Introducing Anonymous Login and an Updated Facebook Login
newsroom.fb.com
newsroom.fb.com
Remember, Facebook is the same company that cuts deals with shady data brokers like the Datalogix (the company that buys your grocery store discount card data and re-sells it, among other things) to build a comprehensive profile of everything you do. Using them for this pseudo-anonymous "anonymous login" helps them a lot more than it will ever help you, as a standalone developer.
I can't wait for Facebook to trademark the term "Anonymous Login," just to complete the irony. Remember, if it was actually anonymous, you wouldn't need Facebook's help to implement it.
That sums it up nicely.
And actually, the thing is I could totally see Facebook enabling truly 'anonymous logins' and whatnot, because it can afford to do it at this point. It is too entrenched as the social king, no other competitor comes close to it, and it's not going to fall down anytime soon because it'll be buoyed by networks effects for quite some time... and so it makes sense to ease things up a little to improve their public image. But, the way they got there, to the top, was by using dirty and despicable dark patterns, like 'Privacy Zuckering': http://darkpatterns.org/library/privacy_zuckering/ For this reason alone, I would stay the hell away from anything Facebook.
It does make sense though. Developers only really want a way to verify the user exists and isn't some spammy bot. Verification like facebook login is the easiest way to go. The problem has always been - far too many people avoid signing up with facebook as it shares "god only knows what" with the site. This works around both issues and really is the only way they can become the single signon entity. Which is what they've been aiming for.
As for "not bothering to implement" (aap), if you already need to handle facebook connect login, its going to be minor to add anon login facebook handles all the identity stuff leaving your app clean of yet another verification loop which annoys the hell out of users.
Sure there is the "apps need that data to make money" situation, but as a matter of fact, the people signing on anonymously were a) going to create a fake facebook or b) signup manually and give you a mailinator address.
Such as?
They're improving collaboration in all products, ie bringing it on par with gdocs.
Something geospatial, dont recall exactly what, maybe it was to do with SharePoint or colo.
The most interesting was they're letting go of forcing ms languages for plugins and allowing you to write and import widgets/plugins as html/js so all those nasty vb scripts of old are going to get some much needed love from all the web devs out there.
I could be wrong on a few of these just what I recall hearing about, happy to be corrected if I misunderstood any of what I was told. Mostly it just sounded like, as a company, they're identifying what their core products are and innovating on them. As in strategically, they're getting their shit together.
Most people are going to access your app from one device, their phone. The phone is the one true source of identity. Let us all be glad that a privacy-paranoid company such as Apple sets the standards there, rather than what Facebook would have liked, had their phone efforts worked out.
I will also note that taking advantage of device token for "login-less anonymous use" is way way smarter for developers, from a usage perspective. Every single tap or interaction is a point of friction for your users; just eliminate them altogether. This is, for example, why TouchID-based devices generate more App Store transactions than devices based on the normal password system.
Using Facebook (or any kind of login) to solve that would be a bad idea (but many might be tempted to do it).
However, in those cases when the task is more complex than that (I just checked, that applies to eleven† of all 23 third party apps I have installed on my iPhone) that’s not a solution. I – the user – want to be able to access the data from anywhere and do actually use that functionality regularly.
Honestly, I personally would have no issue if each of those apps gave me a choice of signing up with either Google or Facebook. That would massively simplify things for me and I wouldn’t have to lug so many accounts around. I can understand the privacy concerns, so I do see the need for alternatives, but for me personally it’s not an issue.
—
† Reeder, Twitter, FB Messenger, iBooks, Pages, Keynote, Numbers, YouTube, Twitch, Vine and Dropbox; Apps that already don’t force me to log in, most because it’s just not necessary: Castro, arte, Star Guide, six game apps; Apps that force me to log in for some functionality and I’m not sure how I feel about them: iPhoto, iMovie, Remote.
Everything else I use from multiple devices.
‘Often’: many websites don’t see this; I’m willing to bet those I use regularly (StackOverflow, HN) aren’t even close. Most analyst describe a currently slight majority for phone metrics (except time on the site); more importantly, demographic elements suggest phone attention share will grow.
> I'm truly sick of hearing that the phone is the only device that matters.
‘Only’: OC hasn’t said exactly that -- he talked about authentification; most people don’t really say that either. Many journalists exagerate a trend and slight majority, but I would (tongue-in-cheek) blame you first for reading badly written magazines.
My experience is that authentification is safer for non-developer users on their smartphone: you have a lot more stream for consistent two-factor authentification; physical security is better for something in your pocket most of the time; it’s the only random-key generator (capable) most people have close to them. Roughly half of users users actually lock the damn thing…
- Exactly and I don't even bother signing with Facebook account anymore with most of the apps, Facebook apps are way of the past.
* What about the web?
* What about cross-platform?
* What about when the device token changes? (for example, after restoring the phone from a backup image)
My take: Facebook Login solves a real problem well and this 'Anonymous' option is a good improvement. The name is no worse than other industry uses of terms "Incognito", "Private", and "Cloaked".
As for cross-platform and token changes -- well, you can't deal with those situations when you're implementing something that's actually anonymous. You're going to have to implement some sort of persistent identity. At that point, you might as well offer a multitude of options, of which Facebook would be one.
This login creates an unnecessary point of friction for all anonymous applications. Just use an existing token (cookie, device token, etc), allow your user to immediately begin using your app (that's what they expect anyhow), and "ease your user in" to a point of giving you identifying information if you need it.
Even if the cookie expiration was set for 100 years, it's going to disappear the moment someone switches their browser, gets a new computer, clears their cookies, etc.
This seems like a reasonable solution.
> Just use an existing token (cookie, device token)
That won't work because the mobile and web account have to be connected.
True, but this login isn't "actually anonymous" - but I can't think of a better term so I don't blame Facebook for using the one they did. It's effectively a global ID with no data attached to it.
on the web, anonymous login would be just a code snippet. What would prevent anyone from showing regular FB login posing as anonymous? Only thing I can think of regular login should have a follow up dialog with confirmation of what's requested, but maybe that can be auto confirmed too? some users may still agree to follow up screen if they trust the anonymous icon.
Remember, if it was actually anonymous, you wouldn't need Facebook's help to implement it.
People implement FB login for a variety of reasons, but one is that doing proper account management is hard. If you want to implement a non-FB anon login, you basically have to implement a full account management solution yourself, assuming you want the anon account data to be persistent (that is, it's not truly anonymous in the sense that you sign in, do things, sign out, and it's as if you were never there). This basically fixes one of my final issues with FB login, that it's still not clear what data FB will give to the app. If anon login means FB doesn't give anything to the app aside from an opaque ID token, that's pretty cool.
That's just not true. Modern web frameworks come with modules that let one have fairly good account management systems without much work.
I'd like to setup an account management system and I was planning on doing it manually but figured there had to be a better way.
For Rails, Devise seems to be the way to go, as it's the most popular by far[0]. It's what I'm using for my project.
[0]https://www.ruby-toolbox.com/categories/rails_authentication
I do Python mostly. Django? Fine. It has an excellent auth system out of the box. But that kind of auth system isn't very flexible either. Now I barely do Django development today so please excuse me behind any insane changes.
Flask and Pyramid world? Custom auth to me. They both have community modules for auth stuff, but do I really like them? I am not the kind of guy just pip install random "useful" package these days. Let's give another example. A year or two ago I tried to do social auth in some of my django and flask apps. Maybe I was dumb but using that social-auth library took me a while to get some of login working. Plus, the code was messy and buggy. In the end, I said screw that and implemented all of the custom login myself, just reading the official doc from twitter and facebook. That also took me a while but I knew the whole implementation inside-out. If I don't trust my own implement because it is insecure, then I must spend the same amount of time inspecting other people's custom modules.
The truth is, generic auth system is hard and is not flexible. In fact, too flexible can be a bad thing: http://plope.com/pyramid_auth_design_api_postmortem
I like customized auth system based on the api provided by the framework - that' what makes Pyramid powerful to me. Sometimes your community auth module can have limitation that you probably have to hack around.
Most modern web frameworks do NOT come with fairly good account management systems.
1. Python + Django
2. Node.js + whatever
3. PHP + CakePHP/CodeIgniter/Yii
I'm not aware of any.By "password-reset" I mean user clicks "Forgot password" and goes through some process like asking a secret question, doing catpcha test, sending a password reset link via e-mail, handling the click on the link, asking for a new password and resetting it.
P.S. Pick different frameworks if you wish.
Alternatively, there appears to be a CBV version of password resets over here that looks fairly easy to extend: https://github.com/brutasse/django-password-reset
I can't talk for node.js (although I have found that its authn/authz frameworks are lacking in general) or various PHP frameworks, but Django at the least is fairly professional.
There's no doubt that Facebook knows who you are even if you use the "Anonymous" login. This just allows a user of RandomApp#100 to login without giving the app everything on their Facebook before they even try it.
Also even with anonymous login, you can later choose to give the app your real info if you trust it more or find it useful.
Do I like Facebook-only login? No. However, this does give the user some more choice as to how much is shared with those apps up front.
They'll probably introduce that reality once 'anonymous' mode has been established and depreciate assumed permissions as time goes on.
Src: http://www.insidefacebook.com/2012/09/24/facebook-partnershi...
Lose your device, lose your account. Yay!
I could claim client-side certificates, but nobody uses those, and certainly not cross-platform.
This is a big win for users who don't want to share their personal data with a random app developer. Facebook still sees your activity, but they already saw your activity.
This for the millions of users that want to try apps without having to fill in multiple onerous registration fields and without having to worry that if they use facebook login, the app will spam all their friends and post to their newsfeed.
This is actually very smart, and I will be implementing it soon. Definitely not an "idiot" move for developers to implement.
Can someone give me some perspective on why Mozilla's Persona is not used more for authentication purposes?
This is not, actually, the first time Facebook has enabled this level of granularity, as far as users being able to grant permissions piecemeal.
It used to be (not sure if it still is) that an app could request one permission here, one permission there, at various points in its application flow. But with each request (in which you could bundle a bunch of different permissions) it was either an "all or none" decision for the user.
This new approach just makes things a little easier, because you can present all of the permissions and data request up front and let the user pick and choose what should be granted.
I think this Facebook thing is really going to take off one day.
I also develop an application that uses Facebook login, and we (using django-social-auth) request one set of permissions initially, and request more later if the user wants to do advanced stuff.
Now, if I could log into Facebook without giving them access to my data, that would be a killer feature.
When the http request is made to facebook, they get their domain cookie back which has your user info in it. On top of that, when their javascript runs they get full access to all the data of the window that made the request meaning they get the other site's cookie as well absolutely everything else.
If you don't want to be tracked by facebook online, you only have a few options. Disable cookies, disable javascript, or only login to facebook in an incognito window. Otherwise, they can track exactly who you are and where you go on any site that makes any request to facebook. Even still, if any request is made to facebook, they can still anonymously track you even if you aren't logged in.
As for apps, I don't think the facebook api would be able to find out the specific usage of the app unless the app purposefully gave it up, although they would know when you login.
I logged out after that, and rarely log back in. I know that's only part of the battle, but it's something. As a result, if a platform requires a Facebook login, I probably won't use it.
You're only choice now is to not use apps that display FB ads.
Before, login with Facebook provided a better and more convenient user experience. Now it just seems clunky. Without the information that we get from Facebook for a user that decides to sign in with Facebook, we don't even have a user.
Of course let's see how they implement it. If the process is too complex, it won't work for users. Given their reputation on privacy - it will be hard to recover. But (almost) no other company has as good a shot at this opportunity.
What we really need is a decentralized identity platform.
Basically its what Facebook is proposing but we do background checks on the accounts to ensure they aren't bots. Our privacy policy will be a lot more serious too. No marketing or targeted advertising.
I am the author of http://platform.qbix.com, and it includes decentralized identity. Each app can run on its own machine/cluster, and communicate with other apps. Each app is itself a user in Q.
When a person using a user-agent authenticates with an app, they can either do it natively (providing, say, their email address) or they can select an external app that they already logged into. The user-agent stores the domain of that app, and it's a simple matter of doing oAuth with that app. Except, of course, the user id isn't given out by the user's "home server" but instead a different "xid" (stands of external id) is given to each consumer app.
In short, an app can start life as a consumer of identity and eventually offer to provide identity. The identity provider doesn't just support oAuth, but ideally would allow the user to publish streams that others can subscribe to and view, import contacts and manage access control (privacy) based on those contacts and labels. Finally, they should be able to connect endpoints (such as their mobile phone, email, facebook account etc.) to receive notifications sent to their account by some apps they've authenticated with.
Whenever an app would need to display personal information back to a user, they could do it without ever knowing their personal info: http://www.faqs.org/patents/app/20120110469#b
What do you think?
In the future we might also encrypt this stuff so governments and others can't get it by simply breaking into the database. I don't have any expertise in this last part, so if anyone does I'd be curious to learn.
The main risk seems to be what happens if Facebook decides to remove Anonymous login. You may have many accounts on your site that had logged in anonymously and participated, but now no longer have a way back in. This seems like an awful scenario, and yet a very possible one -- Facebook is quick to change and remove features on Platform.
But of course there's also the issue that this becomes something that developers themselves can't easily remove once they add it to their app. Or worse, if Facebook decides to block a developer's app from platform. At least with regular Facebook login, most developers requested Email so users could always request that a password be sent to them as an alternate login mechanism.
Developers should be mindful that Facebook explicitly prohibits using Platform to build "competing social networks" (An unfortunately broad category): http://techcrunch.com/2013/01/24/my-precious-social-graph/ And they have a history of enforcing this with the bans of Yandex, Wonder, Vine, and Voxer.
They store everything even when purporting to have deleted it and privacy is contrary to their underlying core business.
Privacy and Facebook is an oxymoron
I can only think of LinkedIn which rather fails at the family / friends segments.
Pure auth has value to developers who want to verify a user without requiring a handshake of verifying an email address, having to manage against spam accounts, and so on. Yes it's possible to have multiple facebook accounts, but there's significantly more friction in facebook's system than in any home-rolled system you're going to come up with. While at the same time, significantly less friction from a "steps the user has to take to log into your app" point of view.
It's another developer option, one flavor among many, that developers can use to make it easier for users to log in. Given the reality that most people actually do use facebook, I think it's kind of interesting.
I'm getting a little tired with how out of touch people on HN seem, especially with regard to things like Facebook. Guess what: the majority of FB's user base does not care about privacy as much as you do. Even people who do care to an extent, and don't implicitly trust FB, are at least comfortable with some level of interaction and sharing on the platform. Anon login is targeted at people who are comfortable with what they share with FB, but are wary of giving their personal info to some random app they want to try.
I'd disagree too, I know many non-HN people who would be happy to switch to something else but Facebook is the incumbent.
I don't disagree with the idea of a "Anon Login" whatsoever, that is a good idea.
Maybe I'm misreading you, but it sounds like you believe that upvotes on HN allow you to infer something meaningful about what real, normal people believe. Don't make that mistake. You'll be in for a rude awakening if you do.
I don't mind this behavior/attitude of not caring because it has allowed many people to experiment with actively exfiltrating data out from behind these walled gardens through various means (some of which have been posted to HN from time to time over the years) without bothering going through OAuth and the like. And increasingly, users behind many of these walled gardens will see the false sense of security they have been offered when people/companies other than facebook can actively leverage and profiteer from "their" data. Once the data is out in the wild, whether facebook gives permission or not is moot.
An example: I've wanted to try out https://giveit100.com/ since launch, but have been waiting for an alternative sign-in.
Thanks FB!
That's what I've been doing, and I will probably continue to do so since even logging in anonymously on Facebook tells Facebook, and whoever else they feel like sharing it with, e.g. advertisers, that I logged in.
- people have already signed up with Facebook
- people don't trust app developers with their FB data, and don't trust app devs not to post crap to their timelines
- people hate signing up for another service again with email and password (you have to give out your email, you have to create/reuse and remember a password)
The more open question is if it will cannibalize FB logins or get incremental people to sign up with FB (people want to do this anonymously but didn't have the option and gave up).
You know what I can find? Facebook having leaky permissions for a year and a half.
EDIT: Here's a screenshot -- http://i.imgur.com/p0peJp6.png The best part was the reviews. They were all either 1 or 5 stars. People were shocked it actually worked.
> In a move to bolster its new 'Anonymous' strategy, Facebook has acquired 4chan for $30 billion in an all-cash deal
> "It's been an incredible journey", said 4chan founder Christopher Poole at a press conference in Menlo Park, CA. "Our anonymous users have been the driving force behind 4chan, and we look forward to bringing that experience to Facebook"
[edit 2:38 CDT to add the string "/app"]
Which barely more invasive than telling them you breathe air, no?
I'm curious what happens to functions inside the app that need identity. Do they work as normal but the app developer can't see the information? Or does everything the user does prompt for a login, so the app developer can be pretty assured that nobody will go for any length of time using the app before they give up and log in?
Everybody must have caught on to Facebook's bad will psych game by now so why would anyone keep using Facebook Login?This latest change just moves the bad will to your login page. Every time someone moves to log in they will be reminded who Facebook thinks should be trusted and it's never going to be you.
Though they now need to educate users so that they don't still feel that their privacy is being violated.
Actually I would like to ask if anyone here knows of more good solutions for making creating accounts expensive. Captchas ain't it anymore.
The best one I know is Phone Verification. http://www.blackhatworld.com/blackhat-seo/making-money/59699...
Buying a cellphone in order to get an account is expensive enough. But is there something better?
Next top feature Facebook should introduce: Automatically generate a new anonymous email address for each app. I can then go into Facebook settings later and prevent any of those addresses from forwarding to my personal address if that app starts spamming or gets hacked. They did have an anonymous email feature at some point, but it wasn't fully ready yet.
I guess I just don't see the point of requiring a user account if it isn't adding value to either the user or the app creator.
One more reason not to use Facebook as a login mechanism I guess.
Logging in to a site provides more value than just sharing personal information. For me, I rarely, if ever, want a site to know my personal information. That's why I rarely use Facebook login service. Now I will.
As a programmer, I surely hope you don't think the only purpose of user accounts is to gain personal information.
Hacker News does not ask for personal information. Does that mean we shouldn't have to log in on HN?
I think he's looking at it from a product/sales lead perspective. HN isn't trying to sell us anything.
It adds plenty of value for the user: they get a logon to the app which allows them to keep information across sessions, while not providing the app vendor any information unnecessary to that function.
It provides a authentication as the same person without providing identification of who that person is.
Now, obviously, anonymous login provides less value to app developers who are using using logins to harvest personal information from users, but then, that's a plus for users.
Specifically, he wants some contact information so he can follow up with a lead, which I think is reasonable. Your average customer may not have time to put much effort into a product/service search and a (relevant, informative) follow-up email can be very helpful.
Ideally you do want what's best for the user, but if more revenue is coming in from the old, non-anonymous method, adoption of this one may be slow or limited.
Now if the app creator has a way to push a message back to the user (fb message or something) without knowing who they are, that might be a good compromise.
I love the name F8. It's a great play on words.
1. anyone who wants to use a site has to create an account with a fb "anonymous" login. there would be no more "free" access" because then you can start to tie free user behavior to actual conversion.
2. Once the user wants to pay, this is tied to giving more information--at least name and email address.
Will be interesting to see the details, because tying free behavior to conversion is a holy grail for marketers.
Has anyone actually tried using this?
Suppose you're creating a site -- let's call it Hacker News -- that requires a user to log in, and all you care about is the part where they enter their username and password.
From there, you're able to assign the user a unique ID and persist their preferences (e.g. header color) across sessions.
It's not exactly a difficult project to roll your own login system, but Anonymous Login gives you the added advantage of being able to "upsell" users into providing more information, if they feel comfortable sharing it.
This would basically make it easier to access or try out all the FB-only-login apps without giving the app owner all the personal info.
"Anonymous login" means you provide no identity information whatsoever. If you're "person #123456789" or "f93f9211-9f49-4bad-ad34-e00f8c536b0f" or whatever - you're not anonymous.
If you use facebook login for your site then you are shooting yourself in the foot if you care about users.
I'm guessing 'What is the point of this?' got you but reading that closely is more this: not everyone is sold on the idea of FB in general as the answer to anything so an alternative product doesn't do him any favors. Like trying to sell someone who doesn't want to drink a smaller bottle of alcohol.
I don't want to sign in with Facebook full stop. I really agree that you shouldn't force people to use a third party service to sign in.
If you're contemplating login, please consider people like us! Do Facebook login as your MVP but please do consider us!
You and parent are both thinking that it is Facebook's fault that third-party service providers are offering FB login.
Is it FB's fault that your favorite website is only accepting user comments unless you login with a FB account? No!
FB has done its good part. I am not here to argue with you or anyone about whether FB is respecting users' privacy and security demand. But now FB gives developers a new login option so that a site can allow users to do something like leaving a blog comment without revealing personal information such as name to the website. FB has done its good part as a platform.
If your website only offers facebook as the only option, that is not FB's fault. Should a website offer more login options? Why are services related to programming and source code usually come with a twitter or github login option instead of facebook? Because nowadays programmers tend to have a Github (or Bitbucket) account.
So why so much negativity around this new feature?
To use an analogy: we have small cars and someone is trying to sell us a big car. We're saying: 'What's the point?' because our desire and needs are already met by something else we have in mind. We see the product as missing a feature or not adding anything extra to the table. Think of it like wanting a mail provider that offers POP but not IMAP. I want one that uses IMAP - am I wrong?
I do not see this as negativity: it's just healthy disagreement. Otherwise every comment here would look the same.
It is unfortunate that the product we're talking about is offered as an alternative to the real thing (Facebook Connect) and it is what a developer would consider using to avoid writing their own login system. The offering does not meet our needs.
What is the point of this? I don't want to have to login with facebook at all. .
and then his reply,
Then use one of the other implementations. The problem is it being facebook, not the concept.
It's basically anti-Facebook login sentiment to me. Fine, I respect that. But,
If you use facebook login for your site then you are shooting yourself in the foot if you care about users.
You can't shoot yourself in the foot if your audience of your service can choose. As I said before, people who only offer FB as a login/sign up option is not FB's fault. In fact, any websites that don't offer the vanilla username/passwrod signup & login mechanism isn't FB's fault. So don't mix that issue in any discussion related to FB's new login mode here.
Now moving to yours:
We are hoping they choose not to use the platform _exclusively_ or as a substitute for their own login.
I will take it as you don't want to use any website not providing the vanilla username/password signup-login, right?
So again this has NOTHING to do with FB and its news announcement.
the product we're talking about is offered as an alternative to the real thing (Facebook Connect) and it is what a developer would consider using to avoid writing their own login system.
I am confused here. Do you like FB connect and like it over anyone's custom login system?
What exactly do you and parent want from Facebook's login and from app developers?
Obviously there's nothing truly anonymous about this service if Facebook knows everything about you...
what happens when people blindly trust a button and someone decides to exploit that by making a fake one open a phishing pop up requesting your Facebook credentials? Has this been done?
People don't tell you anything, they don't have a way to do it. Facebook just does whatever it wants without caring about the users, lets cut the BS.