Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

461–470 of 544 posts

Re: Don't use third party auth to sign in

#461
> Every respectable service allows you to create accounts using your email address, so please use that method to create your accounts.

Although using e-mail sign-up actually provides a number of privacy-related benefits over using the Google account way, it still doesn't solve the main problem - because the e-mail usually is GMail anyway (and when it's not - you can get blocked by Microsoft, Yahoo or anything else too, and you can also loose your own domain).

"Every respectable service" should let and recommend (but not require) you set a secondary e-mail and/or another way to contact you but they usually don't.

Re: Don't use third party auth to sign in

#462

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

There is TLS client authentication, unfortunately it never catched on, probably due to not good and uniform UX in browsers. Imagine if web-browsers have automatically generated password-protected self-signed certificates that could be used to authenticate to web services without need of any third-party.

Re: Don't use third party auth to sign in

#463
post #449
post #443

Earlier quoted context omitted.

It's a step in the right direction, but it's still centralized. A lot of the work done by the Indie Web community around IndieAuth[1] is really attractive. Your identity is your domain, and you can change how your domain says you're allowed to authenticate. Now you can even use sign-in with google without getting locked out should you loose your google account. Aligns really well with using your own domain for email…

There’s also re:claimID¹, which should be fully distributed and work on top of GNS², but it’s still very much a work in progress. 1. https://reclaim.gnunet.org/ 2. https://gnunet.org/en/gns.html

First promotion point:

> Self-sovereign You manage your identities and attributes locally on your computer. No need to trust a third party service with your data.

Why do people assume that is a good thing? I do cybersecurity at work (among other things) and it takes a lot of effort to keep things both available and secure. My home PC, not to mention PCs of my friends, are never going to be as secure.

A system which has a chance will have to be federated, not local-only.

Re: Don't use third party auth to sign in

#465

Earlier quoted context omitted.

Obviously Google knows that you are logged in to Google when you are logged in to Google.

And Google knows that you are not logged in to Google when you are not logged in Google on these web sites.

Of course they do. It uses an IFrame request to the Google.com domain (so that the "host" website doesn't see any details before you login). Google can however see who you are because your auth cookies and what-not will be sent along with that Iframe request on whatever host website decides to use this pattern. See: Medium

A further issue with this is that Google knows you're on that website because the referrer and request headers will have that on the IFrame request.

Edit. I think I replied on the wrong post here.

Re: Don't use third party auth to sign in

#466
post #463
post #449

Earlier quoted context omitted.

There’s also re:claimID¹, which should be fully distributed and work on top of GNS², but it’s still very much a work in progress. 1. https://reclaim.gnunet.org/ 2. https://gnunet.org/en/gns.html

First promotion point: > Self-sovereign You manage your identities and attributes locally on your computer. No need to trust a third party service with your data. Why do people assume that is a good thing? I do cybersecurity at work (among other things) and it takes a lot of effort to keep things both available and secure. My home PC, not to mention PCs of my friends, are never going to be as secure. A system which h…

I work in crypto and we sell a hardware device to keep your seed phrase secure and the physical device is required to sign transactions.

But then you should listen to the advice we're given if we use one for personal use.

1. buy two devices

2. Generate a phrase on one then import to the other

3. Put the second one in a safety deposit box in another city or state, or a safe with a family member also out of the city or state.

4. Keep a copy of the phrase on steel seed phrase tool (Steely, etc)

5. Mount the steel seed phrase backup inside of a wall of your house and plaster and paint over it.

6. If your phrase ever gets seen by any electronic means, it's compromised and the process must be redone (note that importing uses a randomly shuffled alphabet on the device to make MITM or keylogging attacks unusable).

So... Security is hard. We should build systems that make it easy. There should be ways to recover from backups of a service goes offline, but we can't expect everyone to make good decisions.

Not to mention having passwords synced between devices and available on demand is really a requirement of you use random passwords for every site and need to log into something (heaven forbid) on someone else's device.

Re: Don't use third party auth to sign in

#467
post #197
post #116

Earlier quoted context omitted.

You can disable these annoying prompts by going to https://myaccount.google.com/permissions and disabling "Google Account sign-in prompts". Ideally it should have been user opt in but Google followed dark pattern here.

If you have multiple Google accounts logged in, you'll have to do it for each account. Why, Google, why???

I mean, the simple answer is because they're trying to spread the use of Google login, make it ubiquitous, so they can own all authentication mechanisms too as if owning everything else isn't enough.

Re: Don't use third party auth to sign in

#468

Perhaps the courts could be helpful here. A long-established Google account has significant value to the user. If Google terminates such an account, value is destroyed and damages are incurred. You should be able to demonstrate the value of the lost account to a court and demand restitution from the host. If successful, this would impose a cost to Google for shutting down accounts capriciously and incentivize them to…

If successful, google will terminate all free accounts, as will every other free provider (... which will not necessarily be a bad thing)

Honestly it'd be hard for any 3rd party accounts to make that claim except Google, Facebook, Microsoft, and maybe? Twitter and github?

At one point I was signed up in over 300 places using my Google account. Eventually the thought occurred to me, "what happens if I get locked out of this account?" And I don't really mean shutting it down. I lost a Microsoft account with over $3000 worth of purchases and 10 years of history, because I lost access to the recovery email address it used. So since then I've made sure to "spread the risk" so to speak.

Through 2 years of effort it is now only a handful. Some of them remain because either a) there's no other way to sign up or b) there's no way to convert it to an email based account.

But still - that's 2 years. 2 years of weekly, sometimes daily, moving yet another thing off that login (but it still uses the email! that's the next step -- kill the email).

The level of effort has been gargantuan. For some people, it would simply never ever happen. To lose a Google account would not only be damaging, it would be like your entire life being erased.

The level of damage here is enormous and Google has to take responsibility for the power it has amassed.

If they want to terminate all free accounts, it'd be a wonderful thing. Either people would finally be free of the behemoth, or Google's incentives would change to finally care about users (well.... hopefully).

Re: Don't use third party auth to sign in

#469
post #416

You can get also locked out of your phone You can get also locked out of the email that you actually use for signing in because you can never remember the password and they stupidly ask you to change it every 6 months with bizarre constraints You can get locked out of your password manager You can get hijacked The business you're signing into can go under The odds of these things happening are to be weighted against…

> The odds of these things happening are to be weighted against each other

Mmmmm not quite -- they have to be weighed against the consequences if they happen. For people who have had a Gmail account for over a decade (almost 2), they've probably got most of their life connected to it -- losing the account then is tantamount to a huge chunk of your life being erased. Photos. Conversations. Access to dozens or hundreds of other websites.

Basically all that'd be left is your physical ID, your bank account and you get to start over from scratch.

And while all of the above can happen, many things on that list are under your control: losing access to your Google account (usually) isn't.

You're quite correct there are no absolutes but the problem is, when the consequence of something happening is extreme, the level of effort you put in to protect yourself from it must be equally extreme: to the point that it's generally good advice simply not to use 3rd party auth at all.

I no longer do. I use email/password or OTP whenever possible. Sites that insist I use social login are sites I don't sign up with.

Re: Don't use third party auth to sign in

#470

Earlier quoted context omitted.

Reddit website unusable on mobile, it cuts all images in half for me (Nokia 3.1 and Samsung A51), and it's just laggy. I use RedReader from F-Droid instead.

They can't even manage to get their video player to work. Even your local news web sites, which ten years after YouTube still couldn't manage to consistently get a video to play in the browser, have figured it out by now. But Reddit? Nope. Requires me to hit the play button 3-4 times in order to start the video, stops randomly in the middle of the video, and "re-play" never works. I mean, we're almost in 2021! Develo…

My favourite bit is when it starts replaying (with full volume) after I've scrolled halfway down into the comments.
Post reply on HN