4 ms·
I have deep, deep objections to OAuth, and I hoped this article would espouse some of them, but it doesn't. Instead, this article is basically whining about "pr
by copsarebastards 11y ago
I have deep, deep objections to OAuth, and I hoped this article would espouse some of them, but it doesn't. Instead, this article is basically whining about "programming is hard" which is true but also something anyone trying to solve serious problems got over somewhere between high school and getting a real job.
OAuth is hard because it's pretending to solve a hard technical problem (logging in and sharing some private data securely) while actually solving an easy business problem (how do we (a big company) get smaller companies to outsource as much of their user data as possible to us). It kind of solves the hard technical problem (because bigger companies are better at hiding the data you give them from other companies who don't pay for it, and have all your data anyway). But if that half-assed solution to the hard problem is good enough for you, you aren't actually trying to solve it, you're just to persuade uneducated users you've solved it. In short, OAuth For Dummies would be a tautological title for a book.
I've heard it said that it's okay and even desirable to outsource everything in your business to other companies except your core service. But what service exists without users? If you can't get users to sign up for your service and give you their information, then I'd argue you don't even have users. You might as well quit. This isn't a question of "what's the best way to authorize users?" question it's a "do I even have users?" question.
- testrun 11y agoI do not know who is the uneducated here, but in the case of OAuth, the other company already has the user data. What OAuth enables is to use their information to verify the user. What this post is trying to say, is that the method stinks.
- copsarebastards 11y ago> I do not know who is the uneducated here, but in the case of OAuth, the other company already has the user data. No, they don't. Google, for example, doesn't have the entire signup list of all the users of The Old Reader, but they have a lot of The Old Reader's users, because The Old Reader outsources authorization for some of its users to Google. That's data that Google is collecting via OAuth, and you'd better believe they use that data. > What OAuth enables is to use their information to verify the user. That's what it enables for the OAuth consumer, but there are far easier ways of doing that. The difficulties of OAuth exist because OAuth doesn't serve the OAuth consumer's needs, it serves the OAuth provider's needs.
- testrun 11y agoOn the first point I think we are talking about two different things. I am not talking about the entire signup list of Old Reader, I am talking about a user of Old Reader that uses Google OAuth to access Old Reader. In this case Google already has this particular user data. Don't agree on the second one. What it does it serves the site owner needs. They can choose to provide OAuth or not. Some provide it to make it easier for their users to login, and they also provide their own authentication otherwise, other sites use OAuth only and some sites just their own. Most see it as a benefit for their users to only use one login. The benefit for the OAuth providers are stronger relationship with that particular user.
- copsarebastards 11y ago> On the first point I think we are talking about two different things. I am not talking about the entire signup list of Old Reader, I am talking about a user of Old Reader that uses Google OAuth to access Old Reader. In this case Google already has this particular user data. We're talking about different things because you missed my point a few posts ago when I said that the problem it solves is "how do we (a big company) get smaller companies to outsource as much of their user data as possible to us". User lists are data. > Some provide it to make it easier for their users to login If that's their goal, they're failing to achieve it. OAuth requires more steps than a simple username/password signup form, including going to a completely different site to give permission to log in with your data. Google/Facebook/etc. and other OAuth providers aren't stupid: they know that's not a good solution to that problem. If they really wanted to solve that problem they'd write a login library (something like Reddit's signup/login system) which would solve that problem better. The reason OAuth isn't implemented that way is that the goal of OAuth is not to make it easier to sign up and log in. > Most see it as a benefit for their users to only use one login. There is nothing that stops users from using one login everywhere; OAuth does not aid this in any way. I use the same login on all the sites where I don't care about the security of my account. You have yet to make any compelling argument that users or sites which use OAuth are gaining any benefit from OAuth. The only people who benefit from OAuth are OAuth providers.
- tboyd47 11y agoYour comment is dead on. OAuth2 provides a way for people to log into your service without really telling you who they are. Instead, you outsource the task of asking them who they are to another company. But if you don't care who your customers are, why are you asking them to log in? The whole concept makes no sense. And then when you consider that OAuth2 isn't even a protocol, but a "framework for a protocol," whatever that means. But sites use it, and will continue to use it, because it makes signup easier for new users. Here is what the author is missing from is "programming is hard" angle. Yes, programming is hard, but that in itself is not a bad thing, and it's even a good thing if the program itself is a good idea. But OAuth2 is not a good idea. It's not even a bad idea -- it's a framework for a bad idea.
- Bognar 11y ago> But if you don't care who your customers are, why are you asking them to log in? I may not care who they are, but I do care how their identity maps to information in my system. Simple functionality such as favorites or saved preferences doesn't require any information about the user, other than them being able to identify themselves as someone who has previously used the site.
- tboyd47 11y agoCookies or browser fingerprinting should do the trick, with gentle reminders to register. It's how most online shopping carts work. I'm not saying no one should ever use OAuth2, ever. Sometimes websites have to jump through weird hoops to get conversions. But as a web developer, it annoys me a lot.
- Bognar 11y agoCookies and fingerprinting tell me that the same browser is coming back to my website, but I don't care about the browser I care about the user. As a user if I go to a website on my work machine, my home machine, and my phone then I'd like my data to be available on each. I don't have strong opinions on OAuth or any other federated identity solution, I just think it's a specious claim to say that just because a system doesn't care about who a user is then that system doesn't care about the uniqueness of that user.