FYI - never use oauth to log into anything you care about.
FYI - never use oauth to log into anything you care about.
So maybe the lesson should sound more like
- 'Don't use Dropbox for anything you care about' or
- 'Don't do business with large corporations for anything you care about'
To clarify, I am not saying it to protect oauth (in its current state I am not a particular fan of it), but to show, that the technology doesn't change by itself and that someone decided to change it. So the company who decided to execute this unethical change should take its share of the blame too.
There is no fine grained control to permissions.
Software isn't allowed to just be done anymore.
However, your point still stands, because exceptions are just that, exceptions.
Interesting remark. I'm not objecting but it's interesting that this goes against what can one read here very often from people who comment on new products, which goes like this: "if you offered oauth sign up, I'd sign up but won't bother with creating an account". Just an observation.
It'd be nice to see Google offer something like that.
Makes it tough for third-party devs to debug a legit “I am not seeing Page X as an option” though.
I definitely agree with this. While it's true that Google, Microsoft, Facebook, and Apple are probably better at securing accounts than most other companies, there's always the possibility that they can be compromised.
Another problem is that if your oauth provider decides to close your account for whatever reason, it may be difficult or impossible to unlink everything from it.
Not only do I create real accounts for any service I want to use, I divide them up among multiple separate email accounts, so that if one account is compromised, I limit the associated services that are vulnerable as a result.
Or, "Then create a password and revoke oauth permissions from the provider"
Also, the usual tracking stuff.
EDIT: I'm talking about sites that also have their own local user db of course, so you could just do a password reset.