Understanding OAuth 2.0 and OpenID Connect
blog.runscope.com
blog.runscope.com
Do not use Implicit Grant in mobile apps unless interacting with an app provider (and even then, Implicit Grant still has some major footguns if you are using it for authn, which most people are). It was absolutely not "designed specifically for mobile apps." If you are talking to the browser you cannot ensure that the access token is delivered to the right place and access tokens are not bound to the relying party. If you are using the access token for authn like suggested here, you let malicious apps impersonate your users.
If you are using a mobile app and performing OAuth through the browser, use Authz Code flow with PKCE.
Entirely agree and we recommend using Auth Code+PKCE whenever possible. This post is intended to be the first of a few starting with the base spec. In the next one, I plan to go over the RFCs for JWT, Revocation, Inspection, PKCE, the AppAuth pattern, and probably a few others.
Thanks for the note though.
Plus if a breach happens on Facebook or Google, then the hackers get EVERYTHING including access to your site (as a site author).
So there are definitely downsides to doing social login(s) as well, and it's not as clear cut as just "let Google and friends do it for me".
They know that I use the site and (to some extend) when.
I am under the (possibly false) poison that the risk is to let the requesting site (HN here) request to much data from, say, Google (my age, shoe size and whatever they store about me)
For one site, not a huge issue maybe, unless it's ilovemesome<insert something disgusting here>.com
But add this up across many, many sites, and they suddenly get loads and loads more information to sell ads to you with.
I get that that is definitely not an easy thing to do, but an OpenID implementation doesn't have to force users to log in through some major social network, and I feel like your statement asserts that.
(but even with that addendum, I agree, you'll probably still end up wanting to support password based login as a service provider. But as a user, I greatly appreciated not having to constantly get my password manager to meet some random list of requirements.)
A wish for a decentralized solution that actually had user traffic so we could all DROP COLUMN password FROM user.