5 ms·
This is really annoying and not the direction I hope internet companies will move toward. What we need is to be able to login to facebook/yahoo/whatever with g
by selectnull 12y ago
This is really annoying and not the direction I hope internet companies will move toward.
What we need is to be able to login to facebook/yahoo/whatever with google account and vice versa of course; we need to see the idea of OpenID come alive.
- silverbax88 12y agoI'm completely on the other side of the fence. I NEVER use Facebook or Google (or Twitter) to log into anything. If a company only allows that for sign up, I never sign up for those products.
- pmontra 12y agoYou're not alone on that side. Every service must have its own user/password. Single sign on with fb/g+/etc is convenient but it is good especially for those companies.
- laumars 12y agoWhile I do agree with you in sentiment, I don't think it's always better than passport sites. The problem with every site handling their own logins is that you're creating more vectors for attack. Most people reuse passwords (bad practice I know but it is what most non-technical people do) and not all sites are properly secured - in fact some don't even encrypt passwords! So at least passport sites outsource the data protection issues to larger businesses that you'd expect (no; demand) to have experience to handle that data securely.
- jakio 12y agoI personally favour the passport/OpenID idea, from a user experience point of view. In contrast to the problem you've stated, if I were to exclusively use my Google account to log into websites, it becomes a single point of failure if the service was down, and if it were to be compromised.
- laumars 12y ago> In contrast to the problem you've stated, if I were to exclusively use my Google account to log into websites, it becomes a single point of failure if the service was down, and if it were to be compromised. Very true. Sadly there's no real right or wrong answer here; a single point of failure but a better secured portal, or a decentralised network with arguably less secured portals. Personally I try to use a balance of both: Twitter passports for sites I don't trust and passwords for sites I do trust. But that's just my personal preference.
- magicalist 12y ago> Very true. Sadly there's no real right or wrong answer here; a single point of failure but a better secured portal, or a decentralised network with arguably less secured portals. This is exactly right. And, as you mentioned above, there are more kinds of people out there than are present in this thread. I have a password manager and generate a new random password per site, so I don't have any desire to use a single log-in for almost all sites. However, many (most?) people reuse a single password (or a handful of them), and until that changes, they're likely much better protected by having a single well-protected authentication point.
- BrandonMarc 12y agoThere are more vectors for attack, but the damage for any given one is more self-contained ... when there's one giant target, on the other hand, sure it's harder to get in, but if you do you've gotten into everything.
- laumars 12y agoAbsolutely. I'd already discussed this point though: https://news.ycombinator.com/item?id=7857655 https://news.ycombinator.com/item?id=7857655
- borplk 12y agoOh god every time I see this argument it makes my blood boil. It's 2014. There's no excuse for re-using the same damn password over and over again. And it doesn't make sense to make the situation worse for everyone else because they don't care about their online security. Get a yourself a damn password manager and use a unique password for each service then we can kiss all these password leak problems goodbye. Time after time we see people making a big drama because company X had all their 50 million password leaked. Oh was it hashed? Oh was it salted? If you use a unique password for each service, the service provider can store your password in plaintext and you will be safe. That's what I do and I couldn't care less if all the passwords in the world are leaked in plaintext.
- laumars 12y agoYou're right in principle but couldn't be more wrong in practice. I certainly don't have time to educate all 7 billion people in the world about password managers and you're clearly doing very little in that area either (aside kicking off condescending rants at your peers....) so deliberately implementing a scheme that's shit for 99% of the worlds internet users just so it's better for last 1% who are technically minded is just elitist and wrong. Which ever solution is implemented needs to work for all groups of internet users - not just yourself ;)
- stuaxo 12y agoI only use it for writing comments on blogs, where it's easier than making a login I will never use again.
- yincrash 12y agoI much prefer using a SSO service because I don't trust that most websites on the internet can store a password securely.
- hrktb 12y agoYou don't need to. Autogenerate password for every site, and let them fail within their silo. It's more and more manageable even on mobile devices. If a company can't manage passwords securely, they won't be able to keep your data any more secure anyway, so you should entrust private data to site you don't trust, independently of how they handle sign in.
- danudey 12y agoFacebook made changes recently to prevent third-parties from being able to access your Facebook data/identity; unfortunately, the reason I don't use FB/Google/Twitter to sign into things is because it's them I don't trust, not the third-party site.
- silverbax88 12y agoBingo. I don't use FB that much and I don't trust them to have access to (in every sense) every site I have access to.
- darvy 12y agoWell, Google doesn't even support OpenID anymore (at least not the traditional version). https://developers.google.com/accounts/docs/OpenID https://developers.google.com/accounts/docs/OpenID
- Flimm 12y agoI was hoping Mozilla Persona would have taken off by now. It's a more usable and has better privacy than OpenID. I'm still excited for it.
- szatkus 12y agoBeside technical reasons I think that Mozilla is more trustworthy than Google or Facebook.
- Spearchucker 12y agoI'm of the opposite opinion because the seven laws of identity (http://www.identityblog.com/?p=352 http://www.identityblog.com/?p=352). Specifically law 3 (justifiable parties): Digital identity systems must be designed so the disclosure of identifying information is limited to parties having a necessary and justifiable place in a given identity relationship.
- fourstar 12y agoNo no and no. What happens when those companies are no longer around that you are signing in with? Stackoverflow did this with OpenID and I eventually needed to create a StackExchange account to login.