Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

371–380 of 544 posts

Re: Don't use third party auth to sign in

#371

I'm honestly not sure where we went so wrong as a society so as to reach this point. Whether it's overzealous AI or the AMPification of the web. Google act with impunity and without remorse, every action designed to further their goals and agendas without respect to humans caught in the crossfire. If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated…

The soul of the current internet is intrusive, tracking advertising. In Real Life we have fundamental structures such as identity that have not translated to the internet. In the world of advertising everything can be fake and there is no trust. We need a new soul. :-)

Re: Don't use third party auth to sign in

#372
post #190

Earlier quoted context omitted.

> Yet here it is. Google can offer their services and the legal system seemingly doesn't want to be involved. Why ? The real question is why do people use Google to sign in to other services? It never even crossed my mind no matter how long I have had a Google account.

I don't want more accounts and passwords. The security seems strictly worse than just authenticating against my email provider directly.

password managers are a thing. Takes literally 20 seconds to add a new one to a new account.

Re: Don't use third party auth to sign in

#373

Earlier quoted context omitted.

The speed of technological development is faster than the speed of societal or legal development. So yes, right now we've woken up in a world that is not so much cyberpunk as it is techno-feudalism: more and more do you need a presence on the Internet to do things in meatspace... And that presence is by the grace of several feudal lords (Google foremost) - woe betide you should you ever displease them. You do not rea…

This isn't even a tech problem. It's a lack of regulation to give recourse for individuals and lack of ability for them to be treated fairly by businesses. We need to treat companies that put themselves into a position like utilities as utilities. Give individuals actual transparency of why actions where taken, and an ability to appeal these decisions with transparency. It will cost more, but that is ok. What we have…

[deleted]

Re: Don't use third party auth to sign in

#374
post #287

Earlier quoted context omitted.

There's no good reason not to use a password manager in 2020. I recommend this one: https://www.passwordstore.org/

No good reason until an exploit comes out that wreaks havoc.

You can use local ones like KeePassX.

Re: Don't use third party auth to sign in

#375

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

this uses OIDC. it’s a non starter, for reasons unrelated to the part you are “solving” here.

Can you be more specific?

Re: Don't use third party auth to sign in

#376
post #107

Earlier quoted context omitted.

Has there been any retrospectives or published thoughts around why OpenID failed? Ideally a extensive, impartial report would be nice to read through. While it's easy to blame big technology companies for the failure of open standards, there might be other reasons behind it (as well as companies trying to prevent it from succeeding)

OpenID failed because you had to sign up to an OpenID provider and then copy and paste some weird URL from there into websites you wanted to use. Why would anyone bother with that hassle when you can just put in your email address (that you already have & know) and a password. In contrast, OAuth succeeded because most people already have a Facebook / Gmail / Github account, which meant that sign up just becomes click…

Having a DNS-like system that resolved an individual's email address to an OpenID provider (or more than one?) might've been a good idea.

Re: Don't use third party auth to sign in

#377

Earlier quoted context omitted.

> Yet here it is. Google can offer their services and the legal system seemingly doesn't want to be involved. Why ? The real question is why do people use Google to sign in to other services? It never even crossed my mind no matter how long I have had a Google account.

Ease. If you're already logged into Google, it's essentially a one click process.

I get that. But I also don't all my services to depend on Google at all, even if it's just a login.

Re: Don't use third party auth to sign in

#378

Earlier quoted context omitted.

The speed of technological development is faster than the speed of societal or legal development. So yes, right now we've woken up in a world that is not so much cyberpunk as it is techno-feudalism: more and more do you need a presence on the Internet to do things in meatspace... And that presence is by the grace of several feudal lords (Google foremost) - woe betide you should you ever displease them. You do not rea…

Techno-feudalism is exactly what cyberpunk novels were describing. They were dystopias. They were warnings about letting corporations control everything.

True, but so far we just get the bad things (corporatocracy and the the gradual hollowing out of individual liberties) and none of the good things (gene-hacking, neural uplinks, and matrix-avatars) that cyberpunk promised. I demand a refund!

Re: Don't use third party auth to sign in

#380

Earlier quoted context omitted.

Fastmail is very good. The web client is pretty simple, but feels so darned responsive (as in fast) compared to what I was used to from GMail. And spam is so far a non-issue.

Or, host your own on your own metal, to avoid depending on any third party. Alternatively, if you are ok with semi-dependence on a third party, get a $5/mo Linux VPS, and host your E-mail there. With your own Linux instance, you can host whatever you want, have full control, can host other services too like www, git, whatever, and have the assurance that you're not going to suddenly lose access because AI-BOT-204432…

> How did we end up in this world where we so utterly rely on 3rd parties for such everyday critical Internet services?

The same way we ended up in a world where we so utterly rely on 3rd parties for such everyday critical services as growing our food and fixing our cars. There's too many things to do for everyone to do them all on their own.

Post reply on HN