Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

431–440 of 544 posts

Re: Don't use third party auth to sign in

#432

Earlier quoted context omitted.

Ease. If you're already logged into Google, it's essentially a one click process.

I get that. But I also don't all my services to depend on Google at all, even if it's just a login.

The authentication service should ideally be under the control of the user. At least, the user should be able to choose one that they trust. I doubt it's an accident that current authentication systems lack that choice.

Re: Don't use third party auth to sign in

#433
This is not an easy issue. It boils down to responsive customer service at the end. Even if you host your email, your hosting provider can suspend your account if, let's say, your credit card rebilling fails. There should be a better and more resilient way to identify people online in 2020!

Re: Don't use third party auth to sign in

#434

Earlier quoted context omitted.

> I'm honestly not sure where we went so wrong as a society so as to reach this point... Why? The answer is actually very simple: spam. AFAIK pretty much all disabled Google accounts come from Google believing they are part of a spam-sending (or malware-spreading) network. The ability to sign up for free Google accounts means this is a prime target for spammers to use and abuse -- signing up for free Gmail/Drive acco…

> incorrectly disabled Google accounts are actually incredibly rare -- they make the news and cause uproar when they occur, but precisely because it's so unusual Or they rarely make the news because they're so common, and the few that get publicised are because the victim raises a big stink on social media. I've certainly created Twitter and Microsoft accounts and had them wrongly disabled within days, despite not do…

> had them wrongly disabled within days, despite not doing anything at all with them

That's because that's also a common tactic used by spammers -- to register and then do nothing for days/months, on the hopes that an "older" account will be less suspicious.

Nobody's complaining about that though because it's not a problem. No data is lost. Also, I've had it happen to myself (with Twitter) and it was incredibly easy to re-instate.

To clarify, I was referring to legitimate, in-use (with data to lose) accounts being incorrectly disabled.

Re: Don't use third party auth to sign in

#435

Earlier quoted context omitted.

The speed of technological development is faster than the speed of societal or legal development. So yes, right now we've woken up in a world that is not so much cyberpunk as it is techno-feudalism: more and more do you need a presence on the Internet to do things in meatspace... And that presence is by the grace of several feudal lords (Google foremost) - woe betide you should you ever displease them. You do not rea…

This isn't even a tech problem. It's a lack of regulation to give recourse for individuals and lack of ability for them to be treated fairly by businesses. We need to treat companies that put themselves into a position like utilities as utilities. Give individuals actual transparency of why actions where taken, and an ability to appeal these decisions with transparency. It will cost more, but that is ok. What we have…

This. The power company can’t cancel you for a tweet for a reason.

Re: Don't use third party auth to sign in

#436

Earlier quoted context omitted.

Do you not see this as a problem? With the amount of services Google offer, losing them can be devastating; photos, emails, Android backups, contacts and so so much more. This pandemic has been reliant on emails to access services; it's how I get my payslips, talk to my employer, get current information, engage with legal services, and essentially maintain my access to society. Losing my emails would be devastating (…

No, it's not a problem. It's your problem if you become entrenched in their (or Apple's / FB / whatever) services. I have a google account to test my devices / emulators. Never logged in gmail with that account, never will. If they cut it off, I can make another. Same with Apple. I have an Apple free ID for running virtual machines with MacOS / iOS and that's all. I tell my customers to create their own Apple ID and…

> No, it's not a problem. It's your problem if you become entrenched in their

It absolutely is a problem for a large amount of people.

> Do the same, you'll be free

The vast majority of people in the world are not taking the same actions as you are. Therefore this is a large problem for many many people.

Re: Don't use third party auth to sign in

#437

_A plea to the moderators:_ Please change the title of the submission back to match the title of the blog post, "Never Use Google to Sign-In". To be fair to Google I have clearly called out all third-parties in the blog post, some by name. I used Google's name in the title because that name elicits reaction from almost 100% of the audience, since almost everyone has used Google services at some point. I myself am a h…

Ok, we've regoogled it above.

Edit: now that I've had a chance to read the article, I don't agree with that change, and have restored the title back to how a moderator had correctly edited it before.

The reason is that the article doesn't say anything specific to Google. The sole point it does make is common to all the services, and indeed the article seems "conscious" of this, since 3 times it says "google" it immediately qualifies that with a phrase like "or any service".

Nor does the parent comment make the case that this is specific to Google; in fact it makes the opposite case.

Re: Don't use third party auth to sign in

#438
post #435

Earlier quoted context omitted.

This isn't even a tech problem. It's a lack of regulation to give recourse for individuals and lack of ability for them to be treated fairly by businesses. We need to treat companies that put themselves into a position like utilities as utilities. Give individuals actual transparency of why actions where taken, and an ability to appeal these decisions with transparency. It will cost more, but that is ok. What we have…

This. The power company can’t cancel you for a tweet for a reason.

Laws that provide meaningful mechanisms like this would also be a good signal to keep companies from being in such a powerful position. That is good for everyone.

Re: Don't use third party auth to sign in

#439
post #255
post #65

Earlier quoted context omitted.

The only thing worse I can think than having Google read your email is having Yandex read it.

If you aren't in the US, then Yandex is probably safer.

Russian companies cannot refuse data requests from the Russian government. American companies can.

Re: Don't use third party auth to sign in

#440

Earlier quoted context omitted.

Kindle books were actually pretty good, back when they could reliably be liberated. Unfortunately, that's no longer the case. In general, I think that's also a point we can draw from the cyberpunk genre, or maybe from Harry Harrison's old-school prefiguration of it in the Stainless Steel Rat series - the eponymous creature being one well suited to thrive "within the walls" of a society increasingly sclerotized with t…

Off-topic, but legitimately purchased Kindle ebooks can still be quickly and easily liberated for the purposes of DRM-free personal backups of owned content. I won't comment on whether Amazon find this acceptable, or if it is legal in any given jurisdiction, but it is definitely possible.

[deleted]
Post reply on HN