Live data from Hacker News

Don't use third party auth to sign in

gurjeet.singh.im

491–500 of 544 posts

Re: Don't use third party auth to sign in

#491

Earlier quoted context omitted.

This is precisely why I buy vinyl or music from Bandcamp, and choose the disc version of the PS5. I view my digital purchases as things I am forever renting.

... You can't store MP3 files why? You're renting your hard drives, too?

I meant digital purchases with DRM or inside a digital store like Vudu or Amazon Prime.

Re: Don't use third party auth to sign in

#492

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

I see it as a stepping stone for global “real id”. In this case centralization is a feature, not a bug.

Re: Don't use third party auth to sign in

#493
post #442

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

I was my own OpenID Provider for a while, but quit because nobody supports it anymore. It was great for power users but super confusing for laypeople.

That sounds painful in so many ways...

Re: Don't use third party auth to sign in

#494

Earlier quoted context omitted.

I have attempted to read two articles on your site. As I am a privacy-focused person the articles were of interest to me. Both times I haven't gotten past reading the opening sentences when an obnoxious pop-up appeared asking for my email address. It seems ironic that someone publishing articles on privacy advocacy would be so keen to collect my email address. This practice also creates a real miserable experience an…

An email address is public information not private. You can have as many as you like for different purposes.

Email addresses are not public in general. They are not supplied to every site you visit automatically, and should not be manually supplied to every site you visit either. Whether it's a unique per-site address or not, it only makes sense to give it to people/organisations you want correspondence from. Therefore, sites that ask for it when you start reading an article seem really sketchy.

Re: Don't use third party auth to sign in

#495

The risk of getting your account locked is just one of the reasons you shouldn't use Google (and the like) to sign in. But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication? Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again.…

There is TLS client authentication, unfortunately it never catched on, probably due to not good and uniform UX in browsers. Imagine if web-browsers have automatically generated password-protected self-signed certificates that could be used to authenticate to web services without need of any third-party.

> Imagine if web-browsers have automatically generated password-protected self-signed certificates that could be used to authenticate to web services without need of any third-party.

What should be done when creating a new account is that, in addition to the username and password, the website should allow for uploading a certificate signing request. The web browser should then allow the user to create one and upload it. The website should then return the signed certificate to the client and the browser can then store it to use during subsequent connections.

Doing something like this would allow for two factor authentication without the half-baked solutions like sms or email based 2fa.

Re: Don't use third party auth to sign in

#496

Earlier quoted context omitted.

This is precisely why I buy vinyl or music from Bandcamp, and choose the disc version of the PS5. I view my digital purchases as things I am forever renting.

Those discs aren't going to do you much good if you don't have access to or have had access to PSN, since most games ship with a huge day 1 patch to fix all the issues between going gold and the date of sale. Movies/Music/Books can be displayed and played back on damn near anything. Games, especially modern games, exist in both a variable state (constantly revised/updated), but also with a much more limited ability t…

I lost a small number of games due to PlayStation support not being able to get around the fact that although I purchased some of them via PayPal, I also bought other games with a credit card. They could verify I owned the actual account and I answered all security questions but they still wouldn't fix whatever issue I had (this was at least 5 years ago so I forget particulars).

That experience forever turned me off to relying on digital-only.

To your points, having a PSN account is necessary but I can always create a new one if need be.

Whenever possible, I prioritize non-DRM media for purchase.

Re: Don't use third party auth to sign in

#497
post #5

To add to this: Never use a @gmail.com address, buy your own domain and pay the $6/mo to get a Google GSuite with your name@fullname.com address instead. If Google locks your account, you can now move your email hosting to another provider and won't lose access to your entire digital world. Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email acc…

> app-based, not SMS-based two-factor authentication)

How does that work when using an email client and connecting to the server and using SMTP and IMAP?

Re: Don't use third party auth to sign in

#498

Earlier quoted context omitted.

> I run my own mail server but my VPS provider could be coerced to yank it from me. I've got two comments on this. Firstly, you're already doing much better than most people. Make frequent backups, and if it comes down to it, you can always point DNS at a new provider. Second, don't put anything on a VPS that you aren't willing to let the VPS provider or whatever Gov. has jurisdiction access. Where email falls on tha…

There is one more solution. Use a VPS only as an endpoint bastion server. Keep the data and services in your own home server. We need not trust the VPS provider this way. And we can easily recover as long as the domain name and the home server are under your control.

Having domain names under my control are a big reason for my excitement for Handshake's/Namebase's existence.

Re: Don't use third party auth to sign in

#499

Earlier quoted context omitted.

OT: Please tell me you have a blog, I enjoy the way you write. — I run my own mail server but my VPS provider could be coerced to yank it from me. You’ve made me uncomfortable with revelations. Damn, we’re fucked.

> I run my own mail server but my VPS provider could be coerced to yank it from me. I've got two comments on this. Firstly, you're already doing much better than most people. Make frequent backups, and if it comes down to it, you can always point DNS at a new provider. Second, don't put anything on a VPS that you aren't willing to let the VPS provider or whatever Gov. has jurisdiction access. Where email falls on tha…

An idea I've been mulling is getting a baremetal server from Exoscale (based in Switzerland) and running a mailserver on it. Haven't done it yet for many reasons, least of which is laziness...and I want to try and create a JMAP server with an IMAP bridge but that's another story.

Re: Don't use third party auth to sign in

#500
post #286

Earlier quoted context omitted.

I have yet to hear about the first amazon account ban. I don’t think they’re really interested in that, since the accounts are almost by definition making them a bunch of money.

There was the case when they remotely deleted the novel 1984 from a bunch of devices.

Ah, good one. I’d forgotten about that.
Post reply on HN