5 ms·
Another method is to delegate the registration and login flow to external providers, using OAuth. If you have to log in to a website via one of Microsoft, Goog
by gohohn 4y ago
Another method is to delegate the registration and login flow to external providers, using OAuth.
If you have to log in to a website via one of Microsoft, Google, Facebook, Twitter, etc. then, if implemented properly, there's no way of knowing if an account associated with this external identity exists already.
- mint2 4y agoGiving in my Facebook that centralized view and extra data… no thanks. Same with Microsoft and google.
- gohohn 4y agoThe only information they would receive is that you signed in to a specific website.
- godshatter 4y agoMost of those are trying to track me around the net for their own purposes. I'm not volunteering any extra information for them to profile me with. No thanks.
- gohohn 4y agoThe only extra information you would be volunteering is that you signed in to a specific website. In most cases, this is not really a big deal.
- godshatter 4y agoIf I don't want them knowing I surfed to somewebsite.com, why would I want them to know that I actually logged in to someotherwebsite.com? I get that people have different levels of trust for these services than I do. I'm just more cynical than most, I guess.
- bombcar 4y agoYou are also trusting the Oauth provider to never login as you for their own inscrutable purposes.
- gohohn 4y agoThat is true. But then many people put a lot of trust in the major providers in many other areas too, such as hosting their private files and email, holding card payment information, and so on.
- bombcar 4y agoYeah an email provider is basically Oauth with extra steps for ALL your accounts.
- MichaelCollins 4y agoAbsolutely. In the case of Facebook, it's easy to imagine them logging into websites as you to slurp up your contact list on that site. Don't worry, you agreed to it somewhere in the thousand pages of small print! Or as the case of twitter demonstrates, you're also trusting all future owners of the Oauth provider, whoever they may be. If an erratic billionaire with a penchant for breaking the rules whenever it suits him buys your Oauth provider, who's to say what he'll do with his new access? He could treat your accounts as his personal toys. Better hope you don't earn his personal ire when he's on another wine and ambien bender.
- another2another 4y agoLinked in used to (maybe still does) encourage you to provide them login details to your email so that they can scan it for potential matches.
- MichaelCollins 4y ago> this is not really a big deal. If it's not a big deal, then why do they offer this service "for free"? It's all part of their commercial panopticon. You're missing the forest for the trees.