What Do You Think about This Seamless “Registering/Login” User Experience?
community.vanila.io
community.vanila.io
Mediums usage of it actually caused me to switch, on my work computer, from always being logged into Google, to never being logged into my Google account. Now if I have to use one of my companies apps that requires a Google login, I do it incognito.
At home, I never browse while logged in, so I didn't ever notice it that much. Using my Google account for logging into a third party web application is never my first choice. I'll take separate email / passwords for everybody please and thank you.
User/password is an inconvenient method of logging in. True. But it's so common that we have password managers making it convenient again. And supposedly better solution don't have the benefit of that tooling.
They either don't trust password managers, or don't want to change their current workflow.
They don't seem to care that using a password manger is probably a better solution then using the same password everywhere or writing all their passwords in a little black book.
I suspect that you and I aren't representative of typical users, and that Medium and Notion might actually be acting rationally, trying to act in accordance with the ways the majority of their users want the login experience to be.
> They either don't trust password managers, or don't want to change their current workflow.
I used to memorize all my passwords but now I just use my browser's 'remember password' feature. In both Firefox & Chrome it syncs between devices, and is usable on both the desktop and mobile applications. There's no extra setup required, which was the big selling point (or I would still be memorizing them) - one day I reset the browser. FF e2e encrypts it too.
The only drawback is if you need to login on a foreign device - but that's a pretty rare circumstance, and if I can't remember the password I just reset it. I generate passwords with a pattern but I am saved the hassle of typing them in, and having to remember the exceptions that differ from the usual pattern.
Firefox even offers to generate a random secure password when you are creating a new account! It's a built-in solution which provides most of the benefits of a full password manager with 0 setup or switching cost.
You’re not the target audience for these features - not only are you the tiny minority, but no matter what system they give you, you’ll find a way to interact with it safely, so for that interaction you simply don’t matter.
And choosing to do this kind of login pushes blame for authentication issues away from that company, and onto the federated provider, who presumably has legions of security researchers to make sure they’re doing things safely.
I'd imagine Medium would offer "authentication through X", and I can either enter my id for X, or go to the X app and generate a new ID for use for Medium, and paste it on Medium. So next time I want to login to Medium, after entering my username, Medium's backend talks to X's backend (saying user with this ID wishes to login) X can prompt me on one of my devices. Medium can display a unique number on their page for me, and I can compare that to the number my X app is showing me to confirm it's me I'm letting myself in.
This is a 1 minute concept without considering creative ways it can be attacked. But I guess there wouldn't be any money to be made...
Why can't you use CSS to collect the user's email address? Can't CSS blend modes allow you to capture anything that's rendered on the page? Or is that not possible anymore?
Even if the site never learns my Google identity, I hate having to close the signup window. If I misclick, they get my identity. It's so sick.
Ironically, you must sign in with a social media account( facebook / twitter ) or google / github to even use this site..... Single Sign On crap just leads to your whole life getting hacked if something happens. if I cannot setup an account with a unique email address and password, I will leave.
Checking out that page, the traditional signup button (which is what I'd use as I'd rather not use Google login) is actually under that dialog. You can't see it until you dismiss the dialog.
Don't assume I want to give you my identity.
But! Make it super easy for me to act when I decide.
These force-auth types are over-reaching and intrusive. They cause pain to the power-user and cause incidental harm to the standard-user (and maybe more)
Not for free, anyway.
Personally, I like it, and I think that from the typical user's perspective, it can probably be more convenient.
At least, it's more convenient than the classical "click a login link, which takes you to another page, try to remember your password, maybe hit I forgot and have to view your email, and then hope the site takes you back to the page you were originally on" flow. A big win is not having to leave the content you're currently viewing, which is an annoyance on mobile.
A lot of the comments on this thread strike me as cynical, and are dismissing the user experience aspect of something like this. Especially considering that the average user doesn't have a password manager (I could be wrong on this claim, I don't have a source ATM).
EDIT: I should clarify that I'm talking about the "quick sign in" pattern in general, not necessarily about any specific auth provider.
P.S. If you're trying to produce a similar flow on your site, the Credential Manager API (navigator.credentials) allows you save user credentials locally, so when they visit your site, their browser can automatically sign them in.
This reminds me of one time when I logged in to Chrome and misclicked on the dialog that asked whether to sync data. I very quickly went to settings and disabled sync, but I have a feeling Google got all my bookmarks and history and saved passwords.
That's what finally made me delete Chrome (I had already been using Firefox primarily but now have Falkon (WebKit-based KDE browser) instead of Chrome).
Very malicious how the option to keep your information to yourself is gated behind many opt-outs but if you accidentally opt-in once they take everything.
https://github.com/zapier/google-yolo-inline
But it seems the page for one tap - https://developers.google.com/identity/one-tap/web/ - is no longer a thing; the the only solution for "web" experiences is the "sign in/continue with google" javascript client that does the pop-up, eg. https://doodle.com/login.
IMO a website must ask for a permission before displaying this button.
Facebook also has a similar button ("Continue with {my_name}") that use the same iframe method.
Unless there's a security leak somewhere in cookies, which exposed your email address to this site (which doesn't belong to google i presume).
In the other hand, as a conscious consumer, I absolutely hate giving even more information to Google.
It would be cool to have an open source, non-profit organization to work as an universally accepted authentication provider platform. One can always dream.
I try to avoid using creepy websites like this.