Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

351–360 of 544 posts

Re: Don't use third party auth to sign in

#352

Earlier quoted context omitted.

Really the dumbest, most confusing design I've ever seen to make a website seem like it knows who you are when you visit as a guest. When I first saw it on Pinterest, it took me a moment to figure out what I was looking at as a web developer of 20 years. My girlfriend still didn't get it after I was explaining it to her. How does anyone else have a shot at arriving at "oh, so the site doesn't actually have access to…

If you empathize with normal users, you realize they don't care the least about any of this. They want to use a convenient service to do things. To post pictures of themselves, to see what their friends and frenemies are up to, what's the new cool thing etc etc. Login should just work, nobody cares what is displayed where, and which site knows what. Normal people (outside the HN) bubble don't care about these things,…

The problem is that it doesn’t really work, because if next time they somehow log in with their email/Twitter/Facebook/Apple ID instead, it will make a new, totally unrelated account, and all their stuff will be mysteriously gone for no apparent reason.

Re: Don't use third party auth to sign in

#353

Earlier quoted context omitted.

No good reason until an exploit comes out that wreaks havoc.

Hard to imagine what sort of exploit could come out that could cause havoc when the encrypted passwords are stored on your device.

Imagine a vulnerability in the password manager extension that allows a hacked site to fill in and scrape every login stored in the password manager.

Re: Don't use third party auth to sign in

#355
post #287

Earlier quoted context omitted.

There's no good reason not to use a password manager in 2020. I recommend this one: https://www.passwordstore.org/

No good reason until an exploit comes out that wreaks havoc.

There’s still good reasons. Mine is using public computers (library or school), or being able to use any computer at work in private browsing mode.

It’s also trivial to have passwords which are secure and easy to remember (literally off the top of my head): MyD0gb@rk$...

Re: Don't use third party auth to sign in

#356

Earlier quoted context omitted.

Yeah. Reddit is especially really intrusive and annoying. I feel like they just don't want people to use their site anymore. Whenever I open new Reddit, my memory and CPU usage goes up so badly.

Reddit website unusable on mobile, it cuts all images in half for me (Nokia 3.1 and Samsung A51), and it's just laggy. I use RedReader from F-Droid instead.

They can't even manage to get their video player to work. Even your local news web sites, which ten years after YouTube still couldn't manage to consistently get a video to play in the browser, have figured it out by now. But Reddit? Nope. Requires me to hit the play button 3-4 times in order to start the video, stops randomly in the middle of the video, and "re-play" never works. I mean, we're almost in 2021! Developers, if you can't figure it out, just give up and embed YouTube.

Re: Don't use third party auth to sign in

#357

Earlier quoted context omitted.

Yes and it pissed me off because on mobile it pops up like 0.5-2 seconds late so if you're unlucky you go to click on something and it popups up under your finger and you've suddenly signed up and shared your info with a company you had no intention of ever signing up with. I complained to Google. I have a GSuites domain and I don't want my users to be able to sign up via Google. No resolution. I suggest you all comp…

Also I reflexively clicked ok out of laziness and annoyance without knowing what it was. Not quite a dark pattern but you certainly aren’t completely aware what it’s asking within the first second of seeing it.

aren’t completely aware what it’s asking

That is one example of a dark pattern.

Re: Don't use third party auth to sign in

#358
1. This isn't a clear cut, though some services don't allow using both Oauth 2.0 and email / username login, most do. So if the service provider allows both, create a simple user + link your account.

2. Developers should always allow restoring passwords for SSO only users, it is ridiculous for it to even be an issue.

3. As a user, refrain fro using free email accounts to identify on a platform, as others already said, buy a domain not an expensive one, and stick to it, remember to renew, and setup your email address with a reliable service, there are good providers for $1 a month.

Update: line separation...

Re: Don't use third party auth to sign in

#359
post #286

Earlier quoted context omitted.

See also: Kindle books; movies "purchased" from Amazon, Apple, et al; Tesla upgrades you paid extra for; I could go on....

I have yet to hear about the first amazon account ban. I don’t think they’re really interested in that, since the accounts are almost by definition making them a bunch of money.

I once used to buy digital movies on Amazon and thought it was a great experience. Until my first vacation in Canada where I discovered I couldn't watch my movies. I called them and they said that my movies were region-locked to the United States. To their credit, they did refunded all of my digital purchases. I haven't bought anything digital from them since.

So, not an Amazon account ban, but you quickly learn you are not "buying" a movie, but renting it, sometimes with silly restrictions like "only from these IPs".

Re: Don't use third party auth to sign in

#360

Earlier quoted context omitted.

According to the Bureau of Labor Statistics, the number of historian jobs in 2019 was 3500 - that's in the entire US. So... incredibly rare, really.

They did say "degree in history" rather than "job as historian" though.

Exactly. The number of people in the US workforce who have a history degree is a little over a million (https://datausa.io/profile/cip/history).
Post reply on HN