5 ms·
Generally, because managing passwords (both for the end user and for the server) is difficult, and there's no reason to get into the identity management busines
by cdcarter 8y ago
Generally, because managing passwords (both for the end user and for the server) is difficult, and there's no reason to get into the identity management business if you don't absolutely need to.
- WorldMaker 8y agoIt's just unfortunate that OpenID 1/2 or Persona didn't succeed. The "NASCAR" badging problem of OpenID Connect is a poor solution that doesn't scale. A wish for a decentralized solution that actually had user traffic so we could all DROP COLUMN password FROM user.
- zie 8y agoI understand the reasoning behind this, since it's hard to get right, but if we offload all of our logins to Facebook,Google and friends, they suddenly get WAY more information about us. You as site author are giving them access to all of your users, and you as a user of the site are giving them access to where you wander on the Internet. Plus if a breach happens on Facebook or Google, then the hackers get EVERYTHING including access to your site (as a site author). So there are definitely downsides to doing social login(s) as well, and it's not as clear cut as just "let Google and friends do it for me".
- BrandoElFollito 8y agoWhat WAY more information do they get? They know that I use the site and (to some extend) when. I am under the (possibly false) poison that the risk is to let the requesting site (HN here) request to much data from, say, Google (my age, shoe size and whatever they store about me)
- zie 8y agoThey get that you use site X (and y,z, and q too) , when you use those sites, and where you were when you logged in from(i.e. your IP, browser info, etc). For one site, not a huge issue maybe, unless it's ilovemesome<insert something disgusting here>.com But add this up across many, many sites, and they suddenly get loads and loads more information to sell ads to you with.
- BrandoElFollito 8y agoYes, this is true - but at least in the case of Google this is peripheral compared to what they have though my browsing (search, email, etc.).
- eikenberry 8y agoThe main problem is you still need to support password based auth unless you want to lock out part of your user base that doesn't have an account with the supported providers or doesn't want their login activity tracked by one of the providers.
- deathanatos 8y agoand doesn't wish to setup their own provider. I get that that is definitely not an easy thing to do, but an OpenID implementation doesn't have to force users to log in through some major social network, and I feel like your statement asserts that. (but even with that addendum, I agree, you'll probably still end up wanting to support password based login as a service provider. But as a user, I greatly appreciated not having to constantly get my password manager to meet some random list of requirements.)
- ams6110 8y agoI would agree, only I don't see what HN does as "indentity management." There's no mapping to a real person or identity. It's just a local login. HN doesn't care who you are in real life.