9 ms·
One-Click Anonymous Login
- deleted 5y ago[deleted]
- johnhess 5y agoAre you interested in the technical pros/cons, or the pros/cons for your user community? What's your company do?
- fapi1974 5y agoTechnical pros and cons. They way it works is that when you use their login you get prompted to register with them, which is done using a phone number. From what I understand they do not keep the phone number, they just send my site a token that says "yep, this person = that phone number"
- fapi1974 5y agoSorry - my company is an audio social network. Because we don't use a camera for our live streaming many of our members tend to be shy and possibly privacy focused.
- leshokunin 5y agoGetting a 500 error
- fuzzybear3965 5y agoDitto.
- nvartolomei 5y agohttp://web.archive.org/web/20210412193528/https://human-id.org/ http://web.archive.org/web/20210412193528/https://human-id.o...
- d33 5y agoContext if you first read comments then check article: this is here because the site was down right after it made it to the front page.
- avipars 5y agosite down
- arkitaip 5y agoWhat are the use cases for anonymous logins from a business POV? Even if you are legit pro customer privacy, this feels like it requires some fundamental changes in how your business perceives and treats its customers, not just their data.
- fapi1974 5y agoWe would definitely have to make some product changes, but the pitch (which I kind of get) is that we differentiate by using a privacy-focused, non-profit identification method, thereby signaling we value our users' privacy. Given the issues with Clubhouse of late I think this could have value.
- f430 5y agonot much business case
- ipaddr 5y agoEverything has a use case. Sharing a document where others can edit it but it's created by your customer would come to mind.
- fundamental 5y agoAt least looking at the archive.org version of the site it looks like just providing a way of building a username out of hash(phone number, website). I'm not seeing information about passwords or authentication and I wouldn't treat knowledge of someone's phone number to be at the same level of a password. So, to me it looks like marketing hype without substance. It would be useful for the site to be online and not giving 500 errors though to see if they had anything else.
- SparkyMcUnicorn 5y agoThis gave me a little more context: https://web-login.human-id.org/demo/ https://web-login.human-id.org/demo/ Which has all the same issues as SMS 2FA.
- ksm1717 5y agoEvery entity I interact with online collects my data. The saving grace is that they don’t often compare notes. I do not want any entity to have all of my data, even if it has my ssn redacted
- Groxx 5y agoPrevent abusers, single stable identity per human, but you can't cross-reference the identifiers and they don't store anything. ... color me suspicious. I'd read the technical details, but I can't seem to find any through the wayback archive.
- nexuist 5y agoThe front page boldly claims "no data leaks, no hacks." I am immediately suspicious. Nobody in their right mind with sufficient technical background is still claiming that in 2021, for any technical solution.
- endisneigh 5y agoI'd say the main con is that the site isn't reliable. I'm not being facetious. If you're going to use 3rd party sign on, being on the front page of HN shouldn't be enough to bring it down. Imagine if you posted your company's site instead of the underlying technology and your sign-in was negatively affected. My personal feelings, that aside, is that though many of us are privacy conscious, adding more and more dependencies to your site results in us having to trust more entities. Even if they don't store anything, we have to trust they aren't lying, that redirection is implemented properly, etc. I think the best thing you can do if you care about the privacy of your users is minimize the amount of information necessary. So if your site doesn't require email, don't take it. If a phone number isn't necessary, don't ask for it. Use usernames, only ask for an email when the user is doing something that would require it (e.g. they need a receipt). One thing that I love is when a site actually gives you a temporary username the minute you visit the "app" portion and you can use the site as if you created an account without having to do anything. That's usually a sign that the administrators really do care about you not jumping through hoops.
- wmichelin 5y agoDo you work on high traffic websites? Surges in traffic such as these often expose underlying bottlenecks. Give the people a break, I'm sure they'll work on fixing it after today.
- endisneigh 5y agoI'm not criticizing the people. Do you not think it's legitimate criticism that using a niche 3rd party login system can be bad precisely because they're still ironing out the kinks?
- cheriot 5y agoKeep in mind the alternative is that you are ironing out the kinks of a homegrown login system. The big thing in my mind is the ability to migrate away from a SaaS.
- tootie 5y agoSo, this doesn't look like they've actually broken any new ground here that you can't achieve with existing commercial products like Okta or Auth0. They're taking an extra step of asking you to store hashes of their hashes. Which actually feels less secure since if hackers get their hashes, that as good as getting clear passwords to login directly your site? I'm not actually clear on that. But either way, the diagram says they're hashing phone numbers, so presumably that means they authenticate by typing in their phone number which is a terribly password since you give you phone number out to people so they must also send a TOTP via SMS which is better, but not great. NIST has started recommending not to use SMS for out-of-band authentication. Either way, this whole chain of events just delegates authentication your mobile carrier. Same thing if you send a TOTP to an email address. It feels more seamless, but really you're just delegating auth to their email provider. No different that using OAuth.
- fapi1974 5y agoThis is solid advice - thanks. One of the things they mentioned is that this would help prevent botnets. Would OAuth also do that? Also - does the opensource, non-profit status change the dynamics?
- gmfawcett 5y agoNot sure why either open-source or non-profit would change the dynamics? Non-profits are still incentive-driven, and their goals may not align with yours; and open-source code is entirely independent of how data is collected, shared, etc. People do evil with OSS all the time. :)
- Kalium 5y agoNo, nothing about being open-source or a non-profit fixes the technical flaws in a system's design choices. It just makes this a poor design with an ethically pleasing organization behind it.
- Kalium 5y ago> Which actually feels less secure since if hackers get their hashes, that as good as getting clear passwords to login directly your site? I'm not actually clear on that. You're right. This turns hashes into passwords, and is distinctly a step down in security.
- wideareanetwork 5y agoUsers expect signin to work the way they expect it to work. I once implemented a non standard signin where all that was needed was an email link which kept you signed in. Users hated it. They actually went to the trouble of complaining and no doubt it lost me potential signups. These days I only ever do normal email and password signup.
- fapi1974 5y agoYeah, I asked myself the "friction question" too.
- subpixel 5y agoAs a developer I was a big proponent of 'magic link' style authentication when it was new. As a user who occasionally runs into this now, I hate it.
- kzrdude 5y agoWhy? I never run into it. I quite like the infinite login sessions, of course, so assuming the only friction is when those expire?
- bombcar 5y agoIt’s annoying AF for me - I can 1Password into a site with incredibly secure password instantly - but with a magic link I have to find my email client, wait for the email, click it, etc. as a sign in backup it’s nice but as the Main signup it’s a pisser.
- minitech 5y agoFollowed the links to here: https://github.com/bluenumberfoundation/humanid-documentation/blob/bd46a938068a80716c5208af4c3005c2ab5a4ad6/humanIDWhitePaper.pdf https://github.com/bluenumberfoundation/humanid-documentatio... > To make it more difficult to brute force, when generating the humanID Account ID, we will concatenate the phone number with a Salt Key (another string that will be appended before the hash). > sha512hash ( Salt_Key + Phone Number ) = Hash Result This is a complete joke (a SHA-512 of a phone number can be brute-forced on a typical computer in a fraction of a second). I doubt the rest of the protocols and cryptography are any better. Also, phone numbers are not unique identifiers for people. Real people, malicious or not, have multiple or no phone numbers (or phone numbers that can’t receive SMS). I haven’t found a clear answer yet as to whether SMS verification is the only proof step but it seems like that’s the case.
- TylerE 5y agoThat's why there is a salt?
- tyingq 5y ago"The Salt Key is the combination of lowercase letters, uppercase letters and numbers. For SHA512 hash which is 64-bits, the recommended salt key is 64-bits." And the salt itself appears to be private, and I assume, unique per user. So, I'm in no position to say whether that's "good enough", but it's at least not something you're going to brute force in a few seconds.
- godelski 5y agoHow's it actually work? How are you actually making the login anonymous? If a website is able to fingerprint us then are we still anonymous?
- fapi1974 5y agoTo be clear - this is not my product - I was pitched on it as a potential user.
- kevincox 5y agoIt seems like SMS-based auth, with the "gimmick" that I trust this website instead of your website. So already I won't use it because I don't want to authenticate via SMS. It also raises the immediate question of what happens when I change my phone number? But why should I trust this website more than your website? Unless your website is fully zero-trust it is probably better to trust you to throw away my phone number than handing my phone number to this company and other data to your company.
- freeopinion 5y agoThe site is toast, so I can't read how it works, but I will comment in general on 3rd-party auth. I refuse to use sites that require 3rd-party auth. If I have a problem logging in to your site, I want to reach out to you and get it resolved. I don't want you to say, "We don't have any ability to address auth issues on our own site. Take it up with <completely unrelated site>." I don't want my account with you to be suspended because I had a falling out with Facebook or Google or anybody else that is not you.
- ec109685 5y agoAny site using third party sign in should treat it as just one way of logging in. The verified email these providers return should always be able to login you in as well.
- dang 5y agoThe submitted title was "My company got pitched on anonymous sign in – curious to hear pros and cons". Submitters: please don't do that. If you want to add a question or a gloss on an article, that's fine, but do so by posting a comment to the thread. "Please use the original title, unless it is misleading or linkbait; don't editorialize." https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- deleted 5y ago[deleted]
- RileyJames 5y agoHmm this is something I’d like to implement in some sites. I’ve been considering integrating with something like ActivityPub to enable user accounts without “more user accounts”. Minimum viable user & social features.
- iou 5y agoWhy has this been up-voted so much? This is so bad compared to something modern like WebAuthN
- kwhitefoot 5y ago> Our Vision: One Digital Identity per Human – both Anonymous and Accountable Why would I want to use something that allowed me only one identity? And if I have to give away my mobile number it is hardly one-click. And a lot of the stuff that other comments have mentioned!
- aww_dang 5y agoExpect more pushes for a fixed digital identity. Check the id2020 initiative. Gatekeepers are not fans of the pseudonyms we've been using since the early days of the Internet. >Our Vision: One Digital Identity per Human – both Anonymous and Accountable...billions of fake user accounts undermining our societies.
- ANEDI 5y agoThere is interesting project called Idena. Prove you are human with validation as public turing test done on blockchain. There is simple one click login and it's used now on Gitcoin. Website: https://www.idena.io/ https://www.idena.io/
- supergirl 5y agoa lot of marketing and no substance. is it just like a jwt?
- bastianpurrer 5y agoone of the humanID founders here. Very much appreciate the feedback, and also appreciate those that addressed concerns before we could. Always open to those that want to help fix any technical issues they might find - the team is fully nonprofit & open source, you're more than welcome to help! Also, to be clear, while the site was down for an hour, the login never was, as we have set that up independently from the site.
- ChrisArchitect 5y agoclicked the 'Try' option. Got to the part asking for a phone number. Closed.