Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

471–480 of 544 posts

Re: Don't use third party auth to sign in

#471
post #466
post #463

Earlier quoted context omitted.

First promotion point: > Self-sovereign You manage your identities and attributes locally on your computer. No need to trust a third party service with your data. Why do people assume that is a good thing? I do cybersecurity at work (among other things) and it takes a lot of effort to keep things both available and secure. My home PC, not to mention PCs of my friends, are never going to be as secure. A system which h…

I work in crypto and we sell a hardware device to keep your seed phrase secure and the physical device is required to sign transactions. But then you should listen to the advice we're given if we use one for personal use. 1. buy two devices 2. Generate a phrase on one then import to the other 3. Put the second one in a safety deposit box in another city or state, or a safe with a family member also out of the city or…

> [effective and meaningful] Security is hard. We should build systems that make it easy

These are in direct conflict with each other.

Re: Don't use third party auth to sign in

#472

Earlier quoted context omitted.

The speed of technological development is faster than the speed of societal or legal development. So yes, right now we've woken up in a world that is not so much cyberpunk as it is techno-feudalism: more and more do you need a presence on the Internet to do things in meatspace... And that presence is by the grace of several feudal lords (Google foremost) - woe betide you should you ever displease them. You do not rea…

This isn't even a tech problem. It's a lack of regulation to give recourse for individuals and lack of ability for them to be treated fairly by businesses. We need to treat companies that put themselves into a position like utilities as utilities. Give individuals actual transparency of why actions where taken, and an ability to appeal these decisions with transparency. It will cost more, but that is ok. What we have…

I worked at Microsoft for several years about a decade after they lost those famous lawsuits and I can tell you that the company culture around monopoly power and user rights was incredibly well defined. The company was absolutely paranoid about doing anything ever again that would create that set of lawsuits and from what I can tell, in the 8 years since I left MS, that culture is still alive and well. It's probably why MS is the only company I still feel comfortable doing with, among the "tech" companies.

The hard slap they got from the government was enough to apparently permanently change the company culture around treatment of users and other businesses.

I see a lot of the excesses we see coming out of Google, Twitter, FB, to be a consequence of there being, well, zero consequences for their behavior. They're like petulant children who never learned limits and think it's ok to do whatever they want, no matter who they hurt. That's exactly how you teach children -- give them limits. Ironically, the same rule applies to adults.

Re: Don't use third party auth to sign in

#473
post #443

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

It's a step in the right direction, but it's still centralized. A lot of the work done by the Indie Web community around IndieAuth[1] is really attractive. Your identity is your domain, and you can change how your domain says you're allowed to authenticate. Now you can even use sign-in with google without getting locked out should you loose your google account. Aligns really well with using your own domain for email…

I'm a bit divided on whether or not the "centralized" thing is actually a problem Promise should tackle.

On one hand, I want to tell you that Promise is only centralized by default. Which is good for people that doesn't understand what a OpenID/IndieAuth Provider is. But as Promise is open source and the protocol caters for it, it is possible to have Promise redirect authentication requests to your own instance. Which then redirects you back to the relying party you want to sign in to. So it is possible to decentralize if that is what you want

On the other hand, I'm not sure it's a good idea to do it. Centralizing gives a lot of benefits. User experienc being one, but also being able to roll out eg. security updates quickly. But sure, centralization also creates problems.

But until now, I have a feeling that the problems with centralization, can be solved by other measures than going decentralized. Eg. being a non-profit organisation owned by the relying parties. This would guard against a lot of the problems with being centralized.

And I'm still to encounter a decentralized solution with a reasonable user experience for most people. OpenID, IndieAuth, SQRL, re:claimID, I'm looking at you. Sorry.

Re: Don't use third party auth to sign in

#474
post #329

Earlier quoted context omitted.

I've had a recruitment consultant suggest I use a gmail e-mail address on my CV, because it looks weird to have an address at a domain (my own, and not anything strange btw) that people haven't heard of. Sounds crazy. But try dictating an e-mail address over the phone to a hotel or whatever and see that if you say 'Fred Bloggs seventy six at gmail dot com' or whatever, you never have to repeat yourself, whereas anyth…

Counter point, I’ve been told by recruiting that my email makes me stand out because it’s not the norm domain name and it’s a little “fun” in the sense that it conveys a little light personality.

I'm 100% certain that a number of opportunities I've been offered have been because I proved a certain level of competence by maintaining my own email and domain; this certainty is largely due to the incidence of comments like the ones you note. It's definitely a way to stand out.

Re: Don't use third party auth to sign in

#475
post #313
post #290

Earlier quoted context omitted.

Telecom regulators see fit to make sure phone numbers can be ported from one carrier to another. I fail to understand why the same mandate is not required for email addresses and authentication services. They might not look to be as important as a house, but their loss can still have quite a significant impact on someone's livelihood.

The technical mechanisms for maintaining a stable identity already exist. Why aren't people using them?

Yeah, I don't think there's any meaningful way to "port" a "gmail.com" email address away from Google. The entire internet infrastructure is set up so that can't happen, based on the meaning of "domain".

Seems like there's an opportunity there though. If someone could create a platform that would take your address, create you a custom domain, set it up, get your email flowing there (including porting over all your existing email out of gmail), and then helping you move your sign ins to that new address..

That'd be huge. It would also be very, very hard, the amount of infrastructure it would touch.. but doable.

Re: Don't use third party auth to sign in

#476

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

There's been a W3C standard that meets all those requirements for a couple years now: https://www.w3.org/TR/webauthn/ Only problem is there aren't any password managers that implement it, so it's not actually practical to use as a primary authentication factor yet.

WebAuthn is great! I don't see any reason why Promise shouldn't implement it.

I see it this way, that Promise makes it possible for all its relying parties leverage WebAuthn by implementing it once, so they don't have to.

Re: Don't use third party auth to sign in

#477

Earlier quoted context omitted.

Way to speak for another person's intentions AND feelings! That's where we are nowadays, I guess. It's their article, I think it's fair they ask for the name of the post to be preserved. It has nothing to do with their intent (clickbait or not) that the audience here voted up their submission.

> I used Google's name in the title because that name elicits reaction from almost 100% of the audience, And > Changing the title from "Google" to "Third Party Auth" significantly softens the impact and urgency I want the reader to feel upon reading the title, It sounds rather like parent was correct in calling it click bait. For me, any article that has aspirations to manipulating ones emotions in order to illicit a…

But that's not what clickbait is. Clickbait is a title that quickly imposes the feeling of missing and important information. Especially to get people to click through so the link target can serve ads. That's clearly not OPs goal as he makes the title a call to action, omitting no critical information.

Propaganda has nothing to do with the definition of clickbait, so saying "[propaganda ...] Aka click bait." Is very misleading. And betrays your argument that everything should be exclusively logic, specifically omitting any appeal to emotion. That's exactly what you're trying to do by portraying op as using propaganda. And rhetorically speaking would be a disservice to both reader and article.

Re: Don't use third party auth to sign in

#478

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

Legal services can get involved just fine if you file suit. You'll just have to establish that Google owed a duty to you (by contract or otherwise) and that you were harmed by their breach of that duty. (Roughly. I am not a lawyer.)

"It's technically possible for you 30 Spartans to defeat 100,000 Persians so go ahead, good luck" doesn't sound like a winning strategy.

I think the overall point here is to have the support of law that says they DO have a duty to you, by benefit of their hosting your account and authenticating you elsewhere.

Then, WHEN someone goes to sue them, the person has much stronger legs in court rather than lone Peggy Sue trying to defeat Google's 300-strong team of lawyers who exist just to eat little guys for breakfast.

Re: Don't use third party auth to sign in

#479
post #395

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

Cool demo. I couldn’t figure out how to make an account though. I think this would need serious widespread adoption until we saw benefits too. And you’d need some big names...like Google. Which probably will never happen.

Ok, you're not the first to say that...

I hate it, when I type my email and password (correct, that is), and get an error saying "You already have an account. You need to sign in". OK. But would you please just sign me in then. Everything you need is there.

So I chose to make it one. This might be more confusing than anything else... And I might be missing some other point for this to make more sense...

And yes, let's get that widespread adoption

Re: Don't use third party auth to sign in

#480

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

this uses OIDC. it’s a non starter, for reasons unrelated to the part you are “solving” here.

I would love to understand the reasoning here. Sincerely.

What makes OIDC a "non starter"?

I see OIDC as an implementation detail, and have no strong opinions about it.

Post reply on HN