Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

451–460 of 544 posts

Re: Don't use third party auth to sign in

#452
post #329
post #307

Earlier quoted context omitted.

Land is a weak analogy here, because land is scarce.

I've had a recruitment consultant suggest I use a gmail e-mail address on my CV, because it looks weird to have an address at a domain (my own, and not anything strange btw) that people haven't heard of. Sounds crazy. But try dictating an e-mail address over the phone to a hotel or whatever and see that if you say 'Fred Bloggs seventy six at gmail dot com' or whatever, you never have to repeat yourself, whereas anyth…

Counter point, I’ve been told by recruiting that my email makes me stand out because it’s not the norm domain name and it’s a little “fun” in the sense that it conveys a little light personality.

Re: Don't use third party auth to sign in

#453
post #72

Earlier quoted context omitted.

Are you actually the owner of steve.com? Because I've been ordering Dominos pizza with the email steve@steve.com for years. Edit: nevermind. I see you own the .net tld. I've definitely used that to order pizza too. Sorry about that.

Couldn't you use @example.com?

I prefer webmaster@whatever site i'm on

A fair number of places will deny that, but I like to think it sends a message. I'm not sure how many, if any, domains still have a working webmaster@ address though.

Re: Don't use third party auth to sign in

#454

I had a similar problem. I used Google to sign in on digitalocean, then I changed the main domain in google apps and readded the original domain seperately on Google Apps. But probably because some kind of ID mismatch, I was now unable to sign-in on Digitalocean with the original e-mail address recreated in Google Apps. Password recovery didn't work either, for some reason digitalocean doesn't do password reset for a…

And after that?

They probably put a human to communicate with you, verify some identity and then give you access to your servers again, I'm sure?

Compare that with Google (and Facebook, those are the two I have experience with) who will simply lock you out of your account and if you ask for help, they say they cannot. "But what about the three years of photos I've stored?" I asked. "They have now been deleted since your account was terminated" they told me. "Why?" "We cannot tell you".

Re: Don't use third party auth to sign in

#455

Earlier quoted context omitted.

You can do this without paying as well. If your DNS provider supports email forwarding you can use that (if it doesnt you can use improvmx free tier) and use gmail's inbuilt smtp server to send emails using your own domain.

Only issue with not using GSuite is that you won’t be able to DKIM sign those emails, although just SPF might be sufficient.

Why not just use Fastmail?

Re: Don't use third party auth to sign in

#456
post #443

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

It's a step in the right direction, but it's still centralized. A lot of the work done by the Indie Web community around IndieAuth[1] is really attractive. Your identity is your domain, and you can change how your domain says you're allowed to authenticate. Now you can even use sign-in with google without getting locked out should you loose your google account. Aligns really well with using your own domain for email…

I hadn't heard of either Promise or IndieAuth before reading this thread, so apologies if this is a dumb question. But one of the benefits of Promise is that it's pseudonymous:

> You will get a unique identity pr. service you use. This ensures that relying parties have no way to profile you across services.

For me, this is actually the biggest reason that I stopped using social sign-ins. It's not that Google might disable my account one day; it's more that I don't want Google or Facebook tracking me.

How does a decentralized system handle this? If my identity is my domain, doesn't that mean that all these websites now have a unique id which they can use to join together all their separate pieces of data about me?

Re: Don't use third party auth to sign in

#457
post #304

Earlier quoted context omitted.

As long as you don't want to use any Nest products, which now insist that you have a gmail.com address as apparently hosted domains are for business only.

yep, noticed that too. i'm getting nagged to use my gmail login. what a virus. i will add that it's possible to create a google account WITHOUT gmail, https://support.google.com/accounts/answer/27441?hl=en maybe that's sufficient for nest.

Hmm, thanks, I'll have a look into that. The objection to nest using "Google for Domains" or whatever they changed it to these days seems to be to do with the domain admin having access to everything. Which would be just fine for me, as I'm the only one that uses the domain.

Hopefully signing my address up that way, when it's already a domain account, won't b0rk all sorts of other things :/

Re: Don't use third party auth to sign in

#458
post #51
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

This is such excellent advice that I wrote a detailed step-by-step instruction guide for people that don't know how to do precisely that: https://sneak.berlin/20201029/stop-emailing-like-a-rube/ It even has special instructions about how to secure the domain registration and DNS accounts. :) (Don't use G Suite, though.)

Nice. I'd highlight that conceptually, there are two entirely separate concerns here:

1) the front, if you so will - the emails which you give out and to which people (or algos) send you stuff

2) the back, where you receive and read your emails.

For many people, for example:

1) abc@gmail.com

2) gmail.com web mailer, or gmail app on mobile, or native OS app on the computer

You suggest a complete revamp:

1) catchall at own domain: anything@mydomain.com

2) one (or several) protonmail/fastmail accounts

But it's worth highlighting that people can get many benefits already by

1) catchall at own domain: anything@mydomain.com (as you explained)

2) keep whatever you're using now.

Just forward 1) to 2). Then you can start handing out the new email.

Re: Don't use third party auth to sign in

#459
post #51
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

This is such excellent advice that I wrote a detailed step-by-step instruction guide for people that don't know how to do precisely that: https://sneak.berlin/20201029/stop-emailing-like-a-rube/ It even has special instructions about how to secure the domain registration and DNS accounts. :) (Don't use G Suite, though.)

I'm definitely not a power user, but I see and understand the issues.

But for someone like me, if I take all this advice, there is still the aspect of trusting the domain registrar, maintaining a personal email server, hosting, CloudFlare, etc. etc. I have just shifted some risk of offending Google to some other risks of 3x more companies that I have to remember how to deal with now.

So what difference does it mean to me, average user, that I just stick with Google and don't misbehave, versus open myself up to having to deal with 3 other manual processes and companies to remember? It's turtles all the way down.

You see the dilemma for the average user.

Post reply on HN