4 ms·
Why would you trust a website asking for an email and password more?
by far33d 16y ago
Why would you trust a website asking for an email and password more?
- NewHighScore 16y agoEmail is better because you are not locked into using some third party website to log in. You can set up an email server of you own if you wanted to.
- mike-cardwell 16y agoExactly
- meatmanek 16y agoOpenID works great for this too-- you can create your own OpenID provider.
- nuclear_eclipse 16y agoEven better, you can use your domain to delegate privileges to a third party service. Eg, I have my personal domain leetcode.net delegate OpenID authentication to myOpenID.com, but if for some reason I don't like that, or decide to host my own provider, it's as simple as changing my domain's delegation info, and I can continue to use the same OpenID url everywhere.
- far33d 16y agoSure - but that wasn't what he said. He said that requiring facebook makes him think that the website owner shouldn't be trusted with data. Which has nothing to do w/ lock-in on 3rd party websites. It has to do w/ the relative security competence of those who choose to use FB Connect vs. those who choose email.
- mike-cardwell 16y agoWho said anything about security? I would take a "Facebook only" login system to imply that the creator of the website makes bad decisions. I'd prefer to not hand over data to people who make such poor decisions.
- Lewisham 16y agoYeah, exactly. When I see a Facebook login, what I parse is "this site decided that it was a better idea to leave security to the professionals rather than hack something together. A secondary benefit is that I get to get through this signup in 20 seconds than 3 minutes." When I see a dodgy username and password form, what I parse is "I can't wait for them to email me back my password in plaintext, and then store it without a one-way hash."
- kenjackson 16y agoWhy do you think Facebook security is security by professionals? I fully expect that Microsoft and Google have a stronger set of security experts working on their various authentication and encryption methods.
- mikeklaas 16y agoBecause they are paid in the charge of the largest online authentication system in the world? That's not to say that they are the strongest professionals in the world, of course.
- Locke1689 16y agoThey actually have pretty broken security practices from what I've heard. Their security review before pushing live features is definitely as not as strong as Microsoft (I can't really say for Google, I don't know what their security review is like). Check out the Facebook Chat for an example.
- xiongchiamiov 16y agoHe didn't say that he did.