Live data from Hacker News

Sign in with Google in Chrome

underpassapp.com

251–260 of 313 posts

Re: Sign in with Google in Chrome

#251

Earlier quoted context omitted.

> or Firefox Or just use Firefox because even using chromium is empowering Google to keep playing these games. Maybe you have a problem with Firefox (most people won't notice the difference) but is that problem worse that the problem you have with Google?

> Or just use Firefox because even using chromium is empowering Google to keep playing these games. This. People like to complain about problems, but I wonder why they don't invest half that energy in actually fixing the problems. > Maybe you have a problem with Firefox (...) I've started to notice there is a very vocal opposition of Firefox whose common trait is that they actually do not or cannot present any tangib…

I have plenty of arguments against Firefox, but engaging in browser holy wars is so tiresome. I used Firefox since before it was called Firefox up until v89 (I think) when I finally had enough. That's when they for the millionth time messed up the UI in new fanciful ways, and removed more features I relied upon daily. It's a pattern going back decades, and the usual tired old argument is, just install this addon to restore the functionality, or add/remove this to userchrome.css, or install whatever from some random Github link. The problem is I first have to spend time and energy finding these things, and then the authors have to keep supporting them in perpetuity. And often it's tiny stupid things like removing "show image" from the context menu, I now have to install an addon for, but it's a feature I use all the time, but their precious telemetry says only 10% (or whatever) of people use it, so it gets axed in the name of minimalism. Inevitably those 10% of users will whine about it on Bugzilla, and inevitably it will be WONTFIXed and comments disabled. I've seen this scenario play out SO MANY TIMES.

I like the idea of Firefox. Not the execution.

After ditching Firefox, I installed Vivaldi, and while it certainly isn't flawless, I can set up every aspect of it how I want, and in the four or so years I've used it - with a few minor exceptions I could revert with in-browser settings - it looks and works exactly how I set it up in 2021.

So in summary, for me it was very much a paper-cuts thing, rather than any single major Mozilla catastrophe.

Re: Sign in with Google in Chrome

#252

As others mentioned, this is backed by the "open" standard FedCM. While this seems like an open play on the surface (and the standard is open), in practice this is a highly anti-competitive and will just lead to Google being in even more control of the web. The vast majority of users will chose the default for identity. On Chrome this is Google. On Android this is Google. Even on iOS this may be Google because identi…

This "standard" also seems interestingly timed with respect to Passkey adoption, too. If one were feeling pessimistic enough, it almost seems too easy to suggest some interests exist here that want to muddy the sign-in waters to capture users considering switching to Passkeys before they actually switch to Passkeys.

These are orthogonal concerns. Passkeys don't meaningfully simplify the account creation process.

Re: Sign in with Google in Chrome

#253
post #21

The Chrome experience is actually part of a new standard, Federated Credential Management (or FedCM for short). The idea is to create a browser mediated login experience that gives the identity provider and web app what they need without being able to correlate requests across the Internet. I am working on an article on this topic. If you are interested in learning more, here's a video from a recent auth focused conf…

> They are actively working on the standard and Firefox has committed to it. Mozilla standards position says neutral: https://mozilla.github.io/standards-positions/#fedcm Their issue tracker on the subject shows they are interested but have a lot of reservations about the details: > However, some of our reservations on the initial positive position have not been addressed and some new issues have arisen. — https://gi…

I don't speak for Mozilla, but I did see a bug in bugzilla which showed the blocking bugs for FedCM. I don't have the link now, but can share it later. That's what I thought of when I stated Firefox has committed to it. But I could be wrong.

I do see a Mozilla employee engaging regularly. You can see some of the issues he has filed here: https://github.com/w3c-fedid/FedCM/issues?q=is%3Aissue%20sta...

Re: Sign in with Google in Chrome

#254
post #125
post #21

The Chrome experience is actually part of a new standard, Federated Credential Management (or FedCM for short). The idea is to create a browser mediated login experience that gives the identity provider and web app what they need without being able to correlate requests across the Internet. I am working on an article on this topic. If you are interested in learning more, here's a video from a recent auth focused conf…

If it's a new standard, it must have… some kind of cross-industry support right? I ask because it looks like https://github.com/w3c-fedid/FedCM/graphs/contributors is mostly people who work at Google (I gave up once I hit people with ten or fewer commits)…

While most of the contributions I have seen are from Google on the browser side, they are trying to work through the standards process. Here's the first draft of the w3c standard: https://www.w3.org/TR/fedcm/

I know there's a later draft but can't find it right now. Will share when I do.

As mentioned in sibling comments I have seen are least on Firefox contributor and they are actively seeking input from identity providers.

Re: Sign in with Google in Chrome

#255
post #21

The Chrome experience is actually part of a new standard, Federated Credential Management (or FedCM for short). The idea is to create a browser mediated login experience that gives the identity provider and web app what they need without being able to correlate requests across the Internet. I am working on an article on this topic. If you are interested in learning more, here's a video from a recent auth focused conf…

I'm curious - how does the standard make "to continue, google.com will share your name, e-mail address and profile picture" compatible with "a modern, privacy-preserving standard for federated identity on the web" ?? I mean, that doesn't sound privacy-preserving at all?

I don't think they are trying to preserve privacy between you and the identity provider you are logging in with and the website you are logging into. (At least not now. There's talk about some of this with IDP delegation, I think. Here's more on that: https://github.com/w3c-fedid/delegation )

The first goal is to prevent data brokers from correlating data about users across the Internet using cookies and redirects. You can read more about the privacy focus here:

https://www.w3.org/TR/fedcm/#privacy

Re: Sign in with Google in Chrome

#256

Earlier quoted context omitted.

Anti fingerprinting is nice but if you get served ads based on your IP address you're going to need more than just a browser to escape tracking based advertising. Adblockers aren't good enough when websites you visit use first-party servers to forward data back to ad networks.

Serving ads based on IP seems foolish when very, very few people have a static IP. I'm sure that a healthy minority of folks on HN do, but we're hardly representative of the general population.

Your IP is a lot more static than you give it credit for. It's not like the dialup era where you get a new IP each time. For example I have a dynamic IP on my cable modem, but it might as well be static as it only changes after there is a long term power outage. Also, it's likely if you're on a home connection most often, then you only have a limited pool of 32k or so IPs, which dramatically lowers the bits of information needed to identify you.

Re: Sign in with Google in Chrome

#257

Earlier quoted context omitted.

This "standard" also seems interestingly timed with respect to Passkey adoption, too. If one were feeling pessimistic enough, it almost seems too easy to suggest some interests exist here that want to muddy the sign-in waters to capture users considering switching to Passkeys before they actually switch to Passkeys.

These are orthogonal concerns. Passkeys don't meaningfully simplify the account creation process.

Having implemented Passkey-only account creation (and management) I would absolutely disagree. I think that Passkeys can greatly streamline the process. The iOS Passkey flow especially feels as simple by default as the "Sign in with Apple" flow (with the ability to customize it with smart password managers in a way you'd never be able to with "Sign in with Apple").

That's partly because Apple sees it their job to migrate people away from OIDC-style signups, for privacy reasons if nothing else, and towards Passkeys, so their UX team is doing a remarkable job trying to reduce friction.

What's Google's interests here? Are there intentional reasons the Android and Chrome Passkey flows don't "simplify" the account creation process enough? It's easy to be cynical here, and seeing them as orthogonal concerns also feels like muddying waters that shouldn't be muddied right now.

Re: Sign in with Google in Chrome

#258
post #5

This popup should be criminal. Ive misclicked the signin button multiple times, causing PII to be sent to a third party I dont trust without my authorization.

Don't worry about misclicks, Google already tracked your visit when the webpage was loaded. Google One Tap works via a script tag from Google servers: https://developers.google.com/identity/gsi/web/guides/displa...

The bad thing is not sharing the info with Google (you are right, just by siing it, Google has your info), but the random third party website.

Re: Sign in with Google in Chrome

#259
While I agree with the 50+ comments I’ve read here, I think the point is being missed (or I just haven’t gotten to this comment yet) - these super annoying pop-ups should only be a thing AFTER you’ve clicked on login or register. In fact they shouldn’t appear and should instead just be a button the user can click if they wish to use their Google account as the login device for XYZ site. In other words there’s no reason for these to appear when you first visit a webpage, they should only be relevant when the user has taken action specifically to login, or is looking to register an account at xyz.com

It’s as if someone at Google saw the whole cookie banner -> accept cookies fiasco and said wow this seems like a good idea let’s add our own

Re: Sign in with Google in Chrome

#260
post #192

Earlier quoted context omitted.

I would never visit a site like pornhub in a profile that I was logged in to anything other than similar sites. note: I'm not excusing the feature but come on! Have some common sense before visiting a site like that? The place I hate the popup the most is mobile. It comes up moments (0.5 to 2 seconds) after the site loads (say tripadvisor) which means it's possible accept it by accident as it appears under your finge…

> I would never visit a site like pornhub in a profile that I was logged in to anything other than similar sites. But that's not relevant. The popup appears whether you're logged into a google account or not. It's just an extremely annoying popup that appears all over the web.

It does not for me and I only use chrome. ¯\_(ツ)_/¯
Post reply on HN