Live data from Hacker News

Start ups, please don't force me to log in with Facebook

news.ycombinator.com

71–80 of 279 posts

Re: Start ups, please don't force me to log in with Facebook

#71

Earlier quoted context omitted.

All of the above. And also because, I just don't want to have to use FB to login to a totally unrelated site. The use case is, I use FB sparingly because I don't have time to get sucked into that pit. I friend people I meet irl, and 'Like' sites that are relevant to my profession (personal branding & networking). But I don't use it for any other purpose. So if your site isn't relevant to my profession, I don't want t…

Seconded. I don't understand OpenID, but it works, and it's not tied to a single (ominous) company.

The problem with OpenID is that takeup is orders of magnitude lower than Facebook. That hasn't changed for years, and I don't think anyone really expects it to. Users can't use it as a direct facing log-in because users don't tie themselves to URLs, they tie themselves to email addresses. OpenID eventually asks you to trust someone to hold your sign-on details, it may as well be a company most users already do.

I somewhat favor the StackOverflow approach, which is "we won't authenticate you, but here's a bunch of services that do", but inevitably I forget which service is actually tied to my account. This is how it's been with my HN account for a while, I loathe deleting the cookie, as I spent 10 minutes figuring out what ClickPass wants.

TripIt has both Facebook and Google Accounts. I'd probably expand to Yahoo! and Live Mail (if MS has anything for that) and leave it there.

Re: Start ups, please don't force me to log in with Facebook

#72
post #67
post #50

Maintaining a separate identity for every site across the web gets more impractical by the second. I think most people would agree that a third-party authentication service is a positive thing, but there seems to be a stigma, earned or not, surrounding Facebook that makes people hesitant to assign that responsibility to them. I think ultimately it's going to come down to a paid, independent service. Startups can't of…

What's impractical about it ? I'm very comfortable with separate identities per-site. If your site isn't worth a separate identity, why am I interacting with it in the first place?

I'm comfortable with separate identities per site, but it is impractical for most people. You have three general choices:

- Maintain a separate login and password for every site. This requires a lot of memorization and is a pain in the ass when you find yourself trying four passwords because you forgot which you used.

- Use password management software or a naming system that lets you keep track. This is effective but is a bit much for a majority of people who do not, and probably never will, use tools and reasoning to help them do things on their own volition.

- Use the same login and password almost everywhere. This is easy but is shitty security.

You might claim that using a third-party authenticator is just like option #3, but it's not. Option #3 above means that your single credentials are under the control of the least secure site you use them on, so if someone cracks some install of PHPBB version 0.0001 that you logged into, you're fucked. Using a third-party auth provider relieves you from this worry. It even means that you can switch at your leisure and start using a hardware generator or a long passphrase if the provider supports it.

Re: Start ups, please don't force me to log in with Facebook

#73

Earlier quoted context omitted.

Forcing me to be okay with everyone and their dog seeing what I do on my own time and on a completely different site is unacceptable, and frankly just lazy on their part. That has nothing to do with "commitment." I as a consumer get nothing out of it other than a lack of privacy and the heavy-handed assumption that some startup's "service" outweighs that. No thanks, and the fact that I'm not the only one means that i…

I think you may misunderstand what signing in with Facebook does. 1) It could, potentially, provide some value to you as a user. Quora gets to suggest people to follow for you based on your Facebook friends, so your experience on there is seeded with relevant information. 2) Nothing you do on the site you signed in with is published to your Facebook profile, without your explicit consent on a dialog box.

Nothing you do on the site you signed in with is published to your Facebook profile, without your explicit consent on a dialog box

The trouble with this statement is that some users (myself included) don't believe (a) this is true even when they say it's true, or (b) that if it's true today it will still be true tomorrow.

Such paranoid users are worried that FB will make a privacy policy change that turns the privacy off "as a benefit to users," and the opt-out checkbox will be buried seven links deep. I try to use FB's controls to make my FB stuff fairly private, but I still operate on the assumption that one day FB will break my assumptions about what is or isn't shared.

The recent "Places" launch confirmed it for me. If I hadn't read someone else's blog post, I wouldn't have known that simply refusing to opt into places wasn't enough, I also had to explicitly block friends from checking me into locations.

Re: Start ups, please don't force me to log in with Facebook

#74
post #45

Earlier quoted context omitted.

I would much rather have an easy way to tell if someone is a "real" person, and Facebook gives me that. How does Facebook give you that, exactly?

Several ways, none of which is individually full-proof, but taken together they are a very good indicator: - Does the user have a profile photo, or is it the default user icon? - How many friends does the user have? (Generally 0, 1, or 2 is highly suspicious) - Does the user have a real name? [Edit: we have a blacklist of fake names.]

[deleted]

Re: Start ups, please don't force me to log in with Facebook

#75
post #70

"I forgot my username/password" is an immense burden on a small company. You end up having to make horrible tradeoffs between privacy and convenience (how do you really verify that this user is really this person?) and end up with a serious support issue for a product that might otherwise not generate much support email at all. To be clear: even if it costs half your conversion rate, it may be valuable, at least unti…

Automated password resets are a solved problem. Either email a new pw or reset link to a known address, or authenticate with "secret questions".

Both have their problems, but no small company should waste support time when established techniques are available.

Re: Start ups, please don't force me to log in with Facebook

#76
post #50

Maintaining a separate identity for every site across the web gets more impractical by the second. I think most people would agree that a third-party authentication service is a positive thing, but there seems to be a stigma, earned or not, surrounding Facebook that makes people hesitant to assign that responsibility to them. I think ultimately it's going to come down to a paid, independent service. Startups can't of…

What makes me nervous about singing into a site through Facebook is I don't know what kind of permissions I'm giving to the site regarding my FB account.

Re: Start ups, please don't force me to log in with Facebook

#77
post #37

Earlier quoted context omitted.

Why would you trust a website asking for an email and password more?

Email is better because you are not locked into using some third party website to log in. You can set up an email server of you own if you wanted to.

Exactly

Re: Start ups, please don't force me to log in with Facebook

#78
post #8

For me it's more of a matter of privacy. I do have a facebook account but still refuse to log into any site that wants me to connect with facebook.

I agree. I don't know why it's not also a matter of privacy for site owners. They're handing Facebook their entire usage data. Dumb dumb dumb.

Re: Start ups, please don't force me to log in with Facebook

#79

Earlier quoted context omitted.

Forcing me to be okay with everyone and their dog seeing what I do on my own time and on a completely different site is unacceptable, and frankly just lazy on their part. That has nothing to do with "commitment." I as a consumer get nothing out of it other than a lack of privacy and the heavy-handed assumption that some startup's "service" outweighs that. No thanks, and the fact that I'm not the only one means that i…

I think you may misunderstand what signing in with Facebook does. 1) It could, potentially, provide some value to you as a user. Quora gets to suggest people to follow for you based on your Facebook friends, so your experience on there is seeded with relevant information. 2) Nothing you do on the site you signed in with is published to your Facebook profile, without your explicit consent on a dialog box.

It may not be published (2), but facebook certainly tracks and stores the information.

Re: Start ups, please don't force me to log in with Facebook

#80
post #67

Earlier quoted context omitted.

What's impractical about it ? I'm very comfortable with separate identities per-site. If your site isn't worth a separate identity, why am I interacting with it in the first place?

I'm comfortable with separate identities per site, but it is impractical for most people. You have three general choices: - Maintain a separate login and password for every site. This requires a lot of memorization and is a pain in the ass when you find yourself trying four passwords because you forgot which you used. - Use password management software or a naming system that lets you keep track. This is effective bu…

Choice. Let people choose if they want to use Facebook, or if they want to log in directly. Allowing people to log in directly should be the minimum requirement. Facebook should be an addon authentication system, not the only.
Post reply on HN