Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

241–250 of 544 posts

Re: Don't use third party auth to sign in

#241

This is a strong and succinct argument. I'm disturbed it never really occurred to me, probably because I am in part naive and take certain things for granted, like that I will never have a dispute with Google wherein they disable my account. But of course that is possible even at "no fault" on my part, and of course Google is judge/jury/executioner when it comes to their services. Yikes. One thing I don't understand…

The difference is you can still sign in with email and password. OAuth would fail on a locked account.

Re: Don't use third party auth to sign in

#242

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

The speed of technological development is faster than the speed of societal or legal development. So yes, right now we've woken up in a world that is not so much cyberpunk as it is techno-feudalism: more and more do you need a presence on the Internet to do things in meatspace... And that presence is by the grace of several feudal lords (Google foremost) - woe betide you should you ever displease them. You do not rea…

See also: Kindle books; movies "purchased" from Amazon, Apple, et al; Tesla upgrades you paid extra for; I could go on....

Re: Don't use third party auth to sign in

#243
post #15

Isn't that obvious? Convenience always hat some kind of price tag, particularly a security related one. I would have canceled my facebook account long ago if I had not chosen their login for a (unknown) number of service. What would be a better alternative? Use same credentials everywhere? No, because it is just a matter of time it would leak out of one service. Use unique credentials for each service in local passwo…

Use any password manager

Re: Don't use third party auth to sign in

#244
post #84
post #64

Earlier quoted context omitted.

How could my domain be stolen? :O

Phishing or bribing an employee at a domain registrar. Phishing you to get your password and then bribing or social-engineering someone at the phone company to forward your SMS-based 2FA codes to them. Waiting for you to forget to renew your domain and then registering it.

> Phishing or bribing an employee at a domain registrar.

Okay? I don't think anyone would go to that trouble.

> Phishing you to get your password and then bribing or social-engineering someone at the phone company to forward your SMS-based 2FA codes to them.

Seems unlikely, I never log into my registrar's website. I do often have to enter my Google password though!

> Waiting for you to forget to renew your domain and then registering it.

It's auto-renewing.

Re: Don't use third party auth to sign in

#245
post #64

Earlier quoted context omitted.

How could my domain be stolen? :O

Social engineering attack on your domain registrar, court order, choosing a domain controlled by a dodgy registar. There's actually quite a few ways.

> court order

I don't think that's a "real possibility". It isn't impossible, yes, but very unlikely.

Re: Don't use third party auth to sign in

#246
Sort of seems like everyone is going off. When this article doesnt really give any examples. It just says there are lots of examples.

I have around 8 gmails. Theyre all connected to various things via OAuth2 and I have never once had any of them locked.

Maybe im ignorant to some detail here, but, this sounds like a spammer retaliating because they got caught.

Re: Don't use third party auth to sign in

#248

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

> I'm honestly not sure where we went so wrong as a society so as to reach this point... Why? The answer is actually very simple: spam. AFAIK pretty much all disabled Google accounts come from Google believing they are part of a spam-sending (or malware-spreading) network. The ability to sign up for free Google accounts means this is a prime target for spammers to use and abuse -- signing up for free Gmail/Drive acco…

I think it more common than you believe, and certainly more common than the ones that make the news.

The ones that make the news are people that are either well known, or have and active way to promote their problems through social media or news site

I.e they are reporters, know a reporter, dev of a popular app, etc etc etc

They are Jane/John Doe that has less than 50 twitter followers and a normal every day uninteresting person, for which there is no recourse at all not even social media

Re: Don't use third party auth to sign in

#249

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

> I'm honestly not sure where we went so wrong as a society so as to reach this point... Why? The answer is actually very simple: spam. AFAIK pretty much all disabled Google accounts come from Google believing they are part of a spam-sending (or malware-spreading) network. The ability to sign up for free Google accounts means this is a prime target for spammers to use and abuse -- signing up for free Gmail/Drive acco…

> incorrectly disabled Google accounts are actually incredibly rare -- they make the news and cause uproar when they occur, but precisely because it's so unusual

Or they rarely make the news because they're so common, and the few that get publicised are because the victim raises a big stink on social media.

I've certainly created Twitter and Microsoft accounts and had them wrongly disabled within days, despite not doing anything at all with them, let alone anything abusive. Perhaps because I decline to use my cell phone number for 2FA?

Re: Don't use third party auth to sign in

#250
post #225

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

Because a house is significantly more important than an email address. I get being extremely online but let's not be silly here. Plus that email/account is hardly even "yours" in a serious way. Anyone on the HN has a very simple fix for all these problems: get an email in your domain and a password manager for all the accounts. There, solved. You could even still use Gmail with their Google Apps, G Suite, Workplace o…

Put simply, one's house is literally on their own property, and one's Gmail account is literally on Google's property.

If someone owned a vast amount of land, more than needed for everyone on earth to build a house, and the owner told people they could freely build structures but you lose it if you break the rules and the rules can change any time...

Post reply on HN