Live data from Hacker News

Yahoo to End Facebook, Google Sign-In on Its Web Properties

recode.net

31–40 of 52 posts

Re: Yahoo to End Facebook, Google Sign-In on Its Web Properties

#31

I wonder how many of the 10 remaining Yahoo users will be inconvenienced by this. Seriously though, this is a good thing - third party sign in is a horrible idea and should die.

Third party sign in might not be ideal, but having to register for every crappy service and website is much much worse.

And flickr or tumblr have quite a bit more users than you've guessed.

Re: Yahoo to End Facebook, Google Sign-In on Its Web Properties

#35

Earlier quoted context omitted.

I disagree. The more people use Social login and the less people use their one shared password on all sites which tends to be "password1", the better.

It's a bit of an improvement. On the other hand, if that one account is hacked, it gives access to everything else as well. Moreover, you can even get a list of applications/sites tied to that account. Which makes it arguably even less secure. If we want people to be safer, we should learn them how to use a password manager to generate a unique password for every site. And since access to passwords requires two thing…

I use Google Two-Factor authentication. I need my password, and my phone.

If I root your box, and watch you type, I have the password to your password manager, and the password database.

Re: Yahoo to End Facebook, Google Sign-In on Its Web Properties

#36
Unless I really, really, really want to use a service, I only use it if I can login with gmail or facebook.

I don't have time for your shit registration form or strange password requirements. I'm always logged into gmail and facebook, so those are always one-click accounts for me.

I understand wanting to become the identity provider, but the ship has sailed here.

Re: Yahoo to End Facebook, Google Sign-In on Its Web Properties

#37

Earlier quoted context omitted.

I disagree. The more people use Social login and the less people use their one shared password on all sites which tends to be "password1", the better.

The user's single identity should be owned by the user and managed securely by the browser, not by Facebook or Google.

Like Mozilla Persona? I like it but I don't know how they can drive adoption to your average user.

Re: Yahoo to End Facebook, Google Sign-In on Its Web Properties

#38

Earlier quoted context omitted.

It's not popular but I think Yahoo Mail is way better than a lot of people give it credit for as well.

A brief bit of googling shows Yahoo mail has similar numbers of users as Hotmail and Gmail, somewhere between 200-400 millionish, hard numbers aren't often announced. So it's popular, though has lost it's top spot.

And Yahoo mail has taken over verizon mail, at least in some hubs.

Re: Yahoo to End Facebook, Google Sign-In on Its Web Properties

#39

Earlier quoted context omitted.

It's a bit of an improvement. On the other hand, if that one account is hacked, it gives access to everything else as well. Moreover, you can even get a list of applications/sites tied to that account. Which makes it arguably even less secure. If we want people to be safer, we should learn them how to use a password manager to generate a unique password for every site. And since access to passwords requires two thing…

I use Google Two-Factor authentication. I need my password, and my phone. If I root your box, and watch you type, I have the password to your password manager, and the password database.

Arguably, if you root someone's box you could install a modified TLS stack that would allow for a MITM attack to capture the 2FA login flow. (But this would be obviously a little more difficult)

Re: Yahoo to End Facebook, Google Sign-In on Its Web Properties

#40
post #34

I tried to sign up recently with yahoo to access a yahoo group and they demanded a phone number which I didn't want to give them, so I gave up.

(123) 456 7890 wouldn't work?

no, it required a confirmation text/phone call
Post reply on HN