Live data from Hacker News

Social Login Buttons Aren’t Worth It

blog.mailchimp.com

91–100 of 114 posts

Re: Social Login Buttons Aren’t Worth It

#91

For me the most important bit in that was the last line. "Is it worth it? Nope, it’s not to us ." (my emphasis) Not all businesses are the same. B2B businesses like MailChimp usually don't see major increases in value through third party auth. They're providing serious value. People will go to the effort regardless. With a casual use B2C site removing even the tiniest piece of friction in the login process can mean t…

"The "login" bit is often not where the biggest win for third-part auth is. It's in reducing friction in registration."

Yes, which makes it particularly annoying when a website advertizes sign-up via social network only to immediately follow this sign-up with its own registration form, making the social network signup stage an additional stage in signing up, rather than a substitute.

Re: Social Login Buttons Aren’t Worth It

#92

There's another element of this that, to this day, I don't fully understand: Companies subverting their brands and actually promoting facebook. What do I mean by this? The other day we were watching TV and a Charmin ad comes in. At the end of the ad they actually say "go to facebook.com/charmin" What? They have a perfectly good and highly recognizable brand. And, they happen to have a great URL: charmin.com. Why send…

"Who is visiting a Facebook page for toilet paper." Well, 300,000 people LIKE it so something is going on. Based on what little I've done in the social realm and what I've heard from SM consultants, these thoughts are in play: - "Every brand has a Facebook page so we need one" - "Our website is just pages and all we can do it update copy" - "On Facebook we can distribute coupons, run contests, and get people to inter…

These are the thoughts of people who don't even understand how the Web works, and get taken for a ride by consultants.

Kinda like all those businesses that were duped by "Web designers" with cheeseball Flash-based animated demos that later became embarrassing, useless sites. You see this all the time on the sites of non-tech-savvy businesses like restaurants.

Re: Social Login Buttons Aren’t Worth It

#93
post #52

There's another element of this that, to this day, I don't fully understand: Companies subverting their brands and actually promoting facebook. What do I mean by this? The other day we were watching TV and a Charmin ad comes in. At the end of the ad they actually say "go to facebook.com/charmin" What? They have a perfectly good and highly recognizable brand. And, they happen to have a great URL: charmin.com. Why send…

People are spending a lot of money on Facebook promo these days. I have a lot of people that tell me the number of likes on their business pages boosts their credibility etc.

Wishful thinking and a lack of common sense. Ask them if they check out the number of "likes" a business has before deciding whether to transact business with them. It's a meaningless number. In most cases, you'll have no idea what the total size of the business's market is, or whether its customers tend to be heavy Facebook users. GM might have millions of likes and still suck, whereas a machine shop might have 1000 likes and be the best business of its kind in its entire region.

When you look at ridiculous and desperate flailing like QR codes and businesses begging for "likes", you realize that we haven't learned anything.

Re: Social Login Buttons Aren’t Worth It

#94
post #85
post #83

Earlier quoted context omitted.

1. True, but irrelevant. 2. It is very easy. SQL injection etc. isn't something you magically get rid of because you use a facebook login... The reason so many get this wrong is because they don't even try. And if you don't even try you won't get any other aspect of security right and outsourcing your logins isn't going to solve any of that. If you have to outsource this to facebook, the moment you get big you will,…

1. What's irrelevant about having robust and constantly-evolving phishing detection, and optimized flows for getting people back into their accounts? Both of these are important in a high-quality login system IMO. 2. You're right that a lot of folks fail to even try for security, but I disagree that outsourcing password management to facebook won't help them. If they get popped and have no passwords, all that leaks i…

Facebook has big target problems and fortunately has big target defence resources. That doesn't make it right for everybody.

1. If you are small people won't be using your brand as the bait in anything other than spear-phishing when your phishing detection won't work. Emails and password resets are pretty easy. If you need it twilio makes SMS resets pretty easy too but in most cases that is probably overkill.

2. There probably is some benefit here.

3. There are fairly simple and clear best practices that are reasonable for most sites. Most people aren't under targeted attack although they should put a reasonable amount of effort into a reasonable defensive system.

Facebook integration (or other 3rd party login) also brings additional risks as they become a potential attack vector. This may seem unlikely unless you consider the possibility of staff, contractors or app developers finding a way in.

Re: Social Login Buttons Aren’t Worth It

#96

Earlier quoted context omitted.

No no no. What the hell is anyone going to do on charmin.com??? Download a guide on how to wipe your ass? How often will you go there? Once? Never? Exactly. Facebook on the other hand... It's fresh and new. When people go there, they like it and then they're essentially subscribed. As many others have said, they have 300k likes. That means whenever they push something it shows up front and center on the first thing p…

What is Charmin going to put in their Facebook feed that has recurring value? New research on the best way to wipe your ass? I'll continue to get that from charmin.com, rather than risk a charmin app that posts to my wall that tells people I just learned how to wipe my ass.

The same thing they put on TV when my wife is watching the Big Bang Theory.

Re: Social Login Buttons Aren’t Worth It

#97
post #84
post #80

Earlier quoted context omitted.

Most websites that are adding social login buttons also keep their own registration/authentication setup. I think by adding social login buttons you also increase attack surface on your website, no matter how good third party security is.

My point is that you shouldn't bother spending any time rolling your own registration / authentication step. Do you think that using 3rd party auth in lieu of your own auth decreases security?

Right, instead we should cut our potential userbase in half to promote facebook. That's very realistic.

Re: Social Login Buttons Aren’t Worth It

#98

Earlier quoted context omitted.

Yes, both of these UI features would reveal the fact that this username or email already exists. But isn't it impossible not to reveal it on the signup page anyway? You want users to have unique usernames (or emails acting as usernames), therefore the signup form has to tell them if it has been already taken. My suggestion would be to tell users if the username or email is unknown right away - and perhaps add a captc…

You can use the same strategy there too: in the signup page, it can just say "a confirmation email has been sent to your email". In the event that the email is already known, the email will say "someone else has tried to sign up with your email -- if this was you click here to change your password". This way, the attacker will never know if the email genuinely resulted in a new account or not.

And you have absolutely terrible usability and tons of people fail to go through the signup process. So you gained imaginary security that doesn't actually do anything, and lost users. For most sites, that isn't a good tradeoff. I don't care if everyone knows I have a mailchimp account. How is it a security concern that people can find that out? If you are running some kind of freaky porn site it matters, but for 90% of sites it doesn't.

Re: Social Login Buttons Aren’t Worth It

#99

> But after some further consideration, we decided that it was a false risk, as the username reminder form already tells you if a username exists [...] Alright so this security hole already existed in their system elsewhere. After raising the issue that this type of message leaks data, which is a completely valid concern, they dropped it because they were already leaking that data elsewhere? It isn't like email based…

In what way does people being able to find out you have a mailchimp account cause a problem for you? Are you concerned someone is going to threaten to go public with this shocking information if you don't pay them off?

Re: Social Login Buttons Aren’t Worth It

#100

Earlier quoted context omitted.

No no no. What the hell is anyone going to do on charmin.com??? Download a guide on how to wipe your ass? How often will you go there? Once? Never? Exactly. Facebook on the other hand... It's fresh and new. When people go there, they like it and then they're essentially subscribed. As many others have said, they have 300k likes. That means whenever they push something it shows up front and center on the first thing p…

What is Charmin going to put in their Facebook feed that has recurring value? New research on the best way to wipe your ass? I'll continue to get that from charmin.com, rather than risk a charmin app that posts to my wall that tells people I just learned how to wipe my ass.

    thwarted just learned how to wipe his ass.
    -- via Charmin (like | share)
Brilliant. I laughed aloud. :)
Post reply on HN