Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

181–190 of 544 posts

Re: Don't use third party auth to sign in

#181
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

If you are doing all that, why use Google at all? Just to get the broken GSuite variant of Google?

Re: Don't use third party auth to sign in

#182

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

> Yet here it is. Google can offer their services and the legal system seemingly doesn't want to be involved. Why ?

The real question is why do people use Google to sign in to other services? It never even crossed my mind no matter how long I have had a Google account.

Re: Don't use third party auth to sign in

#183
post #165

Earlier quoted context omitted.

Do you not see this as a problem? With the amount of services Google offer, losing them can be devastating; photos, emails, Android backups, contacts and so so much more. This pandemic has been reliant on emails to access services; it's how I get my payslips, talk to my employer, get current information, engage with legal services, and essentially maintain my access to society. Losing my emails would be devastating (…

I do not. Becoming dependent on a large e-mail provider is only because of continued willful ignorance. Better education for how digital services work and how to properly handle your digital identity is the right way to handle this. Implementing regulation and cementing the "major" e-mail providers who have the resources to comply will only deepen people's dependence on these corporations.

Consider that our lives are increasingly complicated. What an adult is expected to know and understand has grown to the point that 16 years of formal education are required.

As email's importance approaches a utility like physical postal service it's reasonable to expect some regulation. So long as the regulation is independently developed and balances the needs of consumers and producers then it shouldn't be too burdensome for competition to exist.

In the worst case taxes could pay out to whichever provider one chooses.

Re: Don't use third party auth to sign in

#184
post #51

Earlier quoted context omitted.

This is such excellent advice that I wrote a detailed step-by-step instruction guide for people that don't know how to do precisely that: https://sneak.berlin/20201029/stop-emailing-like-a-rube/ It even has special instructions about how to secure the domain registration and DNS accounts. :) (Don't use G Suite, though.)

I have attempted to read two articles on your site. As I am a privacy-focused person the articles were of interest to me. Both times I haven't gotten past reading the opening sentences when an obnoxious pop-up appeared asking for my email address. It seems ironic that someone publishing articles on privacy advocacy would be so keen to collect my email address. This practice also creates a real miserable experience an…

An email address is public information not private. You can have as many as you like for different purposes.

Re: Don't use third party auth to sign in

#185

Remember OpenID? Yes, that's what it was for, OAuth wasn't never meant for signing in other websites who just want your mail or something... Of course, all these big tech corps quickly dropped OpenID, they don't want people to control their online credentials or identity...

Sadly everyone wanted to be an OpenID provider, very few wanted to be a consumer of OpenID. Neither Google, Facebook nor any of the other major Internet sites where ever going to allow you to authenticate using a 3rd party.

OAuth is exactly the same. You can't log in to Facebook using your Google account.

Re: Don't use third party auth to sign in

#186

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

US national politics. One party is in bed with the copyright owners, the other doesn’t believe that the government should govern. Google fills the gap.

> One party is in bed with the copyright owners, the other doesn’t believe that the government should govern

This political model is dated. Republicans are no longer conservative. And Democrats have an ascendant progressive wing that rejects corporate influence wholesale.

Re: Don't use third party auth to sign in

#187
post #11

The truth is you should not use Google login to Google services either. You get the service promise you pay for, none. If their secret algorithms decide that you are in breach of whatever ToS, they will lock you out. Not very likely for the average user. But more likely for HN reader who might experiment with programmatic access to the services or do other atypical stuff. Yes, I need to move away from gmail...

You can pay for a Google account.

Re: Don't use third party auth to sign in

#188

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

So what do you propose, make it impossible for Google to ban accounts?

Re: Don't use third party auth to sign in

#189

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

> Yet here it is. Google can offer their services and the legal system seemingly doesn't want to be involved. Why ? The real question is why do people use Google to sign in to other services? It never even crossed my mind no matter how long I have had a Google account.

For similar reasons that you and I use password managers, but add lower friction to the mix.

Re: Don't use third party auth to sign in

#190

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

> Yet here it is. Google can offer their services and the legal system seemingly doesn't want to be involved. Why ? The real question is why do people use Google to sign in to other services? It never even crossed my mind no matter how long I have had a Google account.

I don't want more accounts and passwords. The security seems strictly worse than just authenticating against my email provider directly.
Post reply on HN