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

this uses OIDC. it’s a non starter, for reasons unrelated to the part you are “solving” here.

Re: Don't use third party auth to sign in

#339
post #121

Earlier quoted context omitted.

I use different services for different things. I have 3 email accounts at FastMail and 6 at ProtonMail. Also, some of it is inertia: I've hosted the MX for sneak.berlin at FastMail for several years (and have prepaid some time into the future), and have only been using ProtonMail for about one year (and the HOWTO article is recent). The fact that FastMail might be subject to the new Australian crypto key escrow law[1…

> The fact that FastMail might be subject to the new Australian crypto key escrow law FM is saying it doesn’t affect them, as they are not a secure provider and can already give any information out upon lawful requests. Do you disagree with that?

Fastmail’s specific response: https://fastmail.blog/2018/12/21/advocating-for-privacy-aabi...

That in short, the A&A bill is about breaking end-to-end encryption, which Fastmail has never had anything to do with. It’s scary-sounding legislation, and I reckon it’s misguided at best, but it honestly doesn’t affect all that many businesses [note I’m saying businesses rather than people; many affected businesses will be among the largest ones, serving consumers], because end-to-end encryption of communications is uncommon, because it’s so frightfully inconvenient for all parties involved, because now the server is necessarily dumb and the client has to do a lot more work, and things like searching are typically just altogether broken because you’ll need the full index on the client to do a search.

(And specifically of the domain of email, I wouldn’t trust first-party encryption; if you care about governments accessing your data, first-party encryption such as ProtonMail offers is almost equivalent to no encryption if you can’t verify the code that is running, since that party may be compelled to backdoor the code to steal your password. This is one of the many reasons that Fastmail has never implemented PGP, ⅌ https://fastmail.blog/2016/12/10/why-we-dont-offer-pgp/.)

Re: Don't use third party auth to sign in

#340
post #6

Has anyone else noticed random popups on 3rd party websites asking for google sign in? I even used firefox when it happened: https://imgur.com/a/JC52lBV (lequipe.fr) https://imgur.com/a/VSM3Uk9 (reddit.com) https://imgur.com/a/KpVCYBL (medium.com)

Really the dumbest, most confusing design I've ever seen to make a website seem like it knows who you are when you visit as a guest. When I first saw it on Pinterest, it took me a moment to figure out what I was looking at as a web developer of 20 years. My girlfriend still didn't get it after I was explaining it to her. How does anyone else have a shot at arriving at "oh, so the site doesn't actually have access to…

If you empathize with normal users, you realize they don't care the least about any of this. They want to use a convenient service to do things. To post pictures of themselves, to see what their friends and frenemies are up to, what's the new cool thing etc etc. Login should just work, nobody cares what is displayed where, and which site knows what. Normal people (outside the HN) bubble don't care about these things, like privacy and what data they share. It doesn't get them closer to the things they want to do online, that is post things and consume content.
Post reply on HN