Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

391–400 of 544 posts

Re: Don't use third party auth to sign in

#391
I recently got locked out of my Amazon account. While trying to get it unlocked, I faced one of the worst experiences with Amazon customer team. I even reached to Jeff's email, but no reply. Finally, I have to file an official complaint in the consumer court to get my account unlock. All of these event took around 14-15 days. During these days, I was suddenly unable to use my Echo, Prime video, Kindle books, readwise, and prime now services. I never really tried any other competitor service before, and was solely reliant on Amazon's offering. That time I realized the amount of power such single sign-in yielded. I can only imagine what happens when you use it for every service via a third party and use it daily, only to suddenly see it lock you out. I hope there's a better way to login in the future, maybe something like trusona or magic

PS: I did not do anything wrong but still suffered lot of psychological pain due to this mistake by Amazon's internal security.

Re: Don't use third party auth to sign in

#392

Earlier quoted context omitted.

See also: Kindle books; movies "purchased" from Amazon, Apple, et al; Tesla upgrades you paid extra for; I could go on....

This is precisely why I buy vinyl or music from Bandcamp, and choose the disc version of the PS5. I view my digital purchases as things I am forever renting.

... You can't store MP3 files why? You're renting your hard drives, too?

Re: Don't use third party auth to sign in

#393
post #382

_A plea to the moderators:_ Please change the title of the submission back to match the title of the blog post, "Never Use Google to Sign-In". To be fair to Google I have clearly called out all third-parties in the blog post, some by name. I used Google's name in the title because that name elicits reaction from almost 100% of the audience, since almost everyone has used Google services at some point. I myself am a h…

I.e. you want this article to be clickbait and now you are unhappy that it is not.

Way to speak for another person's intentions AND feelings! That's where we are nowadays, I guess.

It's their article, I think it's fair they ask for the name of the post to be preserved. It has nothing to do with their intent (clickbait or not) that the audience here voted up their submission.

Re: Don't use third party auth to sign in

#394

_A plea to the moderators:_ Please change the title of the submission back to match the title of the blog post, "Never Use Google to Sign-In". To be fair to Google I have clearly called out all third-parties in the blog post, some by name. I used Google's name in the title because that name elicits reaction from almost 100% of the audience, since almost everyone has used Google services at some point. I myself am a h…

The reader will still see your title when they visit the house page.

[deleted]

Re: Don't use third party auth to sign in

#395

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

Cool demo. I couldn’t figure out how to make an account though.

I think this would need serious widespread adoption until we saw benefits too. And you’d need some big names...like Google. Which probably will never happen.

Re: Don't use third party auth to sign in

#396
post #236

Earlier quoted context omitted.

- does you registrar have physical office? is it in a country with legislation friendly towards the country you're based in? - does your registrar send Auth-Info code over email in plain text? - did you enter real contact and residence data when registering the domain including public WHOIS database? This is only a fraction of the attack vector.

> does you registrar have physical office? Yes. > is it in a country with legislation friendly towards the country you're based in? It's in the same country. > does your registrar send Auth-Info code over email in plain text? Of course not, that would be a big red-flag. > did you enter real contact and residence data when registering the domain including public WHOIS database? I have no idea what a public WHOIS datab…

I mean the contact details specified at the registrar and returned over the WHOIS protocol. Depending on the nature of a conflict the entity returned by the WHOIS requests might be considered the owner of the domain.

Unfortunate phrasing on my side:) Actually there exist scammers reaching out to well known mailbox names and requesting a fee for an entry in "WHOIS database".

Re: Don't use third party auth to sign in

#397
post #307

Earlier quoted context omitted.

Put simply, one's house is literally on their own property, and one's Gmail account is literally on Google's property. If someone owned a vast amount of land, more than needed for everyone on earth to build a house, and the owner told people they could freely build structures but you lose it if you break the rules and the rules can change any time...

Land is a weak analogy here, because land is scarce.

The scarcity of land makes it different, but not a weak analogy.

Re: Don't use third party auth to sign in

#398
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

You can do this without paying as well. If your DNS provider supports email forwarding you can use that (if it doesnt you can use improvmx free tier) and use gmail's inbuilt smtp server to send emails using your own domain.

Ya but then you can’t use googles SSO right?

Re: Don't use third party auth to sign in

#399

Earlier quoted context omitted.

The speed of technological development is faster than the speed of societal or legal development. So yes, right now we've woken up in a world that is not so much cyberpunk as it is techno-feudalism: more and more do you need a presence on the Internet to do things in meatspace... And that presence is by the grace of several feudal lords (Google foremost) - woe betide you should you ever displease them. You do not rea…

OT: Please tell me you have a blog, I enjoy the way you write. — I run my own mail server but my VPS provider could be coerced to yank it from me. You’ve made me uncomfortable with revelations. Damn, we’re fucked.

> I run my own mail server but my VPS provider could be coerced to yank it from me.

I've got two comments on this.

Firstly, you're already doing much better than most people. Make frequent backups, and if it comes down to it, you can always point DNS at a new provider.

Second, don't put anything on a VPS that you aren't willing to let the VPS provider or whatever Gov. has jurisdiction access. Where email falls on that spectrum for you is of course your own decision.

Re: Don't use third party auth to sign in

#400
post #346

Earlier quoted context omitted.

> I'm honestly not sure where we went so wrong as a society so as to reach this point... Why? The answer is actually very simple: spam. AFAIK pretty much all disabled Google accounts come from Google believing they are part of a spam-sending (or malware-spreading) network. The ability to sign up for free Google accounts means this is a prime target for spammers to use and abuse -- signing up for free Gmail/Drive acco…

You’d think there’d be a very simple solution to this—one that I believe Google already used for a long time, but just never generalized. That approach: “proof of human work.” Google owns ReCAPTCHA, and every time you do a ReCAPTCHA for Google, you’re doing a little one-time proof-of-humanity for them. But it’s also a proof-of-work; and proofs-of-work that cannot be automated are aggregatable. In other words, the fac…

Even when logged into Google, search still often enough thinks I'm a bot...
Post reply on HN