12 ms·
Twitter has inexplicably turned off access to sign in with Twitter SSO
- AlchemistCamp 4y agoWhat is this doing to Medium? At least when I used it, it was deeply tied to Twitter.
- crooked-v 4y ago"Turned off", or "the last person maintaining it quit and now nobody knows how to fix it"?
- stanislavb 4y agoYeah, I'd bet this is the case. They just don't have anything to gain by turning it off. Do they?
- TheSwordsman 4y agoCould be some really awful ploy to get more people to pay for Twitter Blue.
- rsynnott 4y agoWell, it is strictly speaking an API, and we all know how Saint Car feels about APIs... (I would not be surprised if it was literally this, some sort of absurdist "no exceptions" aspect to the API-killing diktat.)
- nikanj 4y agoI’m mostly impressed how shite the ”webscale” codebase is, if everything bursts to flame the moment the programmers stop babying it. Considering how many man-hours they’ve poured into the product, you’d think it would be somewhat bug free
- ultrarunner 4y agoI wouldn't exactly characterize this as "the moment" that it stops being babied. Twitter agreed to the sale a year ago, and the sale was completed last October, about 5 months ago. Plenty of time to accidentally break a dependency somewhere, even if they're not actively developing or maintaining it.
- hammyhavoc 4y agoIt could be a ruse for folks to get rehired.
- drewbug01 4y agoCome back in a few years, when you’ve written software at this scale and at this velocity. I’m interested to hear what the experience has to teach you, and to see how you grow as an engineer beyond this kind of uninformed nonsense.
- userbinator 4y agoI'm not the one you're replying to, but I've worked on software, for far more critical infrastructure than Twitter, that has run unchanged for over 3 decades. You only hear about the failures. You don't hear about the systems that keep on working. and to see how you grow as an engineer beyond this kind of uninformed nonsense. In other words, "grow as an engineer" means "parroting the lies that keep you employed"? As the saying goes, "it is difficult to get a man to understand something, when his salary depends on his not understanding it". And that explains the sad state of most "modern" software.
- kasey_junk 4y agoThe comment specifically asked for advice on software that changed with the same velocity. It’s the rolling out changes part that adds the interesting risk.
- deleted 4y ago[deleted]
- 4y ago
- justinclift 4y agoAm half expecting some serious security related bug has been found in their SSO, thus them turning it off without warning until it's resolved. But, who knows...
- chris_wot 4y agoTo expect that, you would have to assume a level of responsibility to end users that I find highly unlikely at Twitter right now.
- justinclift 4y agoWhat the heck, someone flagged this?
- aaronbrethorst 4y agoI assume this was unintentional and occurred because no one who's still there knows how these systems work.
- TheSwordsman 4y agoWorrying about situations like this is exactly why I try to avoid SSO at almost all costs for personal stuff, and instead prefer to use a username/email and a unique password. I really feel for any developers who are impacted by this, as well as users who may not be able to get to some of their data. Hopefully it's temporary, although with the Doge icon who knows...
- chaz6 4y agoI completely understand this, but for me this would be very difficult. I use mfa with 3 tokens (one I keep on my person, one by my home computer, and one in a safe place). If one were ever to be lost or damaged it would be a nightmare to have to go through every online account to replace it with a new token.
- askvictor 4y agoSSO idp would generally pass an email address through to the service, no? I could be mistaken about that, but if so, then you'd still have access to a password-recovery-by-email if the identity provider shuts down.
- TheSwordsman 4y agoI've seen many systems that disallow the password reset flow when you sign in via SSO, since the expectation is that you as the service provider are not the authority for the user's identity.
- alex_suzuki 4y agoCan confirm, happened to me just yesterday for ngrok.com/Login with Google.
- fhrow4484 4y agoAvoiding SSO to keep access even if you loose access to bigCo email has been working well, but unfortunately more & more websites are moving away from password to instead verification code in the email. Sure there are advantages to it, but if the email is bigCo, it effectively has the same drawbacks as SSO from same bigCo (i.e unfair account suspension, you're screwed) With email+password, even if you lost access to let's say your Gmail, you can still login with that Gmail address and your password and go change the email in your account profile.
- faceloss 4y ago[dead]
- progrus 4y agoMaybe because very few people have even heard of this, much less used it?
- viraptor 4y agoThat's irrelevant. You don't kill a service like that without a public deprecation plan and a lot of communication. Both users and services that relied on it need time to migrate.
- spicyramen_ 4y agoThis is what normal enterprise facing business do, is really unacceptable that Twitter did that without notice, we normally go through a legal and communication process before we turn off the lights
- dylan604 4y agoI don't know about that. I've seen enough websites that have specifically removed social logins, so it appears that there is an awareness that the feature was "strings attached" kind of thing. And no, these are all tech oriented sites I've seen this on either.
- progrus 4y ago[flagged]
- SanjayMehta 4y agoYes. It was a DIY repair website and a few months later they gave it up. Can't remember the name. ifixit had sso via yahoo et al as well and one day it just broke.
- deleted 4y ago[deleted]
- riffraff 4y agoYes, a bunch of times. It's on the advent of code website for example, which is pretty popular.
- RandomWorker 4y agoOn a side note, I haven’t been able to login to Twitter for a long time. Every time I try with email, phone or username it prompts me that they can’t find user. When I search my own username without logging in it just shows up perfectly. The login has been broken for a long while now.. I hope they are tooling away and fixing it, but unsure
- r00fus 4y agoI have a working login on a single laptop. I can't login anywhere else since Twitter revoked the SMS 2FA option (I had real MFA setup years ago). Oh well, twas fun while it lasted.
- rschoultz 4y agoI was happy seeing this news headline, as Twitter stopped accepting my TOTP after I successfully changed my password in December. I haven’t been able to log in since then, Authenticator step failing. Alas, it seems as if I missed the window; 2FA is now back being required.
- shrubble 4y agoThere is some sort of worry at certain large companies over specialized phishing/ransomware, I have heard; whether this is related, I don't know...
- gotoeleven 4y agoWow only $50 billion of someone else's money to kill twitter. A total bargain for humanity.
- joduplessis 4y agoTwitter seems to be broken on Chrome too - at least for some users. I logged out & now cannot log in. Firefox works, but just super frustrating.
- joduplessis 4y agoFor anybody where this is a thing, copy the "auth_token" cookie from FF to Chrome. I also copied the "twid" cookie for extra measure (seemed relevant) - but I'm not sure if it's necessary.
- ilt 4y agoDoes it have anything to do with Post.news going live, given that Post uses Sign in with Twitter as one of their login options?