15 ms·
Introducing Google+ Sign-In: simple and secure, minus the social spam
- mikeevans 14y agoThis is an interesting feature: https://developers.google.com/+/features/play-installs https://developers.google.com/+/features/play-installs
- shawn-butler 14y agoIsn't this a recurring complaint of HN users? They go to a website in a browser and it tells them to download their app. The complaint usually goes if I wanted to use your #@#%@# app I would be using it, I'm using your web site. Seems spammy to me and also android only. Really getting skeptical of the "gadgetification fanboism" of the web.
- cbhl 14y agoThis is subtly different -- it sends the app to your phone when you're logged in on the desktop.
- marcamillion 14y agoBut isn't that worse? You are browsing an app that you logged into with Google+ and now all of a sudden it's installed on your phone?
- cbhl 14y agoI dunno, Simple locks you out until you download and install the app so you can use the app once to create a signature for their agreements. In such a flow, I'd rather that the intent be spawned from a click on my computer than from me having to go to Google Play online/on the phone and search for it, etc. (Google can install anything on your phone at any time, in theory, because of the way Play works. So if you're worried about "all of a sudden it's installed on your phone" you probably don't want an Android device.)
- Shooti 14y agoYou have to reach some Google-controlled threshold of app quality before you can use it, according to this: https://developers.google.com/+/features/play-installs https://developers.google.com/+/features/play-installs
- dannyr 14y agoIt's not all of a sudden. You have to click "Install" for it to be downloaded on your phone. It's not automatic.
- marcamillion 14y agoAhh...ok. Now that makes sense. I was under the impression that it detects that you have an Android phone - based on your Google profile - and it automatically does that. Well that's cool.
- JoshTriplett 14y agoSmart: with people starting to become aware of just how much access Facebook apps get to your social network, and already well aware of how much apps spam that network, offer apps that put the user in control of that: https://lh3.ggpht.com/-6MCVkHL9Rbs/USvqcyXRUCI/AAAAAAAABGI/oIS8AKHRBkk/s1600/3sharing_is_selective.png https://lh3.ggpht.com/-6MCVkHL9Rbs/USvqcyXRUCI/AAAAAAAABGI/o...
- masklinn 14y agos/put the user in control of that/give it to google instead/
- JoshTriplett 14y agoInherent in any hosted service, which includes most social networks. In a 1:1 comparison to Facebook, that doesn't seem like a relevant issue, though to the extent it matters I think Google has a better reputation than Facebook there. Many people already see Facebook as the company that makes privacy difficult.
- kzrdude 14y agoI know this is silly but my view is: Fool me twice, shame on me. Facebook was first and I was fooled. I will not be taken in by Google+ or any other similar service.
- weareconvo 14y agoThere is simply no comparison in the manner Google treats your personal data with Facebook's attitude toward it. At Google, as a dev, gaining access to personally identifiable information (that was hashed, anonymized like crazy, and scrubbed in every possible way to make damn sure there's no way the dev using the data could possibly track down any of the users) required jumping through so many hoops and getting so many different approvals and reviews it felt almost paranoid. At Facebook, for years, they had a master password that could access all information on anyone's profile. They would just flat-out give this password to every single new hire, even people who weren't working with the data directly.
- pgrote 14y agoCan anyone find a working example outside of Google of the 2 Step authentication working with the Google+ Sign-In?
- pgrote 14y ago2 Step doesn't work on USA Today. You get: Unauthorized request. Error 400
- marban 14y agoApple should have long released an equivalent for iCloud accounts.
- deleted 14y ago[deleted]
- kmfrk 14y agoThey are still working hard on something after the Mat Honan hacking < https://encrypted.google.com/search?hl=en&q=mat%20hack#hl=en&sclient=psy-ab&q=mat+honan+hack+apple&oq=mat+honan+hack+apple&gs_l=serp.3...1409.2092.0.2905.6.6.0.0.0.0.142.784.0j6.6.0.les%3B..0.0...1c.1.4.psy-ab.t8FXRwTZNlI&pbx=1&bav=on.2,or.r_gc.r_pw.r_cp.r_qf.&fp=9ebc75283e7b2b59&biw=1440&bih=779 https://encrypted.google.com/search?hl=en&q=mat%20hack#h... >.
- wereHamster 14y agoAs a developer, how is that different from logging in via Google OAuth?
- mtrimpe 14y agoSkip 50 seconds into the video and you'll see the killer feature here: a seamless handoff to your companion mobile app. It seems they're even offering analytics with it: https://developers.google.com/+/features/play-installs https://developers.google.com/+/features/play-installs
- jianshen 14y agoVery interesting feature. App associated with web page must be free and "meet a quality threshold" determined by Google. [0] https://developers.google.com/+/web/signin/android-app-installs https://developers.google.com/+/web/signin/android-app-insta...
- amalag 14y agoSeems like it enables sharing within your app.
- avodonosov 14y agoNo difference IMHO, here is the link to google+ platform API doc: https://developers.google.com/+/api/oauth https://developers.google.com/+/api/oauth
- m_eiman 14y agominus the social spam Somehow I find that hilarious.
- BruceIV 14y agoYeah ... speaking of "social spam" does anyone else get a "make new friends on Google+" page about 10% of the times you try to go to plus.google.com ? The persistent annoyance of that page was a major reason I went back to Facebook from G+, and now just use it as a Skype replacement.
- protothomas 14y agoI honestly thought from the title that the post would be a mea culpa for just that.
- rm999 14y agoThey ask me to upload a photo of myself 100% of the time I visit the front page of google+. I actively avoid it now.
- OGinparadise 14y agoEverything they do lately seems designed to trick you into doing something, signing for a Google service, joining G+, clicking an ad by mistake, downloading Chrome ... What the hell happened to the Google we knew?
- jbigelow76 14y agoQuarterly earnings reports
- papsosouid 14y ago>What the hell happened to the Google we knew? It never existed, and people were pointing that out this whole time.
- fryguy 14y agoMore than 10% of the time on facebook, I get a "try out these new games your friends are playing" (even though I've rarely played games on facebook), which takes up roughly the same amount of space as the google+ one does.
- danso 14y agoOK, I'm going to go off-topic and sound like a crank...but is the font-size for Google's blogs kept at 13px because: 1) To keep consistency across every service (search, analytics, maps, etc) 2) Because it's what users like, according to in-house studies 3) Because...why change it? Not all the Google blogs use Arial (http://chrome.blogspot.com/ http://chrome.blogspot.com/ uses Open Sans). I'm not trying to be completely snarky here...If it is indeed a best practice, then that's good to know. The width of the Google blogs do conform to showing 80-or-so characters a line, though at 16px, the characters-per-line is about 70, which isn't bad either. (yes, I know HN is at 13px too...but a discussion board with variable length of text and a higher value in being able to see more entries at once is different than the narrative paragraph form)
- blaze33 14y agoSo that I'm still able to read it on my 640x480 CRT screen. Backwards compatibility is serious business at Google. Joking aside, it's a 62.5% x 1.2em font size which is rendered as 12px (at least with my chromium/ff defaults). Probably too small for most readers nowadays (some would certainly agree cf. http://informationarchitects.net/blog/the-web-is-all-about-typography-period/ http://informationarchitects.net/blog/the-web-is-all-about-t...).
- deleted 14y ago[deleted]
- newishuser 14y agominus the social spam... for now while we try to gain users. If they were serious about it, they'd put it in a non-changeable clause in their TOS. Otherwise it's just marketing fluff.
- sunils34 14y agoAnyone else having trouble working through their examples? It seems like they haven't made their example repositories public yet. https://github.com/googleplus https://github.com/googleplus
- willnorris 14y agoThat's the right GitHub org, the samples should be showing up there soon.
- gguuss 14y agoThe first set of samples are available now.
- bitcartel 14y agoDoesn't the combination of Google+ Sign-In and Google Wallet remind you of Microsoft Passport[1]? I wonder if people who had concerns over a decade ago, will have the same concerns now. [1] https://en.wikipedia.org/wiki/Microsoft_account#History https://en.wikipedia.org/wiki/Microsoft_account#History
- Groxx 14y agoExcept that Passport was embedded in the OS. And if I remember correctly, a royal PITA to set up with multiple accounts, or manage your existing data. I infinitely prefer this to be part of the internet instead of the OS, where it's easier to support multiple simultaneous logins.
- anoncow 14y agoThis wil be embedded in their OS too...
- Groxx 14y agoBut not in Windows, OSX, or Linux, where Chrome runs as an application. And it's likely to be embedded (like the normal Google account embedding) in stock Android devices, but not some forks or some carrier modifications (since Google accounts aren't required for any of the features any more). The same cannot be said for Windows. Especially when Windows held an overwhelming monopoly on desktops, unlike Android.
- vvhn 14y agoandroid is going to get an overwhelming majority too. Pretty soon even the basic $30 phone is going to be a smartphone likely running android. iPhones are going to keep on growing at a healthy rate but their numbers will dwarf against android.
- Djehngo 14y agoI don't know much about the specifics of facebook apps, but could anyone outline the differences between facebook's approach to apps and google+'s?
- deleted 14y ago[deleted]
- ecaron 14y agoMost interesting point: http://www.thefancy.com/ http://www.thefancy.com/ (the promo site in the video) ISN'T EVEN USING THE SERVICE!!!
- fyi80 14y agoHmm, looks like the blog post went up before the partners rolled out to their public-facing sites. None of the partners I spot checked have G+ login yet.
- deleted 14y ago[deleted]
- sethjs 14y agoHey there - this is Seth from Google+. The launch partners will be rolling out Google+ Sign-In over the course of the day.
- mynameisvlad 14y agoFyi, the /apps link also doesn't work on my account.
- sethjs 14y agoIt should shortly - the roll-out takes a few hours to get to 100%.
- ecaron 14y agoOn an unrelated note, thanks for joining HN to participate in this discussion. It is really refreshing to know that Googlers like yourself and Matt Cutts are engaged in their community - it makes it much easier to have faith in the technology collaboration vs. when the movers/shakers sit behind a walled garden.
- mtrimpe 14y ago
- znowi 14y agoApparently, this worked out so well for thefancy.com that they took it down. I can only see the usual suspect: Facebook and Twitter sign-ins. In fact, I've checked all the sites listed in the article - none of them have Google+ sign-in. Also, they say you sign-in via Google account, but I suspect it also requires a Google+ profile in order to use this feature.
- tiziano88 14y agoAt the end of the article it says that they are rolling it out gradually.
- tomkarlo 14y agoIt's fairly obvious you have to have the announcement first, then the rollout on major sites (that aren't run by Google.) If the reverse happened, it would be seen as a foul-up. Facebook did the same when they announced "Likes" on external web sites.
- kmfrk 14y agoGreat to see an alternative to Facebook log-in. It's usually either Facebook log-in or e-mail based log-in, which works really poorly on mobile, when you don't have something like LastPass to autofill.
- deleted 14y ago[deleted]
- fyi80 14y agoIt's almost as thought Google designed the service for the benefit of users (who will then vote for developers with their feet) than for the benefit of spammers....
- deleted 14y ago[deleted]
- nailer 14y agoIf the repos were meant to be for custom partners, so would the docs mentioning them.
- seldo 14y agoPlease correct me if I'm wrong, but it seems there's still no offline permission to share on a user's behalf. It seems to be a deliberate design decision, but it makes life tricky for somebody wanting to make a social media management platform (ahem) since there's no mechanism for scheduling future posts, etc.
- BenoitEssiambre 14y agoI wonder if Apple's rejection of apps that track their users* will result in this API being blocked on iOS? * http://www.tuaw.com/2013/02/26/apple-rejecting-ios-apps-for-cookie-tracking/ http://www.tuaw.com/2013/02/26/apple-rejecting-ios-apps-for-...
- wutbrodo 14y agoApple's not rejecting apps that track their users, it's rejecting apps that don't use Apple's user-tracking system. Also, what Apple was trying to combat was persistent tracking without user knowledge (done originally using iOS's exposure of device ID, which was deprecated, and now with these "cookie" tracking implementations). Allowing a user to initiate sign in to an app is a far, far cry from that (and it would be preposterous for iOS to disable the ability to log in to apps).
- hmbg 14y agoI'd guess it will work the same as with facebook login. If you have a good reason to get your users private data, you may do so (using facebook, twitter, google+, etc). If you only need a login mechanism, you need to provide an alternative that does not collect user data beyond what's strictly needed for your app. At least that's what apple's reviewers told me when my app was rejected.
- paddy_m 14y agoIf google wants me to use and depend on their services they need to take google apps for domains seriously. I have three google apps for domains accounts, and a regular gmail account. One apps for domain account is tied to my job, another my personal domain, a third to a former job/personal domain that I registered services with. I used my gmail account to access services that google doesn't make available on google apps for domains. It seems that no matter which google service I'm using, I'm logged into the wrong account. I frequently can't log out from the other account properly on the login page so I have to go back to a mail interface. It is an utter mess. I don't care about google connecting the dots and realizing that I'm the same person in all the places. They make it so frustratingly hard to use and depend on their services that I'm actively looking for alternatives. Linkedin handles it fine, when someone tries to friend me on my professional email address with linkedin, they know that I'm the same person. Google+ doesn't. I don't have a Google+ account on my preferred email account because I can't figure out how to enable it for that domain. I get Google+ friend requests regularly on every email address I have.
- raldi 14y ago> It seems that no matter which google service I'm using, I'm logged into the wrong account. Can you give an example of a series of actions that leads to this? I'm logged into two separate Google accounts at pretty much all times, and I never run into trouble. I'm curious as to what the difference is between our two usage patterns.
- rjd 14y agoThis happens to me all the time, my company hasn't allowed youtube (plus a swathe of other stuff). But youtube gets me annoyed the most. I usually get a hyped 'check this out' friend a friend on IM, then I have to spend what feels like an absurd amount of time swapping accounts and fighting against chrome modals which is always prompting the wrong account details for login. When I'm finished I have to log out and back into my work account. Total pain.
- raldi 14y ago
- david_glazer 14y agoTo ecaron and others asking -- we're doing a gradual rollout over the course of the day, as are our launch partners. You'll see the feature in their apps soon.
- jug6ernaut 14y agoNot on topic not off topic. But until g+ allows linking of multiple gmail accounts to one g+ account i will never be using it. Ever tried switching email address on g+, nightmare...
- modeless 14y agoThe support for that isn't in G+, it's in Gmail. Gmail supports sending and receiving mail from multiple addresses. The other addresses don't even necessarily have to be Gmail accounts. It's easy to link all your email accounts together into one Gmail inbox.
- jug6ernaut 14y agoYes I am aware of this feature in Gmail, but this is not what I am referring to. What im referring to is when contacting other people through g+ it uses w/e email address is associated with g+. This is not always idea, I don't want everyone to know about my email address. Even if u have another email address it is impossible to contact other users using anything but the one email address associated with the account. Also afaik you can link other NON google email addres, just not other google accounts...
- modeless 14y agoYou can link non-Google email addresses to Gmail. Even if they don't support mail forwarding natively Gmail can retrieve the mail from them using POP3.
- bsimpson 14y agoI've never used my GMail account, because bsimpson is a common name and I get all kinds of spam/wrong addresses there. I have Google Apps set up on domains I control for business and personal projects. G+, like GMusic, Wave, and all the other cool Google goodies, launched for GMail only. So, I made a G+ for my GMail address. Then, I heard about Data Portability and the ability to migrate G+ accounts. "Finally, someone at Google understands that people have multiple accounts!" I ran their app, had my account frozen for a week for the 'migration', and created a new G+ for my personal domain. Bizarrely, they didn't delete my old G+ account. I used to have a G+ account tied to the wrong e-mail address. Then, I tried Google's roundabout solution. Now, I have two G+ accounts. =\
- lnanek2 14y agoReminds me of the huge threads of people upset about needing Google+ accounts to post reviews on apps on Google Play now, lol. Guess Google tried eating their own dogfood on this one and it didn't go over well.
- StavrosK 14y agoWait, does this mean apps can finally post to G+? It looks like I can finally write a simple app that can cross-post my Twitter stream to my public G+ circles.
- melvinmt 14y agoFrom the article it seems that app updates are boxed in their own page.
- dragonwriter 14y ago> Wait, does this mean apps can finally post to G+? Apparently; the "Moments" API which supports this (which has, I think, been in limited, trusted-tester use for something like 6 months) appears to now be general availability as of the API documentation update today.
- mixedbit 14y agoGreat, add to this 'minus centralized' and I'm all in. Or wait, Mozilla Persona already does this.
- superuser2 14y agoDpesn't Mozilla hold the map of emails->passwords for Mozilla Persona? That's pretty centralized to me.
- mixedbit 14y agoAny domain can authenticate its users, Mozilla acts as a fallback if a domain does not do this. At this moment most domains do not directly support Persona authentication, so almost always the fallback is used, but the system is decentralized by design.
- brown9-2 14y agoNice dig at Facebook here: In addition: Google+ doesn’t let apps spray “frictionless” updates all over the stream, so app activity will only appear when it’s relevant (like when you’re actually looking for it). edit: referring specifically to how Facebook markets it's sharing options as "frictionless": http://en.wikipedia.org/wiki/Frictionless_sharing http://en.wikipedia.org/wiki/Frictionless_sharing
- OlavHN 14y agoIf all you want is a simple, privacy friendly login then check out Mozillas persona: https://login.persona.org/ https://login.persona.org/ Chances are your users won't have it already, but it's the only single sign-on solution I would use without calculating how much privacy I'm willing to "sell" for not having to register yet another time and remember yet another password.
- sergiosgc 14y agoSecond that. Mozilla persona is fully distributed and not owned by a single entity. Moreover, it sounds like great engineering: do just one thing and do it well. I hope it becomes the universal single sign on of the Web.
- callahad 14y agoThanks! The Persona team is working hard to get past the "your users won't have it already" bit. 1. By the end of March, we'll turn on a Persona <-> Yahoo (OpenID) bridge, followed by one for Google (OpenID) and Hotmail (OAuth). Net win: A billion+ users can fully complete a first-time login with Persona using just three clicks. (Try it today! Use a Yahoo address at http://beta.123done.org/ http://beta.123done.org/) 2. A subset of the team is working on a Persona-backed replacement for Firefox Sync. Net win: tens or hundreds of millions of additional users added to the "Persona-ready" camp. 3. The upcoming FirefoxOS phones all have Persona baked into the default Marketplace. Net win: time will only tell. The above projects just streamline the initial onboarding experience: anyone can use Persona right now with any email address. FWIW, last time I checked, Persona's is averaging > 13,000 daily login transactions over a rolling 7-day window. I don't want to derail, but if you have questions or need help getting Persona set up on your site, please free to email me.
- combataircraft 14y agoAfter I lost the Youtube account that I used for 4 years, thanks to their fucking robust login service: Go fuck yourself, Google If you guys wanna see the future of this project, just try to create an account and upload a video in Youtube. Youtube is a Google company, and they fuck Youtube's membership system up.
- LilValleyBigEgo 14y agoOh good, now every time I sign into a website it's going to nag me to install their app so I can have an incomplete version of their site on my phone that I can't pinch zoom.
- neves 14y agoWith this new signin, will it be possible for someone to develop an application that automatically publishs my site RSS feed in Google+?
- robot 14y agoTerrible idea. I hate the (mis) connected nature of google services. E.g. I don't want to see Google+ contact's recommendations on my youtube page. Now I can't imagine the same happening with even other apps.
- robomartin 14y agoAs I see Google expand it's service offerings I find myself excited with the potential yet refraining from using any of these services for a very good reason: As an entrepreneur you are always up against the very real probability of Google shutting down your account due to unknown violations. This topic has been discussed on HN before. I have seen it and experienced it first hand with clients. You account is auto-magically tagged and permanently suspended and you are screwed. Say goodbye to your docs, email, storage, adwords, adsense, plus and now logins. I would really like to hear from someone at Google on the reasons why your company will not come out and offer: (a) A solid guarantee of non-termination of services (b) Real customer service (c) A sensible mechanism through which honest users of your services can deal with TOS violations (and learn how to fix problems) without risking loosing it all. There's more, but I'm busy. The point is that Google offers a lot of neat stuff but the risk is too great. It's like jumping off a plane with a parachute while someone retains control of a "deploy disable" mechanism. You don't know if you are going to crater yourself on the fifth, the hundredth or the nth jump. You just know that it could happen and you will never know why.
- chetanahuja 14y agoYes this is a serious problem. I do have a lot of my data tied up in google accounts but I still fear the sudden, unexplained ban-hammer coming down on me with no way to contact an actual human to ask questions off of (see this as a hilarious example of google's support for paying customers: https://plus.google.com/114419328456762929144/posts/NAJbzrZwWNj https://plus.google.com/114419328456762929144/posts/NAJbzrZw... )
- weareconvo 14y ago> A solid guarantee of non-termination of services If they terminate your account, it's because they had a reasonable suspicion that the account violated their TOS. So I guess this one is actually related to not knowing what the violation was, and accordingly assuming it was for no good reason. I didn't work on the Policy team - I was a dev - but I seriously doubt anyone there could terminate peoples' accounts without reasonable suspicion of a violation and get away with it. The checks and balances are too tight. > Real customer service Google does have "real customer service". However, as far as I know, it's reserved for the people who are paying Google money for whatever reason. In general, any of Google's free services have so many tens of millions of users that it would be ludicrous to guarantee any level of service for every single one of them. As to the general complaint about the very real possibility of being cut off from your data, that's a risk wherever you go. Drives fail, servers get hacked, someone accidentally hits "delete everything" instead of "refresh monitoring dashboard"... etc. At least with Google Take-Out, they make it incredibly easy to download whatever data you have on there periodically for the purpose of doing backups.
- meh02 14y agoWhy does the app install feature have to be tied to Google+? Android and Google+ are totally separate things. Please give Android developers the equivalent of Apple's app banners without jumping through hoops and sending people to Google+.
- bsimpson 14y agoI've already taken the time to implement a server-side login using OAuth2, as documented by Google here: https://developers.google.com/accounts/docs/OAuth2WebServer https://developers.google.com/accounts/docs/OAuth2WebServer According to these new docs, I need to use the Google+ JS to do client-side authentication, then pass the token to my server: https://developers.google.com/+/web/signin/server-side-flow https://developers.google.com/+/web/signin/server-side-flow I have no interest in building a new code path to support Google login, when I can use the OAuth setup I'm already using for 3 providers (inc. Google). It would be nice if you'd just post the CSS or PNGs you're branding as Google Login and let me use the backend I've already plumbed.
- bsimpson 14y agoI found the actual button design guidelines, and noticed that their launch partners (FitBit and The Fancy) have designed their own buttons in the same style as Google's JS buttons. Here are the design guidelines, PSDs, and PNGs: https://developers.google.com/+/branding-guidelines https://developers.google.com/+/branding-guidelines
- nullc 14y agoHow does this compare with Mozilla Persona? Persona uses cryptographic tokens so that identity providers can't spy on what sites you're using, and can't selectively deny service to various sites. I think that people should resolutely refuse to use any identity service that doesn't have at least those properties.
- mcovey 14y agopersona is an actual trustworthy idp, google ... you are the product.
- jacquesm 14y agoGoogle+ is social spam, and one of the few varieties that is extremely hard to get rid of. Most of the other ones you can simply blackhole.
- hakaaaaak 14y agoI don't want to use Google+ because everyone I care about uses Facebook, and even that I'm growing tired of and use less than I did for a few years. I'll continue to use my Google (Gmail) account for authentication to StackExchange and a few other sites, because it doesn't make me use anything but Gmail. But, if Google starts forcing me to use Google+ actively, I'm going to stop using it for authentication.
- avodonosov 14y agoWhat is so new? It's OAuth 2.0 (see google+ docs: https://developers.google.com/+/api/oauth https://developers.google.com/+/api/oauth). OAuth 2.0 is supported for a relatively long time by Google (the old docs: https://developers.google.com/accounts/docs/OAuth2 https://developers.google.com/accounts/docs/OAuth2)
- deleted 14y ago[deleted]
- donniezazen 14y agoWhat really surprises me is the blatant permissions required by most applications specially on Chrome OS. Many of the applications/extensions I have had opportunity to observe in past few days outright require "all data on all websites."
- mehulkar 14y agoI'm confused, didn't Google+ Sign In already exist? I know I'm using it already...