Don't use third party auth to sign in
gurjeet.singh.im
gurjeet.singh.im
But how did we end up in this horrible state of authentication? Why don't we have something as easy to use as the DNS, but for authentication?
Imagine what authentication would look like, if we all started running is the same direction, instead of implementing our own authentication again and again. If we had something open source, that would allow you to sign in to all the sites you use, while completely protecting your privacy, so none of them know who you are.
This dream can come true. Technically at least. I've taken the the first baby steps with https://promiseauthentication.org which proves that this is possible.
But, for this to become a reality, we really need to start running in the same direction. A collective movement towards a sane, privacy-first Single Sign-On provider that's easy to use for everybody.
How does it prove that?
And it works.
It's a bold choice of words, I acknowledge that. And the proof is only as strong as my abilities to write software.
This is yet another reason why Promise needs a movement behind it. To strengthen the proof. To strengthen security.
Just like the DNS can block users, Promise can ban users and relying parties.
This is not something Promise should take lightly, but the fact that almost everyone has a say in Promise, unlike Google, where almost no one has a say, makes me full of hope that this can be solved in a transparent way.
What makes OIDC a "non starter"?
I see OIDC as an implementation detail, and have no strong opinions about it.
I think this would need serious widespread adoption until we saw benefits too. And you’d need some big names...like Google. Which probably will never happen.
I hate it, when I type my email and password (correct, that is), and get an error saying "You already have an account. You need to sign in". OK. But would you please just sign me in then. Everything you need is there.
So I chose to make it one. This might be more confusing than anything else... And I might be missing some other point for this to make more sense...
And yes, let's get that widespread adoption
Only problem is there aren't any password managers that implement it, so it's not actually practical to use as a primary authentication factor yet.
I see it this way, that Promise makes it possible for all its relying parties leverage WebAuthn by implementing it once, so they don't have to.
Aligns really well with using your own domain for email instead of gmail.
1. https://reclaim.gnunet.org/ 2. https://gnunet.org/en/gns.html
> Self-sovereign You manage your identities and attributes locally on your computer. No need to trust a third party service with your data.
Why do people assume that is a good thing? I do cybersecurity at work (among other things) and it takes a lot of effort to keep things both available and secure. My home PC, not to mention PCs of my friends, are never going to be as secure.
A system which has a chance will have to be federated, not local-only.
But then you should listen to the advice we're given if we use one for personal use.
1. buy two devices
2. Generate a phrase on one then import to the other
3. Put the second one in a safety deposit box in another city or state, or a safe with a family member also out of the city or state.
4. Keep a copy of the phrase on steel seed phrase tool (Steely, etc)
5. Mount the steel seed phrase backup inside of a wall of your house and plaster and paint over it.
6. If your phrase ever gets seen by any electronic means, it's compromised and the process must be redone (note that importing uses a randomly shuffled alphabet on the device to make MITM or keylogging attacks unusable).
So... Security is hard. We should build systems that make it easy. There should be ways to recover from backups of a service goes offline, but we can't expect everyone to make good decisions.
Not to mention having passwords synced between devices and available on demand is really a requirement of you use random passwords for every site and need to log into something (heaven forbid) on someone else's device.
These are in direct conflict with each other.
What's your threat?
Most people are not trying to stop a determined attacker. Most people just want random people to not get be able to get into their stuff--same as a physical lock.
They carry a physical key on their person. It's not too much to ask them to carry a "digital" key on their key ring.
The problem is that most "digital" keys are a pain in the ass:
1) Mostly because everybody wants to "centralize" authentication so that they can charge you and administrate you.
2) Secondarily because there is no good solution for talking to the key on your person. NFC sucks. USB requires that I plug my key in. WiFi requires that the device be able to hit your network. BLE has no access from web pages.
BLE is probably the best choice, but there is no real money in making it work.
There is no way around this... Security isn't a state, it s a process. It relies on the human to propagate it. A bit like a garden.
Make the process simple for the user (but not thoughtless) and that is about as good as is going to get.
> You will get a unique identity pr. service you use. This ensures that relying parties have no way to profile you across services.
For me, this is actually the biggest reason that I stopped using social sign-ins. It's not that Google might disable my account one day; it's more that I don't want Google or Facebook tracking me.
How does a decentralized system handle this? If my identity is my domain, doesn't that mean that all these websites now have a unique id which they can use to join together all their separate pieces of data about me?
Only by being pseudonymous can it provide the level of privacy that should be expected from the global authentication infrastructure that Promise wants to be.
It would be possible to not save the map, and then use some kind of hashing to infer user ids for each site. I chose not to do this, to be able to guarantee no collisions. This might be silly, though. But the thought of people with colliding user ids makes me giddy.
The data stored looks something like this: { "ids": { "example.com": { "07c5c163-875f-424c-a659-a4f99e74eb12": "default" }, "other-example.com": { "ab38b2a6-d560-43d3-b2a3-9148cd91d1b4": "default" } } }
Worth noting is, that there is no personally identifiable information (PII) here.
But we have to have the discussion if this is "too much" data to keep about a user. AFAIK this is the bare minimum of data needed, to be able to guarantee no collisions of user ids. If there is another way to do it, we should do that!
That said, the unique identity is still valuable--Apple offers this with their third party sign in[1]. Practically, if everyone was using self-hosted identity, then the tools would probably make it easy for you to create and track your own new identities for each service you use. This isn't build into something like IndieAuth today, but with the right DNS settings you could have arbitrary subdomains return the same authentication options and act as easy-to-use "sub identities".
On one hand, I want to tell you that Promise is only centralized by default. Which is good for people that doesn't understand what a OpenID/IndieAuth Provider is. But as Promise is open source and the protocol caters for it, it is possible to have Promise redirect authentication requests to your own instance. Which then redirects you back to the relying party you want to sign in to. So it is possible to decentralize if that is what you want
On the other hand, I'm not sure it's a good idea to do it. Centralizing gives a lot of benefits. User experienc being one, but also being able to roll out eg. security updates quickly. But sure, centralization also creates problems.
But until now, I have a feeling that the problems with centralization, can be solved by other measures than going decentralized. Eg. being a non-profit organisation owned by the relying parties. This would guard against a lot of the problems with being centralized.
And I'm still to encounter a decentralized solution with a reasonable user experience for most people. OpenID, IndieAuth, SQRL, re:claimID, I'm looking at you. Sorry.
The challenge with centralized is that it is a single point of failure. The original post was more focused on "If you get locked out of google, you get locked out of everything". In that vein if promise gets hacked/bought/abandoned/changes it's business model etc.. then you lose all your accounts. The anonymous nature of it is great, but this is something Apple already offers with their sign-in with apple which is already widely supported and with the proxy-email solution you can still be contacted by the sites you're signing up with.
I got interested in IndieAuth because of a project of mine[2], trying to make it really easy for everyone to self-host their facebook/twitter equivalent with direct control over who has access. This runs into the problem with wide adoption where you have a separate credential for each of your friends' blogs. With IndieAuth built into the self-hosted platform, then your own self-hosted site becomes the one credential you can use on all your friends' sites. Self-hosted distributed identity for privacy AND ease-of-use.
[1] https://wordpress.org/plugins/indieauth/ [2] You can find the link in other comments I've made on HN
I totally understand what makes IndieAuth is a good solution. And it seems really easy. For me. But I have no idea how I would go about explaining it to, let's say, my mom.
Apple is offering something very similar to what Promise does. The difference is that Apple is a commercial corporation. Which means they're in the game to make money. Promise will be in the game to make authentication easy, secure and private.
In many ways I compare the goal of Promise, with the goal of DNS. Take a commodity and make it available globally in a reliable way. Yes, it will be a single point of failure. So the job of Promise will in large be, to keep the platform secure and reliable.
Apple is a commercial corporation, and one of the biggest (by market cap) companies in the world. That gives me confidence that they'll be around for a long time, have sufficient resources to invest in security and reliability, and they have a well-established reputation for a focus on security. They do other things I don't like[1], but I think this is one area where they're setting really good precedent.
In addition, it's going to be difficult getting any sites (outside of maybe the crypto/grey-market) to adopt an auth system that doesn't let them contact their users. This is also I think a big failing of IndieAuth.
If a site needs to contact the user, it's reasonable to ask for eg. an email. But now the intent of asking for an email has to be crystal clear, which makes you and them more aware of what data you are actually giving them.
Apple sure is doing some good stuff with their authentication solution and their efforts to help people with healthier passwords habits. I'm still not too fond of having such fundamental infrastructure owned by a private company. Would you be comfortable handing over DNS to Apple?
What should be done when creating a new account is that, in addition to the username and password, the website should allow for uploading a certificate signing request. The web browser should then allow the user to create one and upload it. The website should then return the signed certificate to the client and the browser can then store it to use during subsequent connections.
Doing something like this would allow for two factor authentication without the half-baked solutions like sms or email based 2fa.
Your average user is not going to open a command prompt and dig into Openssl. There are (or were, I haven't used them for a decade) browser-specific APIs for generating private keys locally, but they were very flakey, and the whole UX was very confusing for users.
And after this, the user can only sign in on the machine in which the key was created. Your average user will not have a clue how to move certificates and keys around between machines.
I have direct experience with this. Back in 2008 I led a team building an extranet site, and we used X.509 client certificate authentication. We had to build our own tooling for management of the PKI, which was no small task. But ultimately it was key creation and certificate distribution that were the biggest problem - our users absolutely hated the signup process, as well as the fact that they couldn't later signin on another machine.
That's why I said that the browser should provide that feature.
> There are (or were, I haven't used them for a decade) browser-specific APIs for generating private keys locally, but they were very flakey, and the whole UX was very confusing for users.
That's a UX issue that can be solved if the time was put into it
> And after this, the user can only sign in on the machine in which the key was created. Your average user will not have a clue how to move certificates and keys around between machines.
They shouldn't be moving/sharing keys between machines at all. What could be done is to implement a mechanism to associate an additional device with the account. Perhaps something like sending a CSR from the new device and then using the first device to confirm that it's a legitimate request.
So I can only sign into my account from any new machine if I have access to a previously-signed-in device? What happens if my last login session expires? At that point, I have to sign in with a password, and now I'm back to all the terrible things about managing 500 passwords.
Federated identity / SSO through a trusted provider makes so much more sense, the standards are open and there are dozens of implementations available. Nobody needs to reinvent the wheel, we don't need a 15th standard. You just have to sign in with a provider that you trust not to lock you out for no reason, in a way that gives you no recourse (unless you can get your story on the front page of HN). Obviously that provider is not Google.
The scenario I'm envisioning is that one creates an account on a website like HN, but with the additional step of generating a CSR, sending it, and receiving a certificate to store locally (with the browser handling the generation of the CSR and storing the resulting certificate with a standard and easy to understand UX workflow).
Once signed into the account, the website could prompt the user to add additional devices if they so wish (e.g., I created the account and signed in on my laptop, now I'll add my smartphone as a trusted device). This step could be done now, or sometime in the future.
If the prompt encourages users to do so right after creating the account, it's likely that they'll have access to the original device to confirm additional CSRs. Even if they choose not to do so right away, I don't think it's an unreasonable requirement to have access to the original device.
> What happens if my last login session expires? At that point, I have to sign in with a password, and now I'm back to all the terrible things about managing 500 passwords.
If the situation was that websites used 2FA via having the username/password as one factor and client-side TLS as the second factor, then password reuse wouldn't be an issue. Even if someone were to guess the username/password combination, the most they could do is send junk CSRs to try to add their device, which can then get rejected or not acknowledged by the original account holder.
> Federated identity / SSO through a trusted provider makes so much more sense
Perhaps, but based on what I've seen for general services out there, they just use either Google and/or Facebook as the trusted provider. I'm not sure how that situation came about, because it was pretty easy to create multiple accounts on those services without having to provide any basic identifying information (which essentially is the antithesis of what should be considered a trusted provider).
SSL/TLS is a standard that has been around for a long time, and given the ubiquitous use of server-side TLS, I don't see why it would be considered re-inventing the wheel to use the client side part of it. With nginx, you could set a HTTP header with proxy_set_header based on the value of the $ssl_client_verify variable value. Then the application could direct the user to the login page. If the client-cert is valid, then allow them to log in normally. If not, then direct them to log in, send a CSR, and go back to a valid device to confirm that CSR.
> You just have to sign in with a provider that you trust not to lock you out for no reason, in a way that gives you no recourse (unless you can get your story on the front page of HN). Obviously that provider is not Google.
Personally, I think we shouldn't have to involve third party providers in the authentication process. One reason is what you've already mentioned about getting locked out of the account. The second is if that account is compromised. With TLS, you don't need a third party involved in the process at all for the client side.
I just find it disappointing that I'm essentially forced to use email or SMS based 2FA where, arguably, those are less secure compared to having a strong password on the original service. By less secure, I mean that those factors could be compromised in a way to access my account that completely bypasses my strong password. It's the same with requiring security questions and allowing access to the account via a well known answer to one or more of those questions.
It's not exactly a SSO, though.
But most of all, what I'm missing is at least one good option on the sign-in screen. And using a password manager is not it.
Internet identity could maybe be a layered thing where one layer takes care of authentication, which is where Promise lives. The next layer could handle information like name and email. And finally a layer that handles your verified identity by an authority. That last layer is where the danish NemID fits in.
Be aware that doing this now means your DNS provider and domain registrar become vectors for hackers to take over your email account, so make sure these are companies your trust and your access to these accounts is as secure as possible (ie strong unique passwords and app-based, not SMS-based two-factor authentication)
You can export all your email in a single .mbox file.
This might not work if your account is suspended, but if you set up email forwarding to an alternative address (e.g. to protonmail) that might still stay active so you can transition your addresses.
It also depends on the reason for the block - if for example they suspect you of having illegal content (child porn) in your Gmail, you aren't allowed to takeout it.
A balancing of rights exercise would need to be conducted by the controller to balance your right of access your personal data as against the identified risk to the third party that may be brought about by the disclosure of the information. The GDPR notes that these considerations should not result simply in a refusal to provide all relevant information, but the controller should endeavour to comply with the request insofar as possible whilst also ensuring adequate protection for the rights and freedoms of others.
I have very little hope indeed that they will let you do a takeout without finding a human to talk to when your account is locked.
For what it's worth, Facebook does let you do this. You login, get a message your account was banned for no apparent reason, and that you can download a copy of your data. Unfortunately it's broken (screenshot: https://dro.pm/a.png) but hey, there was an attempt.
I like GMail for their spam filtering power, and I honestly believe spam to be email's biggest weakness, and the reason people don't host their own. It certainly scares me, the thought of being flooded with thousands of spam emails daily, or the chance that my own emails would be falsely marked as spam since I'm not part of the major providers or because I did not configure it correctly. Don't know how this can be solved though, email itself is too permissive, and too "tweakable".
With your own Linux instance, you can host whatever you want, have full control, can host other services too like www, git, whatever, and have the assurance that you're not going to suddenly lose access because AI-BOT-204432 decided you violated some obscure terms of service. I've been doing this for close to a decade now (exim + dovecot for E-mail), and it works great. Back in the 90's, this used to be the default. How did we end up in this world where we so utterly rely on 3rd parties for such everyday critical Internet services?
The same way we ended up in a world where we so utterly rely on 3rd parties for such everyday critical services as growing our food and fixing our cars. There's too many things to do for everyone to do them all on their own.
For email? Because Google and Microsoft broke SMTP federation in the name of "anti-spam".
It's practically impossible to get Google, especially, to reliably deliver your email anymore if you aren't an actual email service provider.
* The admin-user.
* The daily/real-user.
In my case I have my real account "steve@steve..", and "admin@steve" which is the gsuite administrator. I only login to make changes to the domain setup, never to send/receive email.
It's annoying to have to pay for that second user, but I feel happier with the privilege separation in place.
I guess I should have started using forname@surname.tld to make it all nice and neat, but I've no desire to change now.
https://support.google.com/cloudidentity/answer/7384506?hl=e...
Edit: nevermind. I see you own the .net tld. I've definitely used that to order pizza too. Sorry about that.
Although very occasionally a service will check for MX records, but that is incredibly uncommon. My go-to email for public WiFi is fuckoff@exmaple.com and have only been denied once (<1%)
A fair number of places will deny that, but I like to think it sends a message. I'm not sure how many, if any, domains still have a working webmaster@ address though.
(I moved from UK to Finland, so I checked the .fi version on a whim. Luckily it was due to expire a few months after I checked, so I setup a script to register it the moment it became available.)
$1,200 is a lot of money, but... anyone aged 23+ is older than Google. 17+ is older than GMail.
It is an illusion to say we know what will or will not happen to Google over the next 20 years. We don't know how entrenched the tech giants are over decades because we've never had anything like them before.
This is a problem that is obviously not going to happen in the next 12 months. But if a person don't control their email address, they shouldn't be using it for anything that it would really hurt to lose.
Realistically we have little control or have any clue on what's going to happen a few years out in almost every aspect of life.
Look at Kodak (the photography company). They were around for over a 100 years, then digital photography came along to disrupt their market and they pretty much disappeared in a few months.
Kodak and Google aren't that different as being a company that offers a service that tons of folks use(d). Kodak used to be "the" place to buy film and get photos developed.
I'm all for controlling your own email (even tho I'm guilty of not doing so), but I think even if you controlled your own email, you'll still be victim of the company you're using maybe going out of business in the future. I wish nothing but success for Fastmail or any other email service that lets you control your email, but if they go down then you're in the same position as Google going down while using gmail.
Kodak was well aware of digital photography, arguably one of its pioneers. What killed Kodak was cellphones. Kodak was too dependent and attached to making cameras and camera-related equipment. Most people did not need separate cameras once cellphones came along (even the 'dumb' models have a camera), so Kodak had nothing relevant to sell... Doubtful Google could be so stupid. Maybe if the Feds separate gmail from Search there'll be problems?
>I wish nothing but success for Fastmail or any other email service that lets you control your email, but if they go down then you're in the same position as Google going down while using gmail.
Keeping all your mails locally is not difficult if you use a mail client rather than a web client. Copying to a local folder every once in a while is a one/two click operation in typical clients.
I had an incident a few weeks ago, where my mailbox lost about 1 weeks worth of messages, and were not retrievable.
I have used them for over 5 years, and this is the only negative incident.
https://sneak.berlin/20201029/stop-emailing-like-a-rube/
It even has special instructions about how to secure the domain registration and DNS accounts. :)
(Don't use G Suite, though.)
And indeed, your site does have a RSS feed, so what's with the e-mail address collecting? Rude!
But why referring to Protonmail and using Fastmail for yourself?
The fact that FastMail might be subject to the new Australian crypto key escrow law[1] is a little bit worrisome, and I may not continue to use them in the future depending on how that plays out.
For things where surveillance is less of an issue, I prefer being able to use a plain IMAP client, which ProtonMail does not support. Their current iOS client is pretty lame, for example (although their web client is better, and I understand that their next major release will improve things a lot across the board). I mention the IMAP issue in the article.
[1]: https://parlinfo.aph.gov.au/parlInfo/download/legislation/bi...
FM is saying it doesn’t affect them, as they are not a secure provider and can already give any information out upon lawful requests.
Do you disagree with that?
That in short, the A&A bill is about breaking end-to-end encryption, which Fastmail has never had anything to do with. It’s scary-sounding legislation, and I reckon it’s misguided at best, but it honestly doesn’t affect all that many businesses [note I’m saying businesses rather than people; many affected businesses will be among the largest ones, serving consumers], because end-to-end encryption of communications is uncommon, because it’s so frightfully inconvenient for all parties involved, because now the server is necessarily dumb and the client has to do a lot more work, and things like searching are typically just altogether broken because you’ll need the full index on the client to do a search.
(And specifically of the domain of email, I wouldn’t trust first-party encryption; if you care about governments accessing your data, first-party encryption such as ProtonMail offers is almost equivalent to no encryption if you can’t verify the code that is running, since that party may be compelled to backdoor the code to steal your password. This is one of the many reasons that Fastmail has never implemented PGP, ⅌ https://fastmail.blog/2016/12/10/why-we-dont-offer-pgp/.)
So your advice would be to go with Protonmail all the way, as you wrote it within your blog?
If you found it valuable, you should submit it yourself. I'm not interested in the accumulation of updoots, feel free to get 'em. :)
I'd rather other people decide what subset of my writing is relevant to HN, as I'm no good at it: I'm too close to the work. (I only write about things I care a lot about.)
But the article is very well written and would be a shame if we didn't got other opinions here in HN, kudos for you, already added it to Pocket for later
Will try to get it rolling then
1) the front, if you so will - the emails which you give out and to which people (or algos) send you stuff
2) the back, where you receive and read your emails.
For many people, for example:
1) abc@gmail.com
2) gmail.com web mailer, or gmail app on mobile, or native OS app on the computer
You suggest a complete revamp:
1) catchall at own domain: anything@mydomain.com
2) one (or several) protonmail/fastmail accounts
But it's worth highlighting that people can get many benefits already by
1) catchall at own domain: anything@mydomain.com (as you explained)
2) keep whatever you're using now.
Just forward 1) to 2). Then you can start handing out the new email.
But for someone like me, if I take all this advice, there is still the aspect of trusting the domain registrar, maintaining a personal email server, hosting, CloudFlare, etc. etc. I have just shifted some risk of offending Google to some other risks of 3x more companies that I have to remember how to deal with now.
So what difference does it mean to me, average user, that I just stick with Google and don't misbehave, versus open myself up to having to deal with 3 other manual processes and companies to remember? It's turtles all the way down.
You see the dilemma for the average user.
Of course if you are worried about some nation state looking into your emails you should encrypt them and use whatever provider.
I don't know your personal circumstances of course, different people may very reasonably make different calculations. But I have more trust in a quality registrar and my bank then in Google under the most likely scenarios where I'd still care (long comas aren't impossible to come out of, even multi-year, but chances of just partial recovery plummet after even a month or two let alone full recovery). I think Google being capricious or making a mistake is a bigger concern, if only because there is almost zero chance of recovering from it (basically have to know a well placed Googler or manage to go viral or be a big enough presence to get their attention). Domains and finance in contrast are both full of competition and portability.
Obviously their sign-in/account infrastructure creates technical impediments against making their products do what they want. They should really fix that.
That's not to say you're wrong, but it would be a turnaround at this point.
i will add that it's possible to create a google account WITHOUT gmail,
https://support.google.com/accounts/answer/27441?hl=en
maybe that's sufficient for nest.
Hopefully signing my address up that way, when it's already a domain account, won't b0rk all sorts of other things :/
[1]: https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
How does that work when using an email client and connecting to the server and using SMTP and IMAP?
Pick a service that lets you use a long password and a security key (like Yubikey) or authenticator (Google, Authy) to log in.
Most services will then let you generate a specific password for an email client. I would assume that behind the scenes that the service is restricting what ports that password can be used on, etc.
Assuming it's a device accessing the service over IMAP and SMTP that can access multiple networks, restricting by IP and/or port won't really help. As I noted in my other reply, it's easy enough to script access to the account if have the password and there's no real association between the application and the credentials that are used for access.
I'm not aware of two-factor authentication for SMTP or IMAP.
This could be achieved using a client side TLS certificate along with a username and password. I know that Postfix and Dovecot support it.
It seems like things should be more granular, such that being banned on YouTube doesn't make your thermostat quit working, ruin your phone contacts/photos/etc, or cut you off from your unspent AdWords funds.
"Google + Sidewalk: bring the dystopia of robo-support to the civil service!"
Or maybe
"Google + Sidewalk: Snowcrash was the blueprint, right?"
With OpenID, basically everyone used a third party ID provider, and so you were just as dependent on that provider as with OAuth. Did you actually self host OpenID? If so, that’s a lot to ask of each person in the world. If you didn’t self host OpenID, I don’t think you had much “control of your online credentials or identity.”
If OAuth was never meant for signing in, then putting Auth in the name was a funny choice. You add the qualifier “websites who just want your mail or something”, but I’ve never seen a single mailing list sign up that used OAuth.
You could pay someone to host it with reasonable guarantees they won't delete your account on a whim and no recourse.
Or you can use a free service that you somewhat trust with your own domain, so you can point the domain to another provider if you need to. Almost no technical knowledge required for that.
> If you didn’t self host OpenID, I don’t think you had much “control of your online credentials or identity.”
Same for email, which is what identity relies on instead of OpenID.
And self-hosting OpenID is much easier than email: you just need domain + LAMP (or equivalent), and don't have to deal with DKIM, SPF, being blacklisted from Gmail/Hotmail, ...
Each user having to find a hosting provider and pay them... it seems like a non-starter. Think about the non-technical people in your life. That solution would only help the very few people who both understand the details of OpenID, and care about the possibility of losing account access at a deep level. Most people have other important stuff going on in life, so good luck convincing them to adopt self-hosted OpenID at greater cost (and effort) to themselves.
This is even assuming that the hosting provider also acts as a domain registrar so each person doesn’t also have to figure out how to buy and own a domain name, to truly own their OpenID, because that would either make this solution much less meaningful in terms of control (with no custom domain), or make it that much harder.
> Same for email, which is what identity relies on instead of OpenID.
I’m not here to argue for self hosted email. There are many email hosting providers that make it relatively easy for you to bring your own domain name... but this is irrelevant. Signing in with an email and password continues to work even if the email account has been suspended. So, it’s not the existential threat that the article is concerned about.
I think the more realistic solution for users is the new FIDO2 standard that will hopefully see adoption soon.
I think Google has done a similar thing on Android, but Apple has for sure made every (up to date) iPhone, iPad, and Mac able to act as a FIDO2 Platform Authenticator.
Even if the user signs up via OAUTH, websites can give the user the choice to sign in via FIDO2 on each device. At that point, users could sign in from those devices even if their Google account were suspended, giving the website a chance to help the user migrate their account authentication.
The FIDO2 flows seem very user friendly, but... the standard is so new, broad adoption remains to be seen.
While it's easy to blame big technology companies for the failure of open standards, there might be other reasons behind it (as well as companies trying to prevent it from succeeding)
Why would anyone bother with that hassle when you can just put in your email address (that you already have & know) and a password.
In contrast, OAuth succeeded because most people already have a Facebook / Gmail / Github account, which meant that sign up just becomes clicking a single button which is easier than email signup.
OpenID was more difficult than email signup, whereas OAuth is easier.
Accepting any domain as an OpenID IdP is not likely to be a feature of publicly facing sites, as they still provide the ability to create / register / use these accounts for spam and other unwanted abusive purposes.
Neither Google, Facebook nor any of the other major Internet sites where ever going to allow you to authenticate using a 3rd party.
Adoption was negligible so they eventually killed it.
If successful, this would impose a cost to Google for shutting down accounts capriciously and incentivize them to do better.
This would be a challenging lawsuit to win. You’d probably need support from an organization like EFF to manage it.
At one point I was signed up in over 300 places using my Google account. Eventually the thought occurred to me, "what happens if I get locked out of this account?" And I don't really mean shutting it down. I lost a Microsoft account with over $3000 worth of purchases and 10 years of history, because I lost access to the recovery email address it used. So since then I've made sure to "spread the risk" so to speak.
Through 2 years of effort it is now only a handful. Some of them remain because either a) there's no other way to sign up or b) there's no way to convert it to an email based account.
But still - that's 2 years. 2 years of weekly, sometimes daily, moving yet another thing off that login (but it still uses the email! that's the next step -- kill the email).
The level of effort has been gargantuan. For some people, it would simply never ever happen. To lose a Google account would not only be damaging, it would be like your entire life being erased.
The level of damage here is enormous and Google has to take responsibility for the power it has amassed.
If they want to terminate all free accounts, it'd be a wonderful thing. Either people would finally be free of the behemoth, or Google's incentives would change to finally care about users (well.... hopefully).
PS: I did not do anything wrong but still suffered lot of psychological pain due to this mistake by Amazon's internal security.
I suppose you, as a site operator, are doing all you can do, though.
We saw this recently with "Sign in with Apple" and Epic Games, where Apple denied access to Epic and the accounts that did not share their actual email were effectively lost.
https://www.epicgames.com/help/en-US/epic-accounts-c74/conne...
> Apple previously stated they would terminate “Sign In with Apple” support for Epic Games accounts after September 11, 2020, but today provided an indefinite extension.
They probably put a human to communicate with you, verify some identity and then give you access to your servers again, I'm sure?
Compare that with Google (and Facebook, those are the two I have experience with) who will simply lock you out of your account and if you ask for help, they say they cannot. "But what about the three years of photos I've stored?" I asked. "They have now been deleted since your account was terminated" they told me. "Why?" "We cannot tell you".
I think the conclusion of the article is flawed. I think the risk of getting locked out is far lower than the odds of any single, or even all of, other (non-major tech co) website you might join getting breached. It's fair to argue the impact might be less also - and I'm happy to have this debate.
In my experience, typical users aren't the ones that get their google accounts banned - they are always banned for doing something significantly more sophisticated.
Yes, I need to move away from gmail...
If Google can, without due process and fair warning, remove your existence then this is a power that should be delegated to the relevant authority, namely the "justice" system to make such considerations.
If your house could be removed at a whim because a bot decided you were a bad person it would likely cause an uproar, it wouldn't be tolerated.
Yet here it is. Google can offer their services and the legal system seemingly doesn't want to be involved.
Why?
The de facto monopoly of most of these players exists in their cross-border market share, making enforcement under traditional antitrust law in any one country difficult.
Unfortunately, it's also something of an international zero sum game due to efficiences of scale -- if the US breaks up Amazon, Alibaba gains world market share, and we're back in the same place.
The most effective remedy I can think of offhand is government involvement in a special, independent branch of the company, dedicated to increasing interoperability and exposing services, empowered by legislation.
If we're going to have monopolies, at least they can be open ones. E.g. 18F + Google Takeout, backed up by regulation
At every point, google users are asked to acknowledge the EULA and TOS. They're being told that google can stop their service for any reason, including that service not being comercially viable. ( I.E. Any Reason )
Access to google services isn't a right. It never was, unlike the property rights you're drawing a false equivalency with.
This pandemic has been reliant on emails to access services; it's how I get my payslips, talk to my employer, get current information, engage with legal services, and essentially maintain my access to society.
Losing my emails would be devastating (hence why I don't use a "major" provider, at least less risk that way).
We need to define what "rights" are and weigh that interest in society. If Google wants to be a "one stop shop" it cannot, and must not, be immune to laws and the rights of individuals to challenge decisions.
Isn't that the foundation of a society?
I have a google account to test my devices / emulators. Never logged in gmail with that account, never will. If they cut it off, I can make another.
Same with Apple. I have an Apple free ID for running virtual machines with MacOS / iOS and that's all. I tell my customers to create their own Apple ID and I deliver them the sources + dev environment and they make their own binaries and publish on Apple store. My job is done once I make the app run on emulators and I tell them from the start of the project this.
I have a FB account to talk on FB mess with parents from school and that's all. I don't even have them as friends there, I am just in 3 lists and that's all.
Also i use protonmail currently as I've started migrating from yahoo 2 years ago (old e-mails still there, I open that e-mail like once per month).
Do the same, you'll be free. Also you can use an e-mail account outside of google domain to actually create a google account, if you really need one.
This was to work on an API integration.
It absolutely is a problem for a large amount of people.
> Do the same, you'll be free
The vast majority of people in the world are not taking the same actions as you are. Therefore this is a large problem for many many people.
Better education for how digital services work and how to properly handle your digital identity is the right way to handle this. Implementing regulation and cementing the "major" e-mail providers who have the resources to comply will only deepen people's dependence on these corporations.
Do I have 15 emails addresses with 15 different providers? When a form asks for my email address I can only give one, what happens if that provider goes away?
What if a government doesn't like $provider and seizes the business? Now I can't get a reset link/change my password/prove my identity...Many government online services ask for your email these days, so you don't really have much control over that. If you said I am joe@blogs.com and blogs.com dies, you're toast.
Please do explain.
If your email provider goes away, you're screwed. Nobody accounts for this situation. Doubly so when you used an identity provider that has gone bust. The question is, how do YOU imagine imposing regulations on mail providers will change anything in a case like this?
Store your credentials, make backups of your emails, don't use identity systems. If things really do go bust, you'll retain access until you can get manual changes made to your accounts.
The other obvious solution is to have identity/e-mail built-in as part of citizenship and be gauranteed by your government.
If you want to solve this problem you have to spend some money somewhere otherwise you are simply demanding providers give you services, for free, forever, not something that seems realistic?
In the worst case scenario you'd have time to setup a new domain and move everything over. Annoying yes, but again extraordinarily rare.
As email's importance approaches a utility like physical postal service it's reasonable to expect some regulation. So long as the regulation is independently developed and balances the needs of consumers and producers then it shouldn't be too burdensome for competition to exist.
In the worst case taxes could pay out to whichever provider one chooses.
(Roughly. I am not a lawyer.)
Less likely here, given the somewhat unexplored territory, but still, the history of class-action litigation evolution is largely of lawyers/firms taking a chance such as this.
I think the overall point here is to have the support of law that says they DO have a duty to you, by benefit of their hosting your account and authenticating you elsewhere.
Then, WHEN someone goes to sue them, the person has much stronger legs in court rather than lone Peggy Sue trying to defeat Google's 300-strong team of lawyers who exist just to eat little guys for breakfast.
So yes, right now we've woken up in a world that is not so much cyberpunk as it is techno-feudalism: more and more do you need a presence on the Internet to do things in meatspace... And that presence is by the grace of several feudal lords (Google foremost) - woe betide you should you ever displease them. You do not really own your email adres, your phone (number) or (pretty soon) even your computer. You're merely a serf.
On the plus side, the momentum for legal measurements seems to be increasing. Let's hope they do get broken up. Power, like plutonium, is dangerous if too concentrated. Regardless of where that concentration lies.
I view my digital purchases as things I am forever renting.
Movies/Music/Books can be displayed and played back on damn near anything. Games, especially modern games, exist in both a variable state (constantly revised/updated), but also with a much more limited ability to access the content.
That experience forever turned me off to relying on digital-only.
To your points, having a PSN account is necessary but I can always create a new one if need be.
Whenever possible, I prioritize non-DRM media for purchase.
I don’t think they’re really interested in that, since the accounts are almost by definition making them a bunch of money.
If you think about it, this shouldn't be all that surprising - after all, this is exactly how intuition works, and the human mind runs very much on intuition, people just don't realize it (at the object level).
Not that that's Nintendo's fault but I think something like this will be the fate of every account that's not used, closed or deleted for a long time and owning your data and software possessions would protect against it.
So, not an Amazon account ban, but you quickly learn you are not "buying" a movie, but renting it, sometimes with silly restrictions like "only from these IPs".
In general, I think that's also a point we can draw from the cyberpunk genre, or maybe from Harry Harrison's old-school prefiguration of it in the Stainless Steel Rat series - the eponymous creature being one well suited to thrive "within the walls" of a society increasingly sclerotized with technocratic bureaucracy, but perhaps equally suited to a life of gnawing through the circumscriptions imposed by competing technofeudalist fiefdoms.
But in every society a small circle of privileged people have always been the norm and despite more wider access to information today it seems like consolidation of power and wealth seems to be trending upward.
—
I run my own mail server but my VPS provider could be coerced to yank it from me. You’ve made me uncomfortable with revelations. Damn, we’re fucked.
[] Every person's thinking and writing is mostly just a pastiche stitched together of thoughts they heard or read from others anyway. (And this is, of course, the meme idea, which is not an original idea itself either)
I've got two comments on this.
Firstly, you're already doing much better than most people. Make frequent backups, and if it comes down to it, you can always point DNS at a new provider.
Second, don't put anything on a VPS that you aren't willing to let the VPS provider or whatever Gov. has jurisdiction access. Where email falls on that spectrum for you is of course your own decision.
But even a little plutonium is too dangerous to let my kid play with it.
Email? Not quite as much.
We need to treat companies that put themselves into a position like utilities as utilities. Give individuals actual transparency of why actions where taken, and an ability to appeal these decisions with transparency.
It will cost more, but that is ok. What we have now is that the actions have caused real harm and the companies are unwilling to justify them. That's an abuse that needs to be removed through law.
The hard slap they got from the government was enough to apparently permanently change the company culture around treatment of users and other businesses.
I see a lot of the excesses we see coming out of Google, Twitter, FB, to be a consequence of there being, well, zero consequences for their behavior. They're like petulant children who never learned limits and think it's ok to do whatever they want, no matter who they hurt. That's exactly how you teach children -- give them limits. Ironically, the same rule applies to adults.
Google fills the gap.
This political model is dated. Republicans are no longer conservative. And Democrats have an ascendant progressive wing that rejects corporate influence wholesale.
Who mostly organise and communicate on giant social media platforms, who they campaign to fact-check things. Not exactly wholesale rejection.
The real question is why do people use Google to sign in to other services? It never even crossed my mind no matter how long I have had a Google account.
It’s also trivial to have passwords which are secure and easy to remember (literally off the top of my head): MyD0gb@rk$...
The stakes are quite high for losing access to your primary email.
If you are using a free e-mail service ran buy one the worlds largest and most powerful marketing companies as the identity / auth provider for your critical services and applications you should seriously reconsider your choice.
To paraphrase your comment: I'm honestly not sure where we went so wrong as a society so as to reach a point that we get mad when a service we do not pay for, ran by a selfish company decides to shutdown our access.
Edit: The point is that it is usually in companies own interest that we don't create laws restricting them, so they typically don't act too amoral. You wont find many companies which goes after every single legal loophole they can abuse, as negative public sentiment builds up laws will form and the company will be much worse off than if they just did the slightly less amoral thing.
The answer is actually very simple: spam.
AFAIK pretty much all disabled Google accounts come from Google believing they are part of a spam-sending (or malware-spreading) network.
The ability to sign up for free Google accounts means this is a prime target for spammers to use and abuse -- signing up for free Gmail/Drive accounts, as well as using stolen credit cars to sign up for paid ones.
As to why the legal system doesn't want to be involved, it's because incorrectly disabled Google accounts are actually incredibly rare -- they make the news and cause uproar when they occur, but precisely because it's so unusual -- it's incredibly rare to personally know someone it happened to. So there isn't any kind of democratic movement against it because in the grand scheme of things it isn't common. It's like worrying about being struck by lightning.
That's why.
If lightning strikes there is not much to be done. Google however can and must have reasonable process to restore the status.
I'd suggest its because its hard to prove or prosecute. Because its technical and obscure. A single case, Google just has to say "Oh sorry; its turned back on". There's no money in them capitulating. And a class-action suit enters into the details of the issue, which are impenetrable to a judge?
The ones that make the news are people that are either well known, or have and active way to promote their problems through social media or news site
I.e they are reporters, know a reporter, dev of a popular app, etc etc etc
They are Jane/John Doe that has less than 50 twitter followers and a normal every day uninteresting person, for which there is no recourse at all not even social media
Or they rarely make the news because they're so common, and the few that get publicised are because the victim raises a big stink on social media.
I've certainly created Twitter and Microsoft accounts and had them wrongly disabled within days, despite not doing anything at all with them, let alone anything abusive. Perhaps because I decline to use my cell phone number for 2FA?
That's because that's also a common tactic used by spammers -- to register and then do nothing for days/months, on the hopes that an "older" account will be less suspicious.
Nobody's complaining about that though because it's not a problem. No data is lost. Also, I've had it happen to myself (with Twitter) and it was incredibly easy to re-instate.
To clarify, I was referring to legitimate, in-use (with data to lose) accounts being incorrectly disabled.
I don't know anyone who has a degree in History but that doesn't mean historians are especially unusual. All it means is that my network is quite small.
The same is true here. The fact few people know someone who has been affected by this problem doesn't mean the problem is unusual. It just means there are hundreds of millions of people who use Google and you know a few thousand at most.
So... incredibly rare, really.
The extremely large majority of people go on to work regular jobs that have nothing to do with their degree and lose much of the information they learned, if it was even substantial at all.
That approach: “proof of human work.” Google owns ReCAPTCHA, and every time you do a ReCAPTCHA for Google, you’re doing a little one-time proof-of-humanity for them. But it’s also a proof-of-work; and proofs-of-work that cannot be automated are aggregatable.
In other words, the fact that someone with Google account X solved a ReCAPTCHA, doesn’t just tell you something about who that account is lately. It should add to a sort of “human-proof credit score” for the account, where Google’s systems are more willing to put faith in the user because of all the times they’ve proven themselves human already.
And, for some scenarios, Google does use the aggregate proof ReCAPTCHA represents this way. This is why you’ll never see the Google Search “stop searching so fast” message when accessing Search through Chrome synced to a well-used Google account; why you’ll get a ReCAPTCHA portal from them instead if you’re not logged in (you’re being asked to build the credit score of your IP/session); and why you’ll be denied upfront if you perform botlike behavior through Tor (where there’s nothing that can be correlated to give you a persistent credit score.)
Now, such a “highly-proven” Google account could still be heuristically detected elsewhere in Google’s systems as being responsible for botlike behavior (e.g. spamming); but, when such a highly-proven account is flagged, it should go in for manual review. Because — as you say — this is incredibly rare! So this process doesn’t need to scale through automation, the way regular Google processes do. It can be high-touch.
But right now, it’s not. (Or they’re just not even using the high-proof-of-humanity metadata on the account during this determination.) Either way, that’s kind of silly.
Plus that email/account is hardly even "yours" in a serious way. Anyone on the HN has a very simple fix for all these problems: get an email in your domain and a password manager for all the accounts. There, solved. You could even still use Gmail with their Google Apps, G Suite, Workplace or whatever it's called this month.
Normies are way out of luck but sadly that is true almost everywhere and they are getting fleeced much worse by banks, employers, and even cable companies than Google ever could hope.
If someone owned a vast amount of land, more than needed for everyone on earth to build a house, and the owner told people they could freely build structures but you lose it if you break the rules and the rules can change any time...
On the technical side, one hears about individuals' domains being marked (blamelessly) as possible-spammers by the big e-mail services, and finding it hard to get messages through. There is effectively some scarcity in legible, desirable gmail addresses.
Maybe it has hurt me somehow but...I wouldn’t want to work somewhere that would hold my email domain against me
If you cant pay your rent because no customer can reach you anymore or loose trust in you (because you don't answer) your house is gone shorter than you think.
Seems like there's an opportunity there though. If someone could create a platform that would take your address, create you a custom domain, set it up, get your email flowing there (including porting over all your existing email out of gmail), and then helping you move your sign ins to that new address..
That'd be huge. It would also be very, very hard, the amount of infrastructure it would touch.. but doable.
As with all things, Education is where we went wrong as a society.
in this case failing to teach people fully that there is no Free Lunch, and if you are getting something no cost to you, then you are no longer the customer, who ever is paying for the good or service is the customer (people should also pay attention to this truism in other area's of life)
In the case of google, you are the product, you are being sold to advertisers, google gives you a very very very small piece of that revenue in the form of a "free service"
I’m not saying it’s an unworthy cause to advocate a change but I’m just not seeing the moral weight compared to factory farming, and other hard industries that have an effect on societies and the planet.
Email ends up being the form of online identity for a lot of people, myself included, so that almost every service that I sign for has my email address as ID. If that email address isn't the ID, it's the preferred way of resetting passwords. I wouldn't be super happy about Facebook being my online ID, nor my cell phone number (see SIM swapping problems).
It's life changing in the same way that losing all your personal documents in a fire sets you up accounting nightmares. Moreover, you're making very light a situation about losing all your pictures. I'm not talking about food pictures, but there's plenty of "me" that's contained in being able to look at pictures of important events of my life (which is why I don't rely only on cloud backups for that).
I don't know what's "life changing" to you, then.
Should I diversify? Probably, but that's more things to secure and keep track of.
When I got started programming full time, tons of people in the software industry were getting their rocks off on how simple it is to install an Oauth library, making it easy as pie for people to sign in to a web service, thus encouraging more sign ups and making more money.
Maybe we've forgotten just how much of a hard-on we and the entire world once had for the likes of Google. 8 years ago, we would have trusted Google with our entire future. Politicians were on board, too, and have made many deals with Silicon Valley which ended up giving these firms a certain level of immunity.
We're all guilty.
Never in my life did I see an Oauth libruary and think this is easy as pie. Overcomplicated perhaps.
... you have clearly not understood that you should not have trusted them in the first place.
Yes, I have a Google account myself, but I try to use it as little as possible. My main reason for using it is the Play Store and I agree that it is unjust, that Google can remove my access to products I have paid for without really justifying for it in the sense of most people.
So I agree that something should be done. I think the line should be where paid services are offered. So if you just use a free service, Google(or any Company) should be able to stop providing you with that service whenever they like (while still providing you with access to the data you have generated or used with the service).
However, as soon as they have charged you, they should be forced to pay you back the whole amount (or offer some other kind of mediation that is more meaningful than receiving answers like 'Computer says no').
It can.
it would likely cause an uproar,
It doesn’t.
it wouldn't be tolerated.
It is.
Big fat article in the New York Times some months ago about AI deciding that landlords shouldn’t rent to certain people, and the AI often being wrong. Very wrong. Like tagging someone as a convicted drug dealer, when the reality is that person has never been in trouble with the law, and never been to the state where the alleged offense supposedly happened.
We have to stop calling this “artificial intelligence,” because it simply is not intelligent. Humans put faith in machines because were told they are intelligent. But all the evidence shows that at best “AI” is good at guessing.
If we started calling these “artificial guessing” systems, people would treat them appropriately. But that doesn’t buy investors a boat.
You can get also locked out of your phone
You can get also locked out of the email that you actually use for signing in because you can never remember the password and they stupidly ask you to change it every 6 months with bizarre constraints
You can get locked out of your password manager
You can get hijacked
The business you're signing into can go under
The odds of these things happening are to be weighted against each other
Yes you shouldn't use third-party sign-in for the bank account that holds all your money (though most consumer bank 2-factor authentication mechanisms, sadly, rely on third parties such as phone and email provider)
Yes it's also ok to use third party sign-in for the odd website that you don't care about which somehow insists on asking you to create an account
There are no absolutes in security risk management </>
Mmmmm not quite -- they have to be weighed against the consequences if they happen. For people who have had a Gmail account for over a decade (almost 2), they've probably got most of their life connected to it -- losing the account then is tantamount to a huge chunk of your life being erased. Photos. Conversations. Access to dozens or hundreds of other websites.
Basically all that'd be left is your physical ID, your bank account and you get to start over from scratch.
And while all of the above can happen, many things on that list are under your control: losing access to your Google account (usually) isn't.
You're quite correct there are no absolutes but the problem is, when the consequence of something happening is extreme, the level of effort you put in to protect yourself from it must be equally extreme: to the point that it's generally good advice simply not to use 3rd party auth at all.
I no longer do. I use email/password or OTP whenever possible. Sites that insist I use social login are sites I don't sign up with.
The similar thing is when a politician says corruption is bad and next thing you know he or she is involved in corruption scandal.
I always use my email to sign up. If I can't register by email, there's a good chance I won't use that service.
Although using e-mail sign-up actually provides a number of privacy-related benefits over using the Google account way, it still doesn't solve the main problem - because the e-mail usually is GMail anyway (and when it's not - you can get blocked by Microsoft, Yahoo or anything else too, and you can also loose your own domain).
"Every respectable service" should let and recommend (but not require) you set a secondary e-mail and/or another way to contact you but they usually don't.
The alternative would have been to use email, which, presumably would have been a gmail.com address.
If Google locked you out of your account, you wouldn't be able to access your email account either.
That way if, for some reason, that e-mail service were to close my account, I could repoint the MX record elsewhere and still have access to my accounts.
Finally, is it not possible to require that all such block critical to someone’s data require some form of govt approved appeals process?
I’m asking these questions so maybe someone can enlighten me on why they were not yet attempted, or if they where, why they failed? Is it legal complexity? Cost? Lack of large scale support, as in, is it only a niche concern that only the HN crowd is complaining about?
Ok.
One thing I don't understand is: the author suggests a remedy is using your email address instead of third party sign in. But what if your email address is Gmail? For example, I just went to my Stack Overflow account and added my email address as a sign in method. But then of course I realized: my email address is Gmail. So what's the difference? How are we supposed to put this into practice without running our own email? Email is just another form of third party auth.
I have around 8 gmails. Theyre all connected to various things via OAuth2 and I have never once had any of them locked.
Maybe im ignorant to some detail here, but, this sounds like a spammer retaliating because they got caught.
However, for random sites, entering an email/password worries me because I have no idea how this password is handled server side, is it stored in plaintext or with a weak algorithm? The vast majority here don't care that much because they use a password manager but I'm worried about the ones that don't, they can be impacted if there is a database leak or if the site owner is shady and starts looking through its database for passwords that look reusable and try them on other important website. How easy would it be to set a nice honeypot website that requires a username/password?
A properly set up google sign in makes it impossible to do that at least. Thoughts?
> A properly set up google sign in makes it impossible to do that at least. Thoughts?
Getting a good password manager and using it correctly removes the threat of someone getting your password and abusing it on other sites.
I guess I have had a busy week.
I restored it but automatically had to start thinking about a backup plan where I’d have to point my MX records away from Gmail to something else immediately in order to prevent email downtime.
I hope they ban people sending bulk email too... You should send that stuff from your own server or MailChimp etc.
This way I should maintain my own email server, because I can be locked out of my email by any of cloud providers as easy.
Of course most people don't have their own domain and linking a domain to a cloud email service is either expensive (Google, Microsoft, Fastmail, etc) or impossible (iCloud).
Paying for your own domain also comes with its own troubles. If you're not using Google (or some other service) as your mail forwarder, good luck being able to email anyone. Stealing you custom domain is also a real possibility, and negates your investment in Gmail 2FA.
There's actually quite a few ways.
I don't think that's a "real possibility". It isn't impossible, yes, but very unlikely.
- does your registrar send Auth-Info code over email in plain text?
- did you enter real contact and residence data when registering the domain including public WHOIS database?
This is only a fraction of the attack vector.
Yes.
> is it in a country with legislation friendly towards the country you're based in?
It's in the same country.
> does your registrar send Auth-Info code over email in plain text?
Of course not, that would be a big red-flag.
> did you enter real contact and residence data when registering the domain including public WHOIS database?
I have no idea what a public WHOIS database is, never registered anything there. For the registrar I've entered my real contact and residence data, should I've not?
Unfortunate phrasing on my side:) Actually there exist scammers reaching out to well known mailbox names and requesting a fee for an entry in "WHOIS database".
The WHOIS client is in most distros, try it out.
Okay? I don't think anyone would go to that trouble.
> Phishing you to get your password and then bribing or social-engineering someone at the phone company to forward your SMS-based 2FA codes to them.
Seems unlikely, I never log into my registrar's website. I do often have to enter my Google password though!
> Waiting for you to forget to renew your domain and then registering it.
It's auto-renewing.
Consider that you have a github account. You might be in the supply chain for a bit of code someone needs to read or backdoor to attack a company that you've never heard of. Github is a harder target though.
The scary ones are the real estate funds redirectors. They just need to be in your inbox for a little bit and boom, hundreds of thousands of $ gone because people don't take the time to re-verify bank account details by in person.
I really don't enjoy this giving up on online sovereignty, just because of the convenience and some quasi-monopolists.
And I say that as someone who has very few accounts at any online-services (if avoidable, I'm not a fundamentalist, after all I am posting here right now) and runs mailserver (and cloudstorage and more). So I'm aware it's not all rainbows and unicorns, and I appreciate this is something that takes the skills and time that not everyone is willing to invest. Nor should they.
But one's own "domain" (in the DNS and also the territorial sense) is something that enables some freedom in a world where power is increasingly being concentrated und surveillance is becoming so ubuquitous.
Good thing I didn't say that then.
Running your own email service isn't hard, even with setting up DKIM and anti-spam and so on, though it is time consuming. It is much harder to make sure people will receive your mail and it not be in their junk mail. I'm still seeing lots of email to mailing lists, with impeccable message content, ending up in spam based on mail server reputation or content similarity metrics. If you're running an organisation that can be very costly. If only a fraction of your recipients mark you as spam you'll get lots of misses.
Handcrafting your own internet stack is very libertarian, but it doesn't scale to anyone without access to deep tech expertise. Even governments decide they can't run mail any more. And I would argue that this isn't something you can fix about email. The problem is that the next system isn't federated at all -- it's balkanised and monetized: WhatsApp/Messenger, iMessage, Duo, Telegram, etc etc.
But if the account I'd use to sign in is my Gmail account, and they had locked that account, wouldn't I be locked out anyway?
Please explain it to me if I'm wrong (cause that happens often).
1. Registering with email is not usually an SSO. Authentication is using password and email is used only for recovery. Your won't get locked out of other services even if email server fails for some reason.
2. Hosting providers usually engage customers much better than ad and social media companies. Chances of getting your service back up with customer support assistance is much better.
3. In case the hosting provider locks you out without recourse, you can always move to another provider and point your DNS records there. For this, it's better to have a different company as registrar and hosting provider.
4. DNS so far is the least affected/abused online resource. The chances of you getting locked out of your domain name is low, unless you fail to renew. They give sufficient warning as well. Let's take advantage of that until companies decide to wreck that.
> There should be a better and more resilient way to identify people online in 2020!
I don't think that's an accident. The choices and freedoms available for authentication seems to be diminishing with time. It was possible to specify the authentication provider a decade ago.
We need a name and shame site for websites that can't be bothered to write a back end database for the 3 columns needed to store emails, salts, and hashes.
Those are just the things off the top of my head, it's not just three columns
Convenience strikes again. They use the google third party sign in since a big company like dnd can't be bothered to implement 3 columns plus your nice to haves.
And they are nice to haves, arguably obvious and easily upgraded to required table stakes, but not _required_ to implement email-based sign in. The first three of your listed iftems are also effectively mitigated with a password manager.
Internally, on my website, i may have an account, that i then link to this Google or FB account.
1) If Google shuts down an account, authorization might still work for the purpose of logging in somewhere else. Your email might not work anymore, like any other services within Google. But authorization does. That it does not, is an implementation detail.
2) Since internally i have created an account, that is only linked to your Google account, i can always allow you to also login via any other method. Maybe with your facebook account.
3) I think, things will become better. You use your devices to authorize yourself. And i then trust your device. Then there is no 3rd party involved anymore.
So it is a mix, i would argue. For machines it is just important to identify you. And in the past, so i have read the users, they all want to get away from password authorization. Just make the darn thing recognize me. (and sometimes not)
I guess at least if you’re using your own domain, you’d be able to repoint mx records to do the recovery.
I tend not to use it for my personal accounts, but honestly, Google Sign In for our work systems has generally been a good experience. Works well for our small team, anyway.
Though the post does have a good point on that non-email auth providers add more risk to the equation.
Kind of. You will have a bad day (or month) if your domain registrar is screwing you. But you do own the domain. So you should be able to get it back.
With Google/Facebook and similar you have no right to your account.
Be careful not to overstate here -- this is only true for restricted definitions of "own".
However, your point remains valid. Control of a domain name is much more predictable and defensible than control of a Google/etc account.
Choose the TLD and the registrar carefully, and do not fail to pay registration fees.
- OP
I would have canceled my facebook account long ago if I had not chosen their login for a (unknown) number of service.
What would be a better alternative? Use same credentials everywhere? No, because it is just a matter of time it would leak out of one service. Use unique credentials for each service in local password manager? Nay, because most of us at least want to sync between desktop an mobile. Use something like Chrome's password manager? That bears similar dangers like those the article points out.
I use BitWarden and it works pretty well on all my iOS devices and across major browsers.
2. Developers should always allow restoring passwords for SSO only users, it is ridiculous for it to even be an issue.
3. As a user, refrain fro using free email accounts to identify on a platform, as others already said, buy a domain not an expensive one, and stick to it, remember to renew, and setup your email address with a reliable service, there are good providers for $1 a month.
Update: line separation...
most services keep your identity even if you sign in with another authenticator, because your profile key is your email.
I think the saving grace of using Google login is that usually you can still "reset your password" via email and get in that way even if Google locks you out.
The real solution to the problem would be a standadized passwordless local authentication for sites, I mean the site uses an API of the browser to auth the user, that way you don't need third parties to authenticate and you have everything in your PC. The W3C is working on it.
[1] Figma
/sarcasm
I think most were contractors using both their own accounts and the customer's accounts to put apps in the play store... which will associate you with random people that pay you to make an app, maybe forever?
Really sad that Mozilla Persona did not make it. To me this was promising solution for 'identity provider service'. This section of service should be heavily regulated since it hs a lot of power.
Also probably it should be paid for.
Never really thought about it until I started seeing Google, Twitter, Facebook and other large companies, start banning people for political reasons.
Imagine if you signed into some site using your Facebook account, and then some intern at Facebook moderating posts didn't like some political statement you ban, and suspended your account?
Like the article says, you're not just locked out of Facebook, but any other account that uses Facebook to authenticate.
That give these sites an insane amount of power. You can argue these massive companies have a right to ban whoever they want on their own platforms, for whatever reason they want. But they shouldn't have a right to ban people on other platforms.
Even if a ban/suspension is made in error and can be reversed, that could still cause someone a lot of harm, or be used as a political weapon. That's legitimately scary.
We’ve trained generations of users to accept it’s alright to give their Google/Facebook/Twitter credentials to any random site under the sun.
https://www.wordfence.com/blog/2017/01/gmail-phishing-data-u...
Better yet, use FIDO.
In the article I clearly call out that using any third-party is a risk, so I don't see a reason why the moderator felt the need to say that in the submission title as well.
What is actually going on @dang ? He asked a legit question and even the OP isn't sure what's up.
> Please enable JavaScript to view the comments powered by Disqus.
The blog post author is using Disqus because it's convenient.
This is a major take-away, too. I have used this as a litmus test for a while. If a service requires you to log in via one of these third parties, and doesn't offer a "create an E-mail based account" option, stay away! They're not a serious business.
Or, even better, favor services/stores that don't require you to create an account.
I don't think it's fair to expect every website I sign up for to be able to safely store passwords. OAuth is a convenient and much safer way to allow users to authenticate to your website or service. I don't think it's fair to dismiss every service that doesn't provide this option.
Sadly this isn't true. I can't register to download my electric bill without a google, facebook or twitter account. Electric companies are local monopolies so I can't switch to another supplier either.
My email account still belongs to google, so I can't claim that this makes any difference in my life. It's a bit disturbing nonetheless.
Ghostery blocked comments powered by Disqus.
Never Use Google.
OVH supports Yubikeys, has DNSSEC and will give you 5GB mailbox for free in your domain just for buying it from them. You can also pay like 20$ per year for 100GB of space for WWW, backups (preferably encrypted) and other stuff.
i maintain a twenty five year old mindspring account just for sites I have no financial connection to.
very easy to accidentally share your whole address book
https://imgur.com/a/JC52lBV (lequipe.fr)
https://imgur.com/a/VSM3Uk9 (reddit.com)
https://imgur.com/a/KpVCYBL (medium.com)
There is a workaround to add custom addons, though: https://github.com/tom-james-watson/old-reddit-redirect/issu...
On the desktop it still usable with old.reddit.com.
But honestly it's probably for the best, less time wasted.
I suspect some bizdev people at Google just had a "great idea".
This uBlock Origin rule blocks the popups at least:
##iframe[src*="accounts.google.com/gsi"]
I knew that I was being tracked, but that was a bit too "in my face" to ignore it.
It's funny because there's nothing new about those login popups - I already knew conceptually that kind of thing was possible - but seeing your little avatar picture show up where it doesn't belong provokes a much more direct reaction than abstract knowledge.
https://github.com/containers-everywhere/contain-google
Installable from the Firefox extension "store".
I complained to Google. I have a GSuites domain and I don't want my users to be able to sign up via Google. No resolution. I suggest you all complain too
I semi worked around it by adding accounts.google.com to my ublock origin block list but about once a month I have to turn it off to allow me to log into Google.
Note: I'm not against google. I am against this auto-popup. The logical conclusion is you'll go to a page and get 6 of those popups or more. One to sign up with Google, one to sign up with Apple. One to sign up with Facebook. One to sign up with Linkedin, etc...
The design of that system by google is not a good design based on the idea that if everyone did it it would be bad. Google should top it. If I click "sign up" on the sight then let the site offer me "login with X" and don't contect X until I click "login with X"
That is one example of a dark pattern.
||accounts.google.com/gsi/iframe/select$subdocument
It blocks just the popups and not the login page itself. But Google may change their methods at any time to circumvent it, so your way is more robust.
This is where uBO's dynamic filtering[1] is useful, as it allows you to globally block `accounts.google.com`, and then unblock it only for specific sites by overriding the global block rule with a local noop rule.
* * *
[1] https://github.com/gorhill/uBlock/wiki/Dynamic-filtering:-qu...
Happened to me as well. So i guess their plan worked. So glad they care about my privacy.
This implies that Google already knows that it's you when it shows the sign-in prompt on some 3rd party website and they are already tracking you there even though you are not signed in. Lovely. Not that you'd expected anything else from Google.
A further issue with this is that Google knows you're on that website because the referrer and request headers will have that on the IFrame request.
Edit. I think I replied on the wrong post here.
There's a fundamental conflict between privacy and convenience, because I have to either allow no third-party cookies, which means no one can embed any authenticated content from a third-party context (think Disqus comments on a blog), or I have to allow third-party tracking. The middle ground -- allowing some third-party cookies but not others -- is a UX nightmare. Just trying to explain the situation to an average user, at all, is nearly impossible, much less interrupting every visit to every site with "Can I use cookies from {site 2} here? How about {site 3,4,5...112}?".
Just confirmed this does seem to stop the annoying login popups from Medium, etc.
I tried to figure out how to disable that a few months ago but my google-fu was weak and it seemed like nobody knew how to do it.
When I first saw it on Pinterest, it took me a moment to figure out what I was looking at as a web developer of 20 years. My girlfriend still didn't get it after I was explaining it to her. How does anyone else have a shot at arriving at "oh, so the site doesn't actually have access to this information that's being displayed on the site."
When I was younger, I thought good UX design was obvious, something all of us had intuition for as users ourselves. All you do is put yourself in the user's shoes and ask basic questions and use basic empathy. Of course, now being in software for so long, I realize it's one of the rarest and most unrecognized skills.
To be fair to Google I have clearly called out all third-parties in the blog post, some by name.
I used Google's name in the title because that name elicits reaction from almost 100% of the audience, since almost everyone has used Google services at some point. I myself am a happy user of Google services, except for one incident [1] a few years ago when I was locked out of my account for 20 days. I was able to recover it because I finally remembered my linked yahoo email's password; I had forgotten that, and never bothered to save it in password manager, because I hadn't used it for many years.
For the record, I was also blocked out of GitLab for 7 days [2] for no apparent reason. This was resolved after a few days of follow-up with their support folks. Upon account recovery, the reason given was that my account was accidentally caught by their spam filters.
Back on topic: Changing the title from "Google" to "Third Party Auth" significantly softens the impact and urgency I want the reader to feel upon reading the title, and the short article that follows.
[1]: https://support.google.com/mail/forum/AAAAK7un8RUAzmxJAkP8gU...
[2]: https://forum.gitlab.com/t/gitlab-com-account-blocked-need-h...
- OP
The title of the article matches the content, so, no, it wasn't a clickbait. Also, if the title was really a clickbait, someone would have surely called it out before my gripe about the title change. In fact, 2 others complained about the title change before I posted my top-level comment; those others' complaints and my responses are now buried under the "More" link at the end of this page.
I understand you, @baby, have good intentions, but I take offense to @bzb6's remarks. I guess that's what I get for responding to a recently created account (41 days ago) with no posts and all of whose comments are one-liners; mostly knee-jerk reactions, no insights, and not considering the nuances of the real-world implications.
It's their article, I think it's fair they ask for the name of the post to be preserved. It has nothing to do with their intent (clickbait or not) that the audience here voted up their submission.
And
>Changing the title from "Google" to "Third Party Auth" significantly softens the impact and urgency I want the reader to feel upon reading the title,
It sounds rather like parent was correct in calling it click bait. For me, any article that has aspirations to manipulating ones emotions in order to illicit a particular outcome is definitely selling some propagandist notion... Aka click bait.
That the article's content, HN submission and the parent comment is the same person @gurjeet, I would like to thank @dang for the modification.
Propaganda has nothing to do with the definition of clickbait, so saying "[propaganda ...] Aka click bait." Is very misleading. And betrays your argument that everything should be exclusively logic, specifically omitting any appeal to emotion. That's exactly what you're trying to do by portraying op as using propaganda. And rhetorically speaking would be a disservice to both reader and article.
He wants to us the name Google to personalize the message assuming that's what a lot of people use. Do you know how I figured that out? That's what OP said was his goal. It's rude to assert otherwise without evidence.
https://youtu.be/oJcEDzgPRrc?t=57 (warning, the video is somewhat off-color)
OP, your first sentence is If a website offers you to sign-in using Google (or any third-party service, say Facebook, Github, etc.), don’t use that feature.
Titling this as "Third Party Auth" is a reasonable and correct summary of your article. Blaming Google specifically is hype-mongering unless you have a specific gripe against Google - and reading through your post, I don't see a Google-specific criticism.
The title for the HN audience is better, but probably equally misleading since 3rd party auth could include Auth0 or Okta, and personally, if you buy into Apple’s privacy story they should be trusted.
Edit: now that I've had a chance to read the article, I don't agree with that change, and have restored the title back to how a moderator had correctly edited it before.
The reason is that the article doesn't say anything specific to Google. The sole point it does make is common to all the services, and indeed the article seems "conscious" of this, since 3 times it says "google" it immediately qualifies that with a phrase like "or any service".
Nor does the parent comment make the case that this is specific to Google; in fact it makes the opposite case.
Never Use Google to Sign-In
Never Use Third Party Auth to Sign In
Don't use third party auth to sign in
I guess a another moderator had a better idea at what title will attract more attention.Given the number of comments, the duration at the top of HN, it's clear that this post (including the title) hit a nerve with many people. But the moderators in their wisdom chose to reduce its reach by watering down the title; twice! Compare the 3 versions of the title so far, which one do you think resonates with most people? If they had chosen to add other prominent offenders' names (Facebook, Github, etc.) I wouldn't have minded a bit; that would have been a better use of the space the title takes up.
But they chose to first generalize it from "Google" to "Third Party Auth" (casual reader: eh, what's a third party auth; who are these people? what's auth? is it authentication, or is it authorization; I guess that's too generic post so I don't care, <keep scrolling>), and then replaced "Never" with "Don't" and lower-cased the rest of it. I don't expect the general population of HN to take my, or anyone else's, advice at face value, but think about the problem in their own context, how much it affects them, how much they care about the problem, and if they agree with the proposed solution, and to what extent.
I'm sure that by watering down the title's efficacy, the moderators have lost opportunity to educate many of the HN readers.
People write content to share their ideas, and they want people to pay attention, because the writer thinks it's important. If the moderators' changes help in that goal, no writer would mind. But in this case I am sure these changes have hurt the chances of spreading the core concern.
I find it offensive that my judgement in choosing the title is being questioned, even though most of others agree that the original title was appropriate, in general. Thankfully, I went with my gut to write the article on my own Blog (and link it here) even though it was 3 short paragraphs, rather than post the original content here. The original title and content will stand there, without fear of someone else's ability to alter it.
Someone else's platform, their rules, their whims; no recourse, as with other platforms.
To self: Shut-up and get on with you life, you have already wasted inordinate amount of time on this.
Not only do they control the content you see, the content you can access, but also history of the content you've accessed.
Fuck this planet.
I wouldn't was to use that identify for every random website, but at least we'd have something reliable.
GSuite:
- pros: vast ecosystem of GMail extensions, eg mail merge
- con: just 30gb total storage
MS:
- pros: 50GB email, 1TB cloud, Office apps included (not that I like them but sometimes you still need them), dirt cheap family plan for $30+ you get 6tb
Yandex:
- free, but yeah all my serious stuff like bank accounts there, IDK
iCloud:
- super expensive
Dropbox:
- no email and ios camera upload broken/lags years behind for ages and super expensive
What do you think? Are there any better options out? Which would you take?