8 ms·
All my side projects and any projects I control use exclusively social login. Here's why. 1. Its way easier on me. I don't have to worry about password resets
by jfaucett 9y ago
All my side projects and any projects I control use exclusively social login. Here's why.
1. Its way easier on me. I don't have to worry about password resets or users hacking an account in the site. OAuth and be done.
2. I don't have to deal with any outgoing or incoming emails and complaints dealing with login.
3. I don't have to worry about scammers, since google/facebook pretty much require phone, a non fake email, 2 Factor auth, etc to sign up. So I can put all that overhead onto google and get the added benefit that most of the users signing up are legit.
4. Legit users. I can't say enough how much having legit users helps the overall quality of almost any platform. Allowing people with a fake-email to sign up and create accounts allows for all kinds of headaches that are largely avoided by using exclusively social sign in.
5. Simplicity. One Click login, where the user immediately sees what information I want to collect and can say yes/no. Login/Sign-Up is done in literally one click.
- lancewiggs 9y agoThen I would never sign up to any of these sites. While I’ve been an edge case for a few years, I suspect it will be increasingly normal - especially for customers who are willing to pay.
- f2n 9y agoI am unlikely to use your site if it requires me to use a Google or Facebook login. Those companies already have too much power to fuck my life up, I have no interest in giving them any more.
- hirsin 9y agoWould a different social login provider be more acceptable? Github for instance? Something or someone that isn't as interested in using your data
- f2n 9y agoGithub maybe... I've been more hesitant to use them, as they control a significant portion of open source project's infrastructure, and could generally make a lot of headaches for me. If you don't have a simple email-based signup I'm going to be hesitant to use your site.
- duxup 9y agoWhat do you imagine GitHub..... doing?
- pen2l 9y agoWhile I'm sympathetic to your viewpoint and to a large degree share it, you are among a vanishingly small minority to not use a site or service just because of social login. 'jfaucett probably is fine sacrificing losing this small minority.
- jfaucett 9y ago> 'jfaucett probably is fine sacrificing losing this small minority. precisely. In my experience, this small minority can actually be subdivided broadly into two groups: those with very high data privacy concerns and scammers/spammers. It turns out that in my experience, the high level data privacy concern people have been the vastly smaller of the two groups, so at the end of the day you are sacrificing a tiny fraction of a fraction of potential users while simultaneously removing tons of scammers from your platform. Admittedly, the ratios probably vary depending on the particulars of your pricing models and potential scam vectors that can be applied to your software, also other factors such as local attitudes toward data privacy (my experience has been in the EU). You can also increase sign-ups by a large portion of the data privacy people by simply doing a lot of things to make your services legit i.e. have domain names registered to the real business or contact person, force https, have a high level overview of your terms and services that clearly and succinctly states how you use users data, have a verified https certificate, etc. But in general "social login only" has been so much better for me than mixed or only email logins I really would not want to go back to the alternatives.
- devgutt 9y agoAlthough I don't disagree, I suspect you are driving away a very interesting group of technically literate, even being small.
- biohax2015 9y agoI can guarantee you no VC or CEO cares about that in 99.99% of cases.
- paulcole 9y ago
- monk_e_boy 9y agoI was like you, until I looked at my unique login/pwd combinations.... there were so so many. I can't remember them all, i switch computers (I'm a teacher) a lot. Logins are so stupid, I've been able to look at my laptop to unlock it for years, touch my phone to unlock it.... login and passwords are going so i don't mind using google to log in for a few years while the rest of the world catches up. For students google log in is essential. Having to create an account, then click a link in an email, then use a site is too hard. It takes too much time and there are too many points of failure. So 99% of comp sci teachers are choosing sites with social logins. So future programmers are all going to prefer them.
- detaro 9y ago> For students google log in is essential. Having to create an account, then click a link in an email, then use a site is too hard. Where the hell do you teach comp-sci?!
- monk_e_boy 9y agoHave you ever taught a class of 35? About 5 of them can't even log into a computer - forgotten passwords, broken mouse, a locked computer that needs a reboot. What email have they entered? School or personal? Or their apple email?
- f2n 9y ago>I can't remember them all I can't remember most of my passwords, if I could that would be a serious security issue. Password managers are a must in this day and age.
- monk_e_boy 9y agoSo you turn up at a new school, they give you a temporary user name, password. You use this to get into the PC, then you use another teachers password to get into google classroom to read the lesson plan. Then I use my own to get into my work email, then my personal one to get into messenger to talk to my child care dude. A password manager is just another point of friction.
- dbielik 9y agoWhy not create a Facebook or Google account just for these websites? Or is it the cross domain tracking that is worrying since everyone's sites are tagged?
- bjelkeman-again 9y agoIt becomes a mess to track where you are logged into what. And cross domain tracking.
- digiwise 9y ago2 accounts can take care of this. You can have one account for life related things and another one specific for Logins. I personally don't care. As I have nothing to hide and I trust most of the businesses providing federated logins. Also, makes life a lot easier. Not only as a developer, but as a user.
- chme 9y ago> I personally don't care. As I have nothing to hide and I trust most of the businesses providing federated logins. Sorry, but every time someone says the phrase "I have nothing to hide" I have to roll my eyes at them. How is that 'argument' in times of the recent facebook scandal still a thing? I know that most people live under a rock, because changing habits is damn difficult and its much easier to make up arguments to support one-selves behaviour than to question and change it, but really these people should start waking up soon. It seems they are led to the corporate social media butchery where their personality and individuality is taken piece by piece and soled to the highest bidder. How much has to be taken from you before you recognize that you can be remote controlled by the organizations with power and money? And will you even have still the will to recognize that and try to change it or will you sedate yourself with the argument that you can trust big brother to watch over you, because he knows best and its so convenient not having to make changes or decisions anymore.
- EGreg 9y ago
- askvictor 9y agoshould be able to use any oauth provider, including github (as long as the service hasnt locked it to just g and facebook. i _do_ hate it hen fcebook login is the only option.
- gormz 9y agolol because logging into a website with google or facebook really does something valuable for them...
- benp84 9y agoOn point 2: people forget which service they signed in with, accidentally make multiple accounts and think their data is gone, and sometimes APIs are down (mostly LinkedIn) or throw errors, all of which lead to customer service headaches without an email/password reset backup. On points 3 & 4: I've seen more fake Facebook and LinkedIn accounts than I can count. Some users have dozens. I haven't looked into how they create them so easily, but they do. While it's certainly more hassle to get one than a fake email, there's still a ton of them.
- incompatible 9y agoIs it really so hard for scammers / spammers to create fake Google / Facebook accounts? What is so hard about creating any number of "non fake emails"? I assume a non-fake email (address) is just one that can accept incoming messages.
- Moru 9y agoGoogle requires a phone number nowadays. And you can't use the same phonenumber more than X times. (Not sure what X is but I hit it last week so had to go on the second phone)
- incompatible 9y agoI didn't know that. But if Facebook still allows sign-ups with an email address only, it gives a way in.
- throwaway47853 9y agoNo it doesn't (at least on the desktop version of the site). You can leave the phone number field blank on the 'Create your Google Account' form. For 2 factor authentication you do need it.
- Moru 9y agoYes it does, you can't get past the second stage. "Please enter a phone number". I'm sure this is different on some things, mabe number of emails created per IP or what country you live in. Google is a big entity, they can afford to treat some areas differently. > Verify your phone number > For your security, Google wants to make sure it’s really you. Google will send a text message with a 6-digit verification code. Standard rates apply
- Finnucane 9y agoI have an empty Facebook account with a pseudonym--the name of a fictional character, so it's actually obvious--and gmail address I don't use for anything. I set this up specifically to use with sites that use 'social' login. I've had it for a few years now, and as far as I can tell FB does not care.
- StanislavPetrov 9y agoI avoid Google, Facebook and all other "social media" like the plague due to privacy issues. I don't have any social media accounts and therefore wouldn't be able to log into any of your projects.