Anonymous Login
developers.facebook.com
developers.facebook.com
What this means is that users who sign in to your website with this are Facebook's users, not your users. Facebook controls them and decides if and when your access to them shall be revoked. At least with an email address, you can bootstrap an independent relationship. Not here.
Mozilla Persona got this right - authentication should be decentralized and establish an independent relationship between website and user. Too bad they gave up on it.
Wait, what if I want that? I'd say 95%+ of sites I sign up for I am just trying out. I don't want an independent relationship to be bootstrapped, I just want to play with the site. Chances are, after a week I will never see it again. But instead, I get a newsletter, and have to unsubscribe. Then I get a friend notification or something, and unsubscribe from those, or try to find out how to deactivate or delete my account.
> Facebook's users, not your users
Yes, that's true. I am a Facebook user. I have an account there, which I use. Why should I spread my email around to sites I don't really consider myself a user of, just because I want to save my game or explore the app or something?
The risks of submitting an email address are overblown. Websites are terrified that you will click the 'spam' button. They don't put those little 'unsubscribe' links at the bottom because they want you to click on them.
I was one of the early adopters of the Facebook platform and 'social login'. Now I think it's a menace. They aren't doing anyone, except themselves, any favors with this.
I share the Persona love but I don't think this is complete: yes, Facebook could zero-day you and drop support but it's really unlikely that they wouldn't announce something in advance which would allow you to pivot, leading to:
> At least with an email address, you can bootstrap an independent relationship.
You can also do this using a Facebook login by having a way for the user to enter an email address. The difference is that you can avoid hitting them for it up front and triggering the “Are they going to spam me?” worry which makes people question using your site in the first place.
You could introduce it at some point where it has a benefit to them – “Please enter your email address if you'd like new turn notifications”, etc. – or, were Facebook to announce that they're discontinuing this service, ask them for another way to login in. Most sites already have a bunch of separate social login services linked to a single identity, this is only one more.
It's also easier to sell a signup when you've got someone in a product they like but can restrict access until they commit. Want to upload a photo? Create an account with Facebook. Want to save your work? Create an account with Facebook. If you're just an anonymous user, you get the same dummy-data experience as logging in with a demo account until you commit and share your email.
I don't know if your audience will swing the same way, but I don't expect this is the magic lubricant you're looking for.
It remains one of the best auth components I've ever used, and I have zero issues from users relating to it.
What sucks is that at some point I'll have to remove this great component because they stopped working on it, and will inevitably sunset the hosted service.
Still a shame they are no longer pushing it, however.
It will also lead to many people having to maintain something that they were choosing not to maintain. i.e. a complex piece of software responsible for security.
Sort of, ish. The official server includes shims for Google and Yahoo!, so that you can log in to Persona directly through them even though they don't have Persona support directly.
If someone is worried enough about privacy - then why are they even logging in via their Facebook profile in the first place? Realistically you would just use a throw-away email account and then no one knows.
Secondly - as a developer - why would I want to accept anonymous logins? If I did - then I can just let them create a username + password with no email account instead?
However the are plenty of articles that say this form of sign up is not necessarily effective.[1]
For this idea to take off - you need to assume the reason for the current lack of uptake is that users dont trust the 3rd party with the Facebook data.
However I personally believe, and would have thought, that most people dont trust Facebook with the linked data, since they are learning more about you?
[1] http://blog.mailchimp.com/social-login-buttons-arent-worth-i...
And frankly, the user should be bailing out there. Regardless of Facebook's sketchy policy changes, they have demonstrated that they will at least do what they promised with my personal data, but there's no reason that I should a new app/service the same level of trust.
With "Anonymous Login" users don't have to worry that the app will be able to do nefarious things with their Facebook data.
I don't think it's really all that different.
A website asking for a friends list with no clear use case sounds suspicious.
I don't understand why any developer would use FB anonymous login when you can just use email which is equally as effective.
I think most people in the real world, outside our cozy tech bubble, trust Facebook pretty deeply. They give them their thoughts, their photos, their schedule, and their private messages to people. I'm not sure their really that concerned about Facebook also knowing that they signed into Candy Crush Saga XIV
Also a single tap is still often much easier than typing a full email address, especially on mobile.
This could be improved somewhat if iOS or Android had a way to autofill your email address on demand. Unless something's changed recently, the only way to do this now requires asking for permission to the entire address book which many people rightly consider a bad idea.
We have found that a significant number of users will just quit the app if presented with a "sign up or login" with Facebook screen at the beginning of the flow.
With this, they don't have to give us any personal data and can start using our app right away. If they want to activate social features later it is really easy to upgrade their token without having to worry about merging accounts.
Edit: regarding the user side, the problem for a lot of users isn't that they don't trust Facebook. It's that they don't trust the random app/website that is asking for their Facebook data.
Personally I feel it is the other way around.
I guess we'll see how successful this is to see what people really think?
I'd rather not be someone's product.
thats me 90% of the time.
I like this because it allows the developer to solve things like unique sync accounts and only ask me for more info after I've liked the app enough to want to do something like share it.
In a humorous way, this post illustrates that old problem well: http://thebloggess.com/2009/08/get-my-husband-off-facebook/
Even though that's not a problem today, I'm still skeptical of apps because of it. So I'll log in with Google+ or another service, but Facebook still makes me feel gross from those old experiences.
Email address, allowing me to use '+' as a mailbox extension. I'll use wtbob+yeldarbsite@example.net. Done.
> We have found that a significant number of users will just quit the app if presented with a "sign up or login" with Facebook screen at the beginning of the flow.
Yup. I refuse to log in with Facebook anywhere but…Facebook.
> With this, they don't have to give us any personal data and can start using our app right away.
I'd still be using Facebook to log in, so no thanks.
> regarding the user side, the problem for a lot of users isn't that they don't trust Facebook.
I don't. In fact, I trust your website with my per-website email a lot more than I do Facebook.
If it makes anything better, I'm one of those people that run away once you ask to log-in with Facebook, and that change won't make me start using it.
It helps overcome the username/password signup hurdle AND it helps assuage fears of random Facebook posting. I'm sure it will be a hit with the next semi-skeezy dating app.
For serious apps (business stuff), I don't see why you'd want this.
Secondly as a developer social login is nice because A) users like it (see above) and B) you off load much of the work of having to deal with authentication and authorization.
Because you want the ability to ban people without them being able to create a new account, but you don't care who they are. (E.g. if you are running an online poker site.)
But I'm not sure Facebook would bother doing so. Hopefully the privacy policy regarding anonymous login specifies what they will or won't track.
They may very well take advantage of it though; they certainly are able to do so legally. We'll see what the policy looks like.
They started by building what site owners and developers want - everything about a user without having to build a complex form and have the user agree to fill it out. And they ended up with what the user wants - to share nothing at all with the site owner and fill out no forms.
My guess is this will be stupidly successful, and good for absolutely no one, but Facebook.
Why? I see it being very good for Facebook users. I'm very happy about not giving any data about myself to random websites I want to check out just once. I especially look forward for the amount of spam (er, value-added marketing e-mails) it cuts out of the circulation.
The proper term for this is "Federated Login". Most enterprises have some form that's used for SSO.
I want to be able to use the convenience of Facebook login, but usually I don't because I'm worried about how much data the app I'm authenticating with has access to.
So, and please correct me if I'm wrong, this is just logging in using Facebook without (probably) sharing "any" data with the software provider, right?
This would surely attract site-owners by providing them with some kind of communication-channel to their users which is important for acquisition, retention, marketing and all that other stuff programmers usually don't like to do :)
The user can unsubscribe/delete account with a click and never gets spam in his inbox for sharing his contact details. Did Persona give away the email-address to site-owners or were there attempts at something like described above (even if persona were just to act as a proxy to your email via api)?
Yes, please. Give me a throw-away app-specific inbox but make sure that I can completely ignore it. It's not only programmers that don't like "acquisition, retention, marketing" - as a user I don't like being subjected to it either.
facebook knows who you are - but they just send a non-identifying string/GUID to the service who is trying to log you in. This is a consistent ID (so that service can build a profile) - but it does not contain any identifying data.
If anything FB is closing the loop.
>anonymous
Very funny.
"Sure it's anonymous, just trust us..."
Why isn't an entity with a more trustworthy past in handling privacy doing something like this? What entity would even qualify?