Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

421–430 of 544 posts

Re: Don't use third party auth to sign in

#421
post #337

Earlier quoted context omitted.

That exact "logic" is extremely common in journalism, as well as on most social media platforms including this one. If you think about it, this shouldn't be all that surprising - after all, this is exactly how intuition works, and the human mind runs very much on intuition, people just don't realize it (at the object level).

I've never heard of intuition so this must false. I'm sure I'd know about it otherwise.

Sometimes I get in a kind of a depressed funk, and then a comment like this comes along to refill my optimism-for-humanity tank.

Re: Don't use third party auth to sign in

#423

_A plea to the moderators:_ Please change the title of the submission back to match the title of the blog post, "Never Use Google to Sign-In". To be fair to Google I have clearly called out all third-parties in the blog post, some by name. I used Google's name in the title because that name elicits reaction from almost 100% of the audience, since almost everyone has used Google services at some point. I myself am a h…

Dissenting. OP, your first sentence is If a website offers you to sign-in using Google (or any third-party service, say Facebook, Github, etc.), don’t use that feature. Titling this as "Third Party Auth" is a reasonable and correct summary of your article. Blaming Google specifically is hype-mongering unless you have a specific gripe against Google - and reading through your post, I don't see a Google-specific critic…

I think the title would be better if it included Facebook because those are the two most prominent and recognizable to the average person.

The title for the HN audience is better, but probably equally misleading since 3rd party auth could include Auth0 or Okta, and personally, if you buy into Apple’s privacy story they should be trusted.

Re: Don't use third party auth to sign in

#424
post #410

_A plea to the moderators:_ Please change the title of the submission back to match the title of the blog post, "Never Use Google to Sign-In". To be fair to Google I have clearly called out all third-parties in the blog post, some by name. I used Google's name in the title because that name elicits reaction from almost 100% of the audience, since almost everyone has used Google services at some point. I myself am a h…

A famous youtuber lost access to his TikTok account when Facebook banned him because he was using Facebook login. https://youtu.be/oJcEDzgPRrc?t=57 (warning, the video is somewhat off-color)

Thanks for sharing this! I didn't find anything off-color in that; maybe it's my level of acceptance.

Re: Don't use third party auth to sign in

#425

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

I don’t see what’s lost if Google disabled my account. Yeah, photos, emails and similar but that is not really life changing. I’m not saying it’s an unworthy cause to advocate a change but I’m just not seeing the moral weight compared to factory farming, and other hard industries that have an effect on societies and the planet.

I lose track of things easily. Gmail is my brain dump. Not only does it track all sorts of important email exchanges, but it also acts as a dump of scans of important documents. I have several gmail addresses so it's not completely single point of failure, but if my hub email was disabled, I am in a world of hurt until I sort things out.

Should I diversify? Probably, but that's more things to secure and keep track of.

Re: Don't use third party auth to sign in

#426

Earlier quoted context omitted.

OT: Please tell me you have a blog, I enjoy the way you write. — I run my own mail server but my VPS provider could be coerced to yank it from me. You’ve made me uncomfortable with revelations. Damn, we’re fucked.

> I run my own mail server but my VPS provider could be coerced to yank it from me. I've got two comments on this. Firstly, you're already doing much better than most people. Make frequent backups, and if it comes down to it, you can always point DNS at a new provider. Second, don't put anything on a VPS that you aren't willing to let the VPS provider or whatever Gov. has jurisdiction access. Where email falls on tha…

There is one more solution. Use a VPS only as an endpoint bastion server. Keep the data and services in your own home server. We need not trust the VPS provider this way. And we can easily recover as long as the domain name and the home server are under your control.

Re: Don't use third party auth to sign in

#427
post #304

Earlier quoted context omitted.

As long as you don't want to use any Nest products, which now insist that you have a gmail.com address as apparently hosted domains are for business only.

There have been a ton of products where Google didn't initially support that but eventually added it. Maybe Nest will one day. Obviously their sign-in/account infrastructure creates technical impediments against making their products do what they want. They should really fix that.

It appears to have been a deliberate choice, and one they have justified on several occasions.

That's not to say you're wrong, but it would be a turnaround at this point.

Re: Don't use third party auth to sign in

#428
post #189

Earlier quoted context omitted.

For similar reasons that you and I use password managers, but add lower friction to the mix.

One could even eliminate those same tasks (not wanting to remember a new password, and not wanting to use a password manager) by setting an unmemorable password and doing a password reset using a Gmail address every time they want to log in. "Log in using Google" basically does that same sort of thing but without the tedium of all the clicking/typing. The mechanism is much different but in terms of dependencies it's…

That doesn't sound like lower friction to normal people.

Re: Don't use third party auth to sign in

#429

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

There's been a W3C standard that meets all those requirements for a couple years now: https://www.w3.org/TR/webauthn/

Only problem is there aren't any password managers that implement it, so it's not actually practical to use as a primary authentication factor yet.

Re: Don't use third party auth to sign in

#430
post #389
post #382

Earlier quoted context omitted.

I.e. you want this article to be clickbait and now you are unhappy that it is not.

All titles are clickbait, researchers, bloggers, youtuber, conference speakers, and journalists who succeed are also ones who know how to choose good titles

Definition of clickbait [1] (emphasis mine): something (such as a headline) designed to make readers want to click on a hyperlink especially when the link leads to content of dubious value or interest.

The title of the article matches the content, so, no, it wasn't a clickbait. Also, if the title was really a clickbait, someone would have surely called it out before my gripe about the title change. In fact, 2 others complained about the title change before I posted my top-level comment; those others' complaints and my responses are now buried under the "More" link at the end of this page.

I understand you, @baby, have good intentions, but I take offense to @bzb6's remarks. I guess that's what I get for responding to a recently created account (41 days ago) with no posts and all of whose comments are one-liners; mostly knee-jerk reactions, no insights, and not considering the nuances of the real-world implications.

[1]: https://www.merriam-webster.com/dictionary/clickbait

Post reply on HN