> If you use 'Login with X' you're giving X access to all your accounts.
That's definitely not correct. You are giving X to access only whatever scopes you allowed, on a single account.
Here's an example of just 'userinfo'. Click this and see what it asks for: https://accounts.google.com/AccountChooser?service=lso&conti...
Per the screen, it only allows:
" - View your full name, profile picture and profile URL"
" - View any publicly available information on your Google+ profile (if you have one or create one in the future)"
It can't see your photos, see your contacts, read your email, post G+ messages, or anything else you didn't authorise.
So, in other words:
- RandomWebApp lets users log in with Google.
- A RandomWebApp user has a Google account, and allows RandomWebApp to oauth against his Google account.
- Since Google issue the access token used for RandomWebApp, Google could conceivably access RandomWebApp on the user's behalf.
That's a legitimate concern.
I don't see how separating identification and authorization conceptually helps. You have to trust your identification provider, in any kind of a federated or multi-party system. (Ie, a system where you can log into your google account and get access to another system, whether using OpenID 1.0, 2.0, OAuth, whatever).
Having Google hurt me is what I fear.
Google's use of its identity service is not on an equal footing as RandomWebApp's. Having a Google+ identity means accepting its TOS for a specific list of services provided by Google[1].
Violating the TOS (eg, by misusing, even accidentally, one of Google's services (think DMCA and ContentID mis-tagging fair use material, or even by not providing the name that the US has registered for you)) means losing your identity. That has definitely happened to at least a dozen of people I know.
Additionally, Google enforces identity in the context of a company based in the US. Whatever obligations it has in front of its government, and whatever weaknesses the government finds, will allow misusing your identity, even when Google itself isn't being evil.
[1] Excerpt from the TOS:
> Our Services are very diverse, so sometimes additional terms or product requirements (including age requirements) may apply. Additional terms will be available with the relevant Services, and those additional terms become part of your agreement with us if you use those Services.
Being authorized to use a particular account is still seperate from proving who I am. I have visions of going to the Pentagon and I say "Hi, President Obama here, give me access to all your intelligence data" and the analysts saying "Certainly sir! You have top authorisation, here is all the data". :-)
Actually, that would work better at a bank. "Hi, I'm Donald Trump, give me a million dollars from my loose change account, thanks!"
OAuth definitely does authenticate though (hence the name).
Your first sentence is totally correct though.
Hope that helps.
The conflation of authorization with authentication is an accident and a mistake. They are still quite separate concepts. Authentication is about verifying identity. Authorization is about privileges afforded a given identity. Access control models usually depend on some form of upstream authentication.
The third-party authorization flows provided by OAuth are not intended to establish or verify a user's identity. Their purpose is to extend a user's access to a third-party in a limited way without sharing passwords.
Social Sign-in is an accident of 3-Legged OAuth and its use for this purpose is considered a very weak form of authentication.
OpenID Connect takes the best ideas from preceding identity protocols and incorporates them into OAuth flows, giving the best of both worlds.
More information on all of the above here: https://github.com/christiansmith/anvil-connect/wiki/Referen...
Can anyone advocating OpenID connect give a single sentence explanation of why people (developers and users) would want to use it vs limited scope oauth?