Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

381–390 of 544 posts

Re: Don't use third party auth to sign in

#381

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

If your house could be removed at a whim because a bot decided you were a bad person

It can.

it would likely cause an uproar,

It doesn’t.

it wouldn't be tolerated.

It is.

Big fat article in the New York Times some months ago about AI deciding that landlords shouldn’t rent to certain people, and the AI often being wrong. Very wrong. Like tagging someone as a convicted drug dealer, when the reality is that person has never been in trouble with the law, and never been to the state where the alleged offense supposedly happened.

We have to stop calling this “artificial intelligence,” because it simply is not intelligent. Humans put faith in machines because were told they are intelligent. But all the evidence shows that at best “AI” is good at guessing.

If we started calling these “artificial guessing” systems, people would treat them appropriately. But that doesn’t buy investors a boat.

Re: Don't use third party auth to sign in

#382

_A plea to the moderators:_ Please change the title of the submission back to match the title of the blog post, "Never Use Google to Sign-In". To be fair to Google I have clearly called out all third-parties in the blog post, some by name. I used Google's name in the title because that name elicits reaction from almost 100% of the audience, since almost everyone has used Google services at some point. I myself am a h…

I.e. you want this article to be clickbait and now you are unhappy that it is not.

Re: Don't use third party auth to sign in

#383

Earlier quoted context omitted.

The speed of technological development is faster than the speed of societal or legal development. So yes, right now we've woken up in a world that is not so much cyberpunk as it is techno-feudalism: more and more do you need a presence on the Internet to do things in meatspace... And that presence is by the grace of several feudal lords (Google foremost) - woe betide you should you ever displease them. You do not rea…

OT: Please tell me you have a blog, I enjoy the way you write. — I run my own mail server but my VPS provider could be coerced to yank it from me. You’ve made me uncomfortable with revelations. Damn, we’re fucked.

Thank you, but none of my ideas are novel in any way[] and there are far better writers than me already expounding the same points, no need to add to the noise. Stallman, Doctorow, et al. pretty much saw these developments coming years ago and warned about them.

[] Every person's thinking and writing is mostly just a pastiche stitched together of thoughts they heard or read from others anyway. (And this is, of course, the meme idea, which is not an original idea itself either)

Re: Don't use third party auth to sign in

#384

_A plea to the moderators:_ Please change the title of the submission back to match the title of the blog post, "Never Use Google to Sign-In". To be fair to Google I have clearly called out all third-parties in the blog post, some by name. I used Google's name in the title because that name elicits reaction from almost 100% of the audience, since almost everyone has used Google services at some point. I myself am a h…

The reader will still see your title when they visit the house page.

Re: Don't use third party auth to sign in

#385

Earlier quoted context omitted.

Kindle books were actually pretty good, back when they could reliably be liberated. Unfortunately, that's no longer the case. In general, I think that's also a point we can draw from the cyberpunk genre, or maybe from Harry Harrison's old-school prefiguration of it in the Stainless Steel Rat series - the eponymous creature being one well suited to thrive "within the walls" of a society increasingly sclerotized with t…

Off-topic, but legitimately purchased Kindle ebooks can still be quickly and easily liberated for the purposes of DRM-free personal backups of owned content. I won't comment on whether Amazon find this acceptable, or if it is legal in any given jurisdiction, but it is definitely possible.

Thankfully it will (probably) never get as bad as Stallman described it[1], but you never know.

[1] https://www.gnu.org/philosophy/right-to-read.html

Re: Don't use third party auth to sign in

#386
post #382

_A plea to the moderators:_ Please change the title of the submission back to match the title of the blog post, "Never Use Google to Sign-In". To be fair to Google I have clearly called out all third-parties in the blog post, some by name. I used Google's name in the title because that name elicits reaction from almost 100% of the audience, since almost everyone has used Google services at some point. I myself am a h…

I.e. you want this article to be clickbait and now you are unhappy that it is not.

I want the title to reflect what prompted this article in the first place. Just as others are calling out, I noticed those Google login boxes on unrelated websites. I want the reader to also make that connection and then read the article to understand what’s at stake.

Re: Don't use third party auth to sign in

#387
post #116
post #6

Has anyone else noticed random popups on 3rd party websites asking for google sign in? I even used firefox when it happened: https://imgur.com/a/JC52lBV (lequipe.fr) https://imgur.com/a/VSM3Uk9 (reddit.com) https://imgur.com/a/KpVCYBL (medium.com)

You can disable these annoying prompts by going to https://myaccount.google.com/permissions and disabling "Google Account sign-in prompts". Ideally it should have been user opt in but Google followed dark pattern here.

I've been fiddling with ublock on how to disable this. would've never guessed about the settings in google account. this should've been disabled by default or an option on the pop-up to permanently disable it.

Re: Don't use third party auth to sign in

#388
post #152

Earlier quoted context omitted.

If anything happens to you which prevents you from renewing your domain, e.g. you are detained or in a coma, then it's probably gone as well unless you have a lot of credit on your registrar account.

Most domain registrars support autorenew with a credit card.

Most credit cards have an expiry date

Re: Don't use third party auth to sign in

#389
post #382

_A plea to the moderators:_ Please change the title of the submission back to match the title of the blog post, "Never Use Google to Sign-In". To be fair to Google I have clearly called out all third-parties in the blog post, some by name. I used Google's name in the title because that name elicits reaction from almost 100% of the audience, since almost everyone has used Google services at some point. I myself am a h…

I.e. you want this article to be clickbait and now you are unhappy that it is not.

All titles are clickbait, researchers, bloggers, youtuber, conference speakers, and journalists who succeed are also ones who know how to choose good titles

Re: Don't use third party auth to sign in

#390
For the average user, with poor password hygiene, I'd advise them to use a federated identity option that is more likely to have a decent password - they are more likely to have a good password for an account they care about.

I think the conclusion of the article is flawed. I think the risk of getting locked out is far lower than the odds of any single, or even all of, other (non-major tech co) website you might join getting breached. It's fair to argue the impact might be less also - and I'm happy to have this debate.

In my experience, typical users aren't the ones that get their google accounts banned - they are always banned for doing something significantly more sophisticated.

Post reply on HN