Don't use third party auth to sign in
331–340 of 544 posts
Re: Don't use third party auth to sign in
#332Re: Don't use third party auth to sign in
#333Earlier quoted context omitted.
US national politics. One party is in bed with the copyright owners, the other doesn’t believe that the government should govern. Google fills the gap.
> One party is in bed with the copyright owners, the other doesn’t believe that the government should govern This political model is dated. Republicans are no longer conservative. And Democrats have an ascendant progressive wing that rejects corporate influence wholesale.
Who mostly organise and communicate on giant social media platforms, who they campaign to fact-check things. Not exactly wholesale rejection.
Re: Don't use third party auth to sign in
#334The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…
Re: Don't use third party auth to sign in
#335Earlier quoted context omitted.
There's no good reason not to use a password manager in 2020. I recommend this one: https://www.passwordstore.org/
No good reason until an exploit comes out that wreaks havoc.
Re: Don't use third party auth to sign in
#336Earlier quoted context omitted.
> One party is in bed with the copyright owners, the other doesn’t believe that the government should govern This political model is dated. Republicans are no longer conservative. And Democrats have an ascendant progressive wing that rejects corporate influence wholesale.
They will milk you for your vote but when power is won you will be excluded. Look at what happened last week on the leaked conference call. Progressives were blamed for losing so many house/senate races.
Re: Don't use third party auth to sign in
#337Earlier quoted context omitted.
I'm having trouble understanding your point. Leaving aside simply googling it, surely you can't be saying that because you haven't heard of something, it doesn't exist or isn't a threat or isn't worth any concern.
That exact "logic" is extremely common in journalism, as well as on most social media platforms including this one. If you think about it, this shouldn't be all that surprising - after all, this is exactly how intuition works, and the human mind runs very much on intuition, people just don't realize it (at the object level).
Re: Don't use third party auth to sign in
#338The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…
Re: Don't use third party auth to sign in
#339Earlier quoted context omitted.
I use different services for different things. I have 3 email accounts at FastMail and 6 at ProtonMail. Also, some of it is inertia: I've hosted the MX for sneak.berlin at FastMail for several years (and have prepaid some time into the future), and have only been using ProtonMail for about one year (and the HOWTO article is recent). The fact that FastMail might be subject to the new Australian crypto key escrow law[1…
> The fact that FastMail might be subject to the new Australian crypto key escrow law FM is saying it doesn’t affect them, as they are not a secure provider and can already give any information out upon lawful requests. Do you disagree with that?
That in short, the A&A bill is about breaking end-to-end encryption, which Fastmail has never had anything to do with. It’s scary-sounding legislation, and I reckon it’s misguided at best, but it honestly doesn’t affect all that many businesses [note I’m saying businesses rather than people; many affected businesses will be among the largest ones, serving consumers], because end-to-end encryption of communications is uncommon, because it’s so frightfully inconvenient for all parties involved, because now the server is necessarily dumb and the client has to do a lot more work, and things like searching are typically just altogether broken because you’ll need the full index on the client to do a search.
(And specifically of the domain of email, I wouldn’t trust first-party encryption; if you care about governments accessing your data, first-party encryption such as ProtonMail offers is almost equivalent to no encryption if you can’t verify the code that is running, since that party may be compelled to backdoor the code to steal your password. This is one of the many reasons that Fastmail has never implemented PGP, ⅌ https://fastmail.blog/2016/12/10/why-we-dont-offer-pgp/.)
Re: Don't use third party auth to sign in
#340Has anyone else noticed random popups on 3rd party websites asking for google sign in? I even used firefox when it happened: https://imgur.com/a/JC52lBV (lequipe.fr) https://imgur.com/a/VSM3Uk9 (reddit.com) https://imgur.com/a/KpVCYBL (medium.com)
Really the dumbest, most confusing design I've ever seen to make a website seem like it knows who you are when you visit as a guest. When I first saw it on Pinterest, it took me a moment to figure out what I was looking at as a web developer of 20 years. My girlfriend still didn't get it after I was explaining it to her. How does anyone else have a shot at arriving at "oh, so the site doesn't actually have access to…