Live data from Hacker News

Sign in with Google in Chrome

underpassapp.com

21–30 of 313 posts

Re: Sign in with Google in Chrome

#21
The Chrome experience is actually part of a new standard, Federated Credential Management (or FedCM for short).

The idea is to create a browser mediated login experience that gives the identity provider and web app what they need without being able to correlate requests across the Internet.

I am working on an article on this topic. If you are interested in learning more, here's a video from a recent auth focused conference (full disclosure: my company put it on and I emceed): https://m.youtube.com/watch?v=FBAD4x7MWdI

They are actively working on the standard and Firefox has committed to it. Edge already supports it. They are looking for identity provider feedback.

More here: https://github.com/w3c-fedid/FedCM (we meet weekly on Tuesdays).

Re: Sign in with Google in Chrome

#22

I think this is referring to the FedCM api [1] It works with providers other than Google, just no one else has implemented it yet. Google's One Tap library tries to use the new api, and falls back to the classic One Tap popup when using a browser that doesn't yet implement FedCM (notice how the chrome built-in one says "sign in with google.com" rather than "sign in with Google" like One Tap normally shows) Mozilla ar…

Yeah, I attend the FedCM meetings. Firefox has one dev working on it who attends regularly. I have found some posts where the safari team has said "seems like a good idea, we'll consider implementing" but have not seen further action.

Edge supports it, and it should be relatively easy for the other Chromium based browsers.

Re: Sign in with Google in Chrome

#23
post #4
post #3

Earlier quoted context omitted.

I'm never confused about what I've used to sign in because I only use randomly generated passwords using my password manager (Bitwarden), and it offers to use them automatically when I go to a website. Another advantage is that Google cannot cut my access to all of my accounts on the internet.

HN userbase is not representative of the large majority of the users of a service. Most of are fully capable of using a password manager, some even self-hosted that we expose via Tailscale, but for a lot of users, they are using a service to get things done and authentication is a necessary hurdle. Sign in with Google/Apple/Github solves that.

Counterpoint: my parents managed to lock each other out of their shared Amazon account after being coerced into "upgrading" their login method. Thankfully they managed to reset it somehow and go back to saved passwords, which Just Work™.

Re: Sign in with Google in Chrome

#24

That Google popups are so annoying, they often cover the content, I wonder does Google pay websites for this or they annoy users for free? Also I don't understand who registers Google Accounts these days because every time I try to do this, they show a QR code and require to scan it with a mobile device, and I don't have time now to set up a virtual machine and research what it does to a mobile device and how one can…

You don't sound like the average user.

They either already have a gmail, or sign up for one my scanning the QR code you mention. I don't recall if a phone number is mandatory, but the average user probably has one, doesn't mind giving it to Google (to not lose access to their account if they forget their password is a perfectly valid reason for most people). And they'll probably not provide one from a sanctioned terrorist state with a reputation of nefarious cyber activities. Like buying Google Accounts, but much worse too.

Re: Sign in with Google in Chrome

#28

“Sign in with Google” is annoying, but at least you can turn it off with chrome://settings/content/federatedIdentityApi Does anyone know how to switch this off on Safari please, especially Mobile Safari. I’ve noticed these sign-in popups on iOS 18.

A generic way to stop this across all devices would be great. I don't suppose something can be done with DNS via Pi-hole?

Re: Sign in with Google in Chrome

#30
post #11
post #5

This popup should be criminal. Ive misclicked the signin button multiple times, causing PII to be sent to a third party I dont trust without my authorization.

[flagged]

> most of them are at least slightly criminal

Huh ? Not wanting reddit to know my government name makes me a suspect ?

Post reply on HN