Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

411–420 of 544 posts

Re: Don't use third party auth to sign in

#411
post #401
post #389

Earlier quoted context omitted.

All titles are clickbait, researchers, bloggers, youtuber, conference speakers, and journalists who succeed are also ones who know how to choose good titles

Not all titles are clickbait, and even if the majority are, we should strive for better

Clickbait is a spectrum not a binary. I think keeping google in the title doesn't detract from conveying what the article is about while at the same time making it more attractive.

Re: Don't use third party auth to sign in

#412

_A plea to the moderators:_ Please change the title of the submission back to match the title of the blog post, "Never Use Google to Sign-In". To be fair to Google I have clearly called out all third-parties in the blog post, some by name. I used Google's name in the title because that name elicits reaction from almost 100% of the audience, since almost everyone has used Google services at some point. I myself am a h…

Dissenting.

OP, your first sentence is If a website offers you to sign-in using Google (or any third-party service, say Facebook, Github, etc.), don’t use that feature.

Titling this as "Third Party Auth" is a reasonable and correct summary of your article. Blaming Google specifically is hype-mongering unless you have a specific gripe against Google - and reading through your post, I don't see a Google-specific criticism.

Re: Don't use third party auth to sign in

#413
Many sites seem to use the email associated with the third party account as the identifier: so, if I lose access to Google, I can use the email address to reset the password or use Facebook or Apple sign-in, as long as those accounts serve up the same e-mail address.

Re: Don't use third party auth to sign in

#414
post #382

Earlier quoted context omitted.

I.e. you want this article to be clickbait and now you are unhappy that it is not.

Way to speak for another person's intentions AND feelings! That's where we are nowadays, I guess. It's their article, I think it's fair they ask for the name of the post to be preserved. It has nothing to do with their intent (clickbait or not) that the audience here voted up their submission.

> I used Google's name in the title because that name elicits reaction from almost 100% of the audience,

And

>Changing the title from "Google" to "Third Party Auth" significantly softens the impact and urgency I want the reader to feel upon reading the title,

It sounds rather like parent was correct in calling it click bait. For me, any article that has aspirations to manipulating ones emotions in order to illicit a particular outcome is definitely selling some propagandist notion... Aka click bait.

That the article's content, HN submission and the parent comment is the same person @gurjeet, I would like to thank @dang for the modification.

Re: Don't use third party auth to sign in

#416

You can get also locked out of your phone

You can get also locked out of the email that you actually use for signing in because you can never remember the password and they stupidly ask you to change it every 6 months with bizarre constraints

You can get locked out of your password manager

You can get hijacked

The business you're signing into can go under

The odds of these things happening are to be weighted against each other

Yes you shouldn't use third-party sign-in for the bank account that holds all your money (though most consumer bank 2-factor authentication mechanisms, sadly, rely on third parties such as phone and email provider)

Yes it's also ok to use third party sign-in for the odd website that you don't care about which somehow insists on asking you to create an account

There are no absolutes in security risk management

Re: Don't use third party auth to sign in

#417

Earlier quoted context omitted.

No good reason until an exploit comes out that wreaks havoc.

There’s still good reasons. Mine is using public computers (library or school), or being able to use any computer at work in private browsing mode. It’s also trivial to have passwords which are secure and easy to remember (literally off the top of my head): MyD0gb@rk$...

That is not a secure password. The phrase "mydogbarks" appears in several word lists and hashcat has had leetspeak rules for years now.

Re: Don't use third party auth to sign in

#418

Many sites seem to use the email associated with the third party account as the identifier: so, if I lose access to Google, I can use the email address to reset the password or use Facebook or Apple sign-in, as long as those accounts serve up the same e-mail address.

My sign in as google uses the @gmail address, which I don't have access to other than signing into google, so I wouldn't be able to get the reset email link. Interestingly, since I use my own domains, my facebook signin is different than my gmail address. But interesting, I've never tried using a second oauth as a match to the first.

Re: Don't use third party auth to sign in

#419
post #382

_A plea to the moderators:_ Please change the title of the submission back to match the title of the blog post, "Never Use Google to Sign-In". To be fair to Google I have clearly called out all third-parties in the blog post, some by name. I used Google's name in the title because that name elicits reaction from almost 100% of the audience, since almost everyone has used Google services at some point. I myself am a h…

I.e. you want this article to be clickbait and now you are unhappy that it is not.

No, clickbait would be: This guy used Google to login, you'll never guess what happens next!!

He wants to us the name Google to personalize the message assuming that's what a lot of people use. Do you know how I figured that out? That's what OP said was his goal. It's rude to assert otherwise without evidence.

Post reply on HN