Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

441–450 of 544 posts

Re: Don't use third party auth to sign in

#441
post #382

Earlier quoted context omitted.

I.e. you want this article to be clickbait and now you are unhappy that it is not.

No, clickbait would be: This guy used Google to login, you'll never guess what happens next!! He wants to us the name Google to personalize the message assuming that's what a lot of people use. Do you know how I figured that out? That's what OP said was his goal. It's rude to assert otherwise without evidence.

“I opted out of a Yubi key, forgot my Yahoo password, didn’t have the authenticator set up, couldn’t text message myself, and wasted 3 days fixing it” could maybe fit as a title too.

Re: Don't use third party auth to sign in

#442

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

I was my own OpenID Provider for a while, but quit because nobody supports it anymore. It was great for power users but super confusing for laypeople.

Re: Don't use third party auth to sign in

#443

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

It's a step in the right direction, but it's still centralized. A lot of the work done by the Indie Web community around IndieAuth[1] is really attractive. Your identity is your domain, and you can change how your domain says you're allowed to authenticate. Now you can even use sign-in with google without getting locked out should you loose your google account.

Aligns really well with using your own domain for email instead of gmail.

[1] https://indieauth.net/

Re: Don't use third party auth to sign in

#444
I had a similar problem. I used Google to sign in on digitalocean, then I changed the main domain in google apps and readded the original domain seperately on Google Apps. But probably because some kind of ID mismatch, I was now unable to sign-in on Digitalocean with the original e-mail address recreated in Google Apps. Password recovery didn't work either, for some reason digitalocean doesn't do password reset for accounts that were created using Google sign-in. I was forced to create a support ticket with digitalocean and wait.

Re: Don't use third party auth to sign in

#445

This is not an easy issue. It boils down to responsive customer service at the end. Even if you host your email, your hosting provider can suspend your account if, let's say, your credit card rebilling fails. There should be a better and more resilient way to identify people online in 2020!

Hosting is still better than registering with Google/FB for several reasons:

1. Registering with email is not usually an SSO. Authentication is using password and email is used only for recovery. Your won't get locked out of other services even if email server fails for some reason.

2. Hosting providers usually engage customers much better than ad and social media companies. Chances of getting your service back up with customer support assistance is much better.

3. In case the hosting provider locks you out without recourse, you can always move to another provider and point your DNS records there. For this, it's better to have a different company as registrar and hosting provider.

4. DNS so far is the least affected/abused online resource. The chances of you getting locked out of your domain name is low, unless you fail to renew. They give sufficient warning as well. Let's take advantage of that until companies decide to wreck that.

> There should be a better and more resilient way to identify people online in 2020!

I don't think that's an accident. The choices and freedoms available for authentication seems to be diminishing with time. It was possible to specify the authentication provider a decade ago.

Re: Don't use third party auth to sign in

#446

_A plea to the moderators:_ Please change the title of the submission back to match the title of the blog post, "Never Use Google to Sign-In". To be fair to Google I have clearly called out all third-parties in the blog post, some by name. I used Google's name in the title because that name elicits reaction from almost 100% of the audience, since almost everyone has used Google services at some point. I myself am a h…

Oh wow, now the title has been changed again! Here are the different versions the title went through:

  Never Use Google to Sign-In
  Never Use Third Party Auth to Sign In
  Don't use third party auth to sign in
I guess a another moderator had a better idea at what title will attract more attention.

Given the number of comments, the duration at the top of HN, it's clear that this post (including the title) hit a nerve with many people. But the moderators in their wisdom chose to reduce its reach by watering down the title; twice! Compare the 3 versions of the title so far, which one do you think resonates with most people? If they had chosen to add other prominent offenders' names (Facebook, Github, etc.) I wouldn't have minded a bit; that would have been a better use of the space the title takes up.

But they chose to first generalize it from "Google" to "Third Party Auth" (casual reader: eh, what's a third party auth; who are these people? what's auth? is it authentication, or is it authorization; I guess that's too generic post so I don't care, ), and then replaced "Never" with "Don't" and lower-cased the rest of it. I don't expect the general population of HN to take my, or anyone else's, advice at face value, but think about the problem in their own context, how much it affects them, how much they care about the problem, and if they agree with the proposed solution, and to what extent.

I'm sure that by watering down the title's efficacy, the moderators have lost opportunity to educate many of the HN readers.

People write content to share their ideas, and they want people to pay attention, because the writer thinks it's important. If the moderators' changes help in that goal, no writer would mind. But in this case I am sure these changes have hurt the chances of spreading the core concern.

I find it offensive that my judgement in choosing the title is being questioned, even though most of others agree that the original title was appropriate, in general. Thankfully, I went with my gut to write the article on my own Blog (and link it here) even though it was 3 short paragraphs, rather than post the original content here. The original title and content will stand there, without fear of someone else's ability to alter it.

Someone else's platform, their rules, their whims; no recourse, as with other platforms.

To self: Shut-up and get on with you life, you have already wasted inordinate amount of time on this.

Re: Don't use third party auth to sign in

#447
post #304
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

As long as you don't want to use any Nest products, which now insist that you have a gmail.com address as apparently hosted domains are for business only.

yep, noticed that too. i'm getting nagged to use my gmail login. what a virus.

i will add that it's possible to create a google account WITHOUT gmail,

https://support.google.com/accounts/answer/27441?hl=en

maybe that's sufficient for nest.

Re: Don't use third party auth to sign in

#448
post #361

Even when some service allow registering using good 'ol email, some still refuses to accept any non gmail/outlook address. Met a service that wouldn't allow me to register using my own domain email address a week ago. Baffled me staring at the google, fb and twitter sso button with the form for email address giving error of "please use an email address from a reputable provider".

I have faced that at least on four occasions. Some were even for paid accounts. Who expects someone to pay to create a spam account?

Re: Don't use third party auth to sign in

#449
post #443

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

It's a step in the right direction, but it's still centralized. A lot of the work done by the Indie Web community around IndieAuth[1] is really attractive. Your identity is your domain, and you can change how your domain says you're allowed to authenticate. Now you can even use sign-in with google without getting locked out should you loose your google account. Aligns really well with using your own domain for email…

There’s also re:claimID¹, which should be fully distributed and work on top of GNS², but it’s still very much a work in progress.

1. https://reclaim.gnunet.org/ 2. https://gnunet.org/en/gns.html

Re: Don't use third party auth to sign in

#450

_A plea to the moderators:_ Please change the title of the submission back to match the title of the blog post, "Never Use Google to Sign-In". To be fair to Google I have clearly called out all third-parties in the blog post, some by name. I used Google's name in the title because that name elicits reaction from almost 100% of the audience, since almost everyone has used Google services at some point. I myself am a h…

Oh wow, now the title has been changed again! Here are the different versions the title went through: Never Use Google to Sign-In Never Use Third Party Auth to Sign In Don't use third party auth to sign in I guess a another moderator had a better idea at what title will attract more attention. Given the number of comments, the duration at the top of HN, it's clear that this post (including the title) hit a nerve with…

[deleted]
Post reply on HN