Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

341–350 of 544 posts

Re: Don't use third party auth to sign in

#341
post #287
post #190

Earlier quoted context omitted.

I don't want more accounts and passwords. The security seems strictly worse than just authenticating against my email provider directly.

There's no good reason not to use a password manager in 2020. I recommend this one: https://www.passwordstore.org/

Is there an android app for it?

Re: Don't use third party auth to sign in

#342

Earlier quoted context omitted.

it's incredibly rare to personally know someone it happened to I don't know anyone who has a degree in History but that doesn't mean historians are especially unusual. All it means is that my network is quite small. The same is true here. The fact few people know someone who has been affected by this problem doesn't mean the problem is unusual. It just means there are hundreds of millions of people who use Google and…

According to the Bureau of Labor Statistics, the number of historian jobs in 2019 was 3500 - that's in the entire US. So... incredibly rare, really.

All the unemployed historians now feel oppressed, thanks.

Re: Don't use third party auth to sign in

#343
post #286

Earlier quoted context omitted.

See also: Kindle books; movies "purchased" from Amazon, Apple, et al; Tesla upgrades you paid extra for; I could go on....

I have yet to hear about the first amazon account ban. I don’t think they’re really interested in that, since the accounts are almost by definition making them a bunch of money.

There was the case when they remotely deleted the novel 1984 from a bunch of devices.

Re: Don't use third party auth to sign in

#344
post #189

Earlier quoted context omitted.

For similar reasons that you and I use password managers, but add lower friction to the mix.

One could even eliminate those same tasks (not wanting to remember a new password, and not wanting to use a password manager) by setting an unmemorable password and doing a password reset using a Gmail address every time they want to log in. "Log in using Google" basically does that same sort of thing but without the tedium of all the clicking/typing. The mechanism is much different but in terms of dependencies it's…

Slack has this I think. You just sign in with a special link sent via email.

Re: Don't use third party auth to sign in

#345
post #320

When you use Google or FB or others to sign in, you just get some data, that you can trust. Internally, on my website, i may have an account, that i then link to this Google or FB account. 1) If Google shuts down an account, authorization might still work for the purpose of logging in somewhere else. Your email might not work anymore, like any other services within Google. But authorization does. That it does not, is…

Regarding point 3, the trend is in the direction of making your devices a lot less "yours", and a lot more hooked into 3rd (4th, etc) party services.

Many people use yubikeys, for example. As a user, i declare ownership over these keys. I buy these. They become mine. And i use them then for authorization.

So it is a mix, i would argue. For machines it is just important to identify you. And in the past, so i have read the users, they all want to get away from password authorization. Just make the darn thing recognize me. (and sometimes not)

Re: Don't use third party auth to sign in

#346

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

> I'm honestly not sure where we went so wrong as a society so as to reach this point... Why? The answer is actually very simple: spam. AFAIK pretty much all disabled Google accounts come from Google believing they are part of a spam-sending (or malware-spreading) network. The ability to sign up for free Google accounts means this is a prime target for spammers to use and abuse -- signing up for free Gmail/Drive acco…

You’d think there’d be a very simple solution to this—one that I believe Google already used for a long time, but just never generalized.

That approach: “proof of human work.” Google owns ReCAPTCHA, and every time you do a ReCAPTCHA for Google, you’re doing a little one-time proof-of-humanity for them. But it’s also a proof-of-work; and proofs-of-work that cannot be automated are aggregatable.

In other words, the fact that someone with Google account X solved a ReCAPTCHA, doesn’t just tell you something about who that account is lately. It should add to a sort of “human-proof credit score” for the account, where Google’s systems are more willing to put faith in the user because of all the times they’ve proven themselves human already.

And, for some scenarios, Google does use the aggregate proof ReCAPTCHA represents this way. This is why you’ll never see the Google Search “stop searching so fast” message when accessing Search through Chrome synced to a well-used Google account; why you’ll get a ReCAPTCHA portal from them instead if you’re not logged in (you’re being asked to build the credit score of your IP/session); and why you’ll be denied upfront if you perform botlike behavior through Tor (where there’s nothing that can be correlated to give you a persistent credit score.)

Now, such a “highly-proven” Google account could still be heuristically detected elsewhere in Google’s systems as being responsible for botlike behavior (e.g. spamming); but, when such a highly-proven account is flagged, it should go in for manual review. Because — as you say — this is incredibly rare! So this process doesn’t need to scale through automation, the way regular Google processes do. It can be high-touch.

But right now, it’s not. (Or they’re just not even using the high-proof-of-humanity metadata on the account during this determination.) Either way, that’s kind of silly.

Re: Don't use third party auth to sign in

#347
post #289

Earlier quoted context omitted.

They will milk you for your vote but when power is won you will be excluded. Look at what happened last week on the leaked conference call. Progressives were blamed for losing so many house/senate races.

Can you provide a link/name for this leaked conference call? I'm interested in listening to it.

Not op but hre's an article https://www.bloomberg.com/news/articles/2020-11-06/house-dem...

Re: Don't use third party auth to sign in

#348

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

Why – "Sufficiently Powerful Optimization Of Any Known Target Destroys All Value" https://thezvi.wordpress.com/2019/12/31/does-big-business-ha...

Re: Don't use third party auth to sign in

#349

Earlier quoted context omitted.

it's incredibly rare to personally know someone it happened to I don't know anyone who has a degree in History but that doesn't mean historians are especially unusual. All it means is that my network is quite small. The same is true here. The fact few people know someone who has been affected by this problem doesn't mean the problem is unusual. It just means there are hundreds of millions of people who use Google and…

According to the Bureau of Labor Statistics, the number of historian jobs in 2019 was 3500 - that's in the entire US. So... incredibly rare, really.

They did say "degree in history" rather than "job as historian" though.

Re: Don't use third party auth to sign in

#350

Earlier quoted context omitted.

The speed of technological development is faster than the speed of societal or legal development. So yes, right now we've woken up in a world that is not so much cyberpunk as it is techno-feudalism: more and more do you need a presence on the Internet to do things in meatspace... And that presence is by the grace of several feudal lords (Google foremost) - woe betide you should you ever displease them. You do not rea…

Techno-feudalism is exactly what cyberpunk novels were describing. They were dystopias. They were warnings about letting corporations control everything.

Techno-feudalism and anarcho-syndicalism will form a dynamic balance, if the prophets are to be believed. :-)
Post reply on HN