Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

401–410 of 544 posts

Re: Don't use third party auth to sign in

#401
post #389
post #382

Earlier quoted context omitted.

I.e. you want this article to be clickbait and now you are unhappy that it is not.

All titles are clickbait, researchers, bloggers, youtuber, conference speakers, and journalists who succeed are also ones who know how to choose good titles

Not all titles are clickbait, and even if the majority are, we should strive for better

Re: Don't use third party auth to sign in

#402
post #362
post #354

Where can I check which websites I looged in with google? I found https://myaccount.google.com/permissions?gar=1 but 26 apps is like 1/10 of what I have I think

OAuth apps don't necessarily appear there, only apps using additional scopes than basic profile verification and email address

I think all OAuth apps are supposed to show up there - I have both apps with basic account info only, and apps with more.

Re: Don't use third party auth to sign in

#403

Earlier quoted context omitted.

They did say "degree in history" rather than "job as historian" though.

Exactly. The number of people in the US workforce who have a history degree is a little over a million ( https://datausa.io/profile/cip/history ).

Undergraduate degrees are easy to get. Having a psychology degree doesn’t mean you’re a psychologists, a history degree doesn’t mean you’re a historian, and a math degree doesn’t mean you’re a mathematician.

The extremely large majority of people go on to work regular jobs that have nothing to do with their degree and lose much of the information they learned, if it was even substantial at all.

Re: Don't use third party auth to sign in

#404
What if the site you’re using is properly configured and uses this third party to confirm your email address? Can’t you then sign in using a different trusted intermediary or email if something goes awry with the one you used the first time?

Re: Don't use third party auth to sign in

#405

Earlier quoted context omitted.

this uses OIDC. it’s a non starter, for reasons unrelated to the part you are “solving” here.

Can you be more specific?

For a smaller company, that doesn't have the ability to dedicate a team of people to authn and authz, OIDC/OAuth/SAML/etc are all extremely complicated tools that take a lot of experience to even begin to understand the terminology. Ask your average engineer to implement logins for an API they'll be able to do it. Ask your average engineer to implement current SSO-like integrations for even the most standard of use cases (website logins) and it's a huge pain. Drift ever so slightly off the beaten path (IoT devices for example) and you're in for a "fun" time.

Re: Don't use third party auth to sign in

#406
post #6

Has anyone else noticed random popups on 3rd party websites asking for google sign in? I even used firefox when it happened: https://imgur.com/a/JC52lBV (lequipe.fr) https://imgur.com/a/VSM3Uk9 (reddit.com) https://imgur.com/a/KpVCYBL (medium.com)

Yes and it pissed me off because on mobile it pops up like 0.5-2 seconds late so if you're unlucky you go to click on something and it popups up under your finger and you've suddenly signed up and shared your info with a company you had no intention of ever signing up with. I complained to Google. I have a GSuites domain and I don't want my users to be able to sign up via Google. No resolution. I suggest you all comp…

> popups up under your finger and you've suddenly signed up

Happened to me as well. So i guess their plan worked. So glad they care about my privacy.

Re: Don't use third party auth to sign in

#407
post #304
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

As long as you don't want to use any Nest products, which now insist that you have a gmail.com address as apparently hosted domains are for business only.

There have been a ton of products where Google didn't initially support that but eventually added it. Maybe Nest will one day.

Obviously their sign-in/account infrastructure creates technical impediments against making their products do what they want. They should really fix that.

Re: Don't use third party auth to sign in

#408

Earlier quoted context omitted.

See also: Kindle books; movies "purchased" from Amazon, Apple, et al; Tesla upgrades you paid extra for; I could go on....

This is precisely why I buy vinyl or music from Bandcamp, and choose the disc version of the PS5. I view my digital purchases as things I am forever renting.

Those discs aren't going to do you much good if you don't have access to or have had access to PSN, since most games ship with a huge day 1 patch to fix all the issues between going gold and the date of sale.

Movies/Music/Books can be displayed and played back on damn near anything. Games, especially modern games, exist in both a variable state (constantly revised/updated), but also with a much more limited ability to access the content.

Re: Don't use third party auth to sign in

#410

_A plea to the moderators:_ Please change the title of the submission back to match the title of the blog post, "Never Use Google to Sign-In". To be fair to Google I have clearly called out all third-parties in the blog post, some by name. I used Google's name in the title because that name elicits reaction from almost 100% of the audience, since almost everyone has used Google services at some point. I myself am a h…

A famous youtuber lost access to his TikTok account when Facebook banned him because he was using Facebook login.

https://youtu.be/oJcEDzgPRrc?t=57 (warning, the video is somewhat off-color)

Post reply on HN