Live data from Hacker News

Social Login Buttons Aren't Worth It (2012)

blog.mailchimp.com

61–70 of 76 posts

Re: Social Login Buttons Aren't Worth It (2012)

#61

Earlier quoted context omitted.

the reason for it is specifically addressed in the article... "But after some further consideration, we decided that it was a false risk, as the username reminder form already tells you if a username exists"

For usernames it might be true but many sites use emails instead of usernames (and rightfully so, it's already complicated for people to remember passwords without forcing them to also remember an unique username). Emails are more personal and might be easier to link back to personal information. Thus, confirming that there is an associated account with a given email is also a privacy leak, because maybe people don't…

email addressess are frequently public information anyway, and often get leaked through other methods like giant CC list emails. Unless you have a specific reason to conceal email addresses, I'd argue that the cost of keeping that tiny nugget of information secret is too high for the level of security it adds.

And as they say in the article, that information is already leaked by the password reset process: "No email by that name available".

Re: Social Login Buttons Aren't Worth It (2012)

#62
post #59

Earlier quoted context omitted.

Good point. My thoughts: - Email is not the only option to deliver tokens. You could also go for SMS, or both - For most registrations such emails are anyway commonplace. Combined with long sessions (where possible), I think the risks of delayed emails are low (compared to guys getting frustrated with the password) - I'm so far happy with Mandrill. But as you say: random b.s. can happen

Random b.s. happens with SMS messages too. I've waited minutes for tokens from my bank's login system on more than one occasion. Also it's not always the case that a user has access to email when he's trying to log in to your app.

Yes, stuff happens. But as said: Most services use long-lived sessions. It's a choice: Trouble people with either insecure passwords and password resets, or take the risk that sometimes when a session was closed people might in rare cases not receive their tokens. Looking at my daily browsing I would be more than happy to get rid of most of the passwords.

Re: Social Login Buttons Aren't Worth It (2012)

#64
post #35

On why telling users if it is the username or password that is incorrect they say... But after some further consideration, we decided that it was a false risk, as the username reminder form already tells you if a username exists, and is not a significant security risk for the bajilions of sites that have them. Oh, damn i didn't realize bajilions of sites do this and yet are so secure. Next time, a better response i h…

Well, if they show a captcha after 5 missed attempts your brute force scripts won't go far.

Re: Social Login Buttons Aren't Worth It (2012)

#65
post #61

Earlier quoted context omitted.

For usernames it might be true but many sites use emails instead of usernames (and rightfully so, it's already complicated for people to remember passwords without forcing them to also remember an unique username). Emails are more personal and might be easier to link back to personal information. Thus, confirming that there is an associated account with a given email is also a privacy leak, because maybe people don't…

email addressess are frequently public information anyway, and often get leaked through other methods like giant CC list emails. Unless you have a specific reason to conceal email addresses, I'd argue that the cost of keeping that tiny nugget of information secret is too high for the level of security it adds. And as they say in the article, that information is already leaked by the password reset process: "No email…

Would the argument then be to change the password reset process to something like, "After we verify that this address exists in our records, a password reset email will be sent to it."

Re: Social Login Buttons Aren't Worth It (2012)

#66
Wrong conclusion. There's a difference between bad idea and bad execution.

MailChimp is a business site. Twitter and Facebook are personal mediums. There's a mismatch. As a manager, I wouldn't want my employees using personal mediums for business (I have no control), and conversely, as an employee, I don't want to be logged into Facebook from work, or share my Facebook information with businesses. I would never log in to MailChimp with either of those.

On the other hand, we use Google Apps for Business. I use that as a common login for everything that supports it. Most businesses use Google for business in some form (if nothing else, Google Docs or Youtube or similar), so even if not Google Apps, there's already some integration.

Single sign-on is much more secure than either managing 100 different passwords, or having 100 different businesses managing my password. It's much more convenient. It's just a clear win.

Re: Social Login Buttons Aren't Worth It (2012)

#67
post #49

Earlier quoted context omitted.

But don't you leak the same information during registration? What happens when a user tries to sign up with an already existing email address? Don't you return an error saying that email has already been used?

This actually argues in favor of only using social logins, which would not leak any clues about other users of the site.

Oh, I wasn't arguing either way. Personally I prefer social login, but I have no strong conviction either way.

Re: Social Login Buttons Aren't Worth It (2012)

#68
post #58
post #56

Earlier quoted context omitted.

Google logins are the absolute worst, now you have to remember which of your accounts you logged in with (like many others here I have 5 active accounts - I really wish they could give me a single identity that would work with all of them).

If you want a single identity why do you have five active accounts? I have multiple google accounts because I want separate google identities.

I have separate google identities because I have a gmail account and my work uses Google Apps; I also have another account that I use for YouTube which I refuse to merge into my gmail account (if that's even possible).

I don't want to merge them together because they're separate accounts for separate purposes, but that's a difficult position to keep because of how absurdly difficult it can be to deal with multiple google accounts. Even though Google supports multiple accounts, their base assumption is that people have exactly one Google account which is exactly one identity which incorporates all of one person.

I've been unable to accept calendar invites sent to my work account because Google Calendar insisted on opening to my personal account when I clicked the link; even if I opened my work calendar using the drop-down, and closed the other window, the link would only open to my personal calendar and then tell me 'you don't have access to this calendar'.

It feels as though the parent poster was asking for Google to understand that one person can have multiple accounts, rather than assuming a 1:1 mapping between the two and behaving as such.

Re: Social Login Buttons Aren't Worth It (2012)

#69
post #33

As a user I strongly agree that I want to know which of my username or password is wrong. While you're at it, please remind me which characters your website allows, and how many are expected. User/pass guessing by crackers can be solved with passphrases. Don't let registrants get by with a crackable password. Then remind us at the login screen that your site wants a passphrase (you can even flash me something that re…

This comes dangerously close to this one: https://www.portcullis-security.com/security-research-and-do... Very user-friendly, but not exactly secure. Each bit of information you volunteer to unauthorized user reduces the work the attacker has to do to gain access. As for "how many expected" - limiting the password length is not exactly a good idea in any case.

I just mean if you do limit the password length or character type, please remind me at the login screen, because there's no way I will remember across sites who wanted 6-8 characters from [aA9$_!#] and who wanted 12-16 from [a9-].

Re: Social Login Buttons Aren't Worth It (2012)

#70
post #58
post #56

Earlier quoted context omitted.

Google logins are the absolute worst, now you have to remember which of your accounts you logged in with (like many others here I have 5 active accounts - I really wish they could give me a single identity that would work with all of them).

If you want a single identity why do you have five active accounts? I have multiple google accounts because I want separate google identities.

I have one gmail account and 4 different google apps accounts (one so I can have a personalised email that I've had for 15 years, the other 3 are different companies that I'm involved with). I use trello with 3 of those accounts but i only want one login, hence the confusion...
Post reply on HN