11 ms·
It's unfortunate that signing up via Facebook or twitter or some other OAuth method gives people such a creepy feeling. It sure is a lot more convenient for eve
by csbrooks 12y ago
It's unfortunate that signing up via Facebook or twitter or some other OAuth method gives people such a creepy feeling. It sure is a lot more convenient for everyone involved: don't need a password, no email confirmation, sometimes it's one click and you're in.
I feel like Facebook screwed this up for everyone when people's feeds were covered with apps their friends were using. Now when a site asks you to authorize it with facebook, users don't feel like they can trust what it's going to do.
- jbogp 12y agoI agree. I think the creepy feeling comes from the potential threat to your private life... I know Facebook and the others are trying hard to make it clear what permissions are involved each time you sign-up but the fact that you have to check "ooh this one can access my friends list, I don't like that" is pretty unconfortable
- lazyjones 12y ago> I know Facebook and the others are trying hard to make it clear what permissions are involved each time you sign-up What they don't make clear is that Facebook is informed every time people visit (or in some cases, login in to) those other sites and can generate better profiles from that data, even sleep schedules, even for people who rarely use FB itself.
- return0 12y agoI would like a minimal identity provider, i.e. something like BrowserID where you can create throwaway identities that is not associated with any social presence.
- skrebbel 12y agoI used to think that this was an ideal space for governments, or some semi-public organization. Identity as a societal service, much like running water and electricity and highways. But then Snowden dropped by to tell us that we can trust our own governments even less than all these companies.
- return0 12y agoIt could be browser-based implementation only, maybe connected to a locally stored private key.
- cessor 12y agoWe had this discussion when we were talking about web based IDEs here on hn the other day (can't be bothered for the link). I like oauth, but I hate clicking "sign in with {Facebook|Twitter|Github}" and then being asked for a user name and email address. This is redundant and nonsensical... Most app people are very happy to immediatly use the account email to send you stupid personalized followups, aka "Peter From Lame-App". If it would be "click, see and forget" - OAuth signup would be great, but being required to accept spam really breaks the deal. I am not sure if too many people share that feeling, but it really bugs me. The issue you point out with aggressive App spam on facebook is different with other services, I feel. Twitter Apps usually ask whether they might tweet something in my name. So I believe you are right, facebook might have screwed this up a little.
- Lockyy 12y agoI'm working with OAuth right now and the only info that I'm not being given that I have to ask for is an email address when the user uses twitter. Twitter doesn't give you an email address, and you cannot ask for it, so the only option is to ask for it. Which makes things harder on my end. It really feels redundant and makes me wonder what the Twitter team was thinking.
- cessor 12y agoAs a user of these services I can stay that I am very happy about this *(I didn't know, but somebody here on hn claimed github auth did the same thing). This is exactly how it should work. What on earth is your excuse to really need my email address? I am sorry if I sound rude, but this behavior enrages me somewhat. If you wish to track data that is connected to my identity, i.e. provide continuity in your service, store some stuff that I made, settings, preferences, you don't need my email address. If you really wish to communicate: Talk to me on twitter, it's nearly public! With oauth you receive a token as a representation of my identity, not my email address. If you really need an email address - then why do you need oauth? If I go to a store to just browse through the shelves I don't have to give the clerk my telefone number. Why would he need it anyway? To annoy me every once in a while and bully me into visiting his store, which I voluntarily entered in the first place? Here is a positive example: - Go to iron.io - Log in with your twitter account - Nothing happens: You can use the app and they show you around pretty nicely. Yet Iron provides a service upgrade, which requires credit information. They ask for it, specificly when they need it: When you want more from their service. In that case you have to provide them with the info. This is how websites could handle this issue. Log in with oauth. If you REALLY personally need to contact me, then you can ask me later. Not upon login or to distinguish me from other people or provide continuity. Emails are communication handles. They shouldn't be a poor man's surrogate database primary key. I remain very curious: What does _your_ service need my email address for?
- Piskvorrr 12y agoCreepy feeling. Well guess what: apparently something that you say on FB which anyone finds offensive can lead to your FB account being disabled, without warning or official way to appeal. Now tell me again, how convenient is this global login that can at any time disappear from under your feet?
- deleted 12y ago[deleted]
- tehwebguy 12y agoIs that common? It seems like it is in the same neighborhood of likelihood as losing your Gmail account for cause.
- silverbax88 12y agoI don't user Gmail either, partially because I just think the UI is terrible but primarily because I don't want another company controlling access to my email.
- Piskvorrr 12y agoGMail is mostly used for e-mail, which is something of a private conversation between (usually two) people. Facebook posts are quite the contrary: public, visible to the world at large, plus the users are actively encouraged to flag items they dislike. Now don't get me wrong: this is quite necessary for a social network - but using the same social network as the Universal Login For Everything is where this very feature becomes the SPOF. Also, whereas GMail is not inclined to police the morality of its users, FB is. Not the same as data-mining, not the same as "legality" - for example, you have repeatedly used a word that FB retroactively considers a bannable offense, say goodbye to your account; or you have, a long time ago, posted pictures that are considered indecent under the new rules; or enough other users maliciously coordinate to flag an innocuous item of yours - and the banhammer falls automatically. Moreover, GMail != e-mail: you are completely free to register with any of the bazillion e-mail providers, there is no need to use GMail; as for Facebook, there is only one.
- 12y ago
- silverbax88 12y agoWhy is it more convenient for me to turn over all of my data and accounts to companies I don't trust/use/like?
- tim333 12y agoThe thing is that in the absence of the likes of facebook you usually don't turn over your data and accounts. You just typically give them username: Somerubbish password: 123whatever and that's it.
- silverbax88 12y agoNo, I don't. I use a password manager. I promise I'm not being obtuse. That is what I do. I create an account, and add it to KeePass. Because I never know when I will need it later, even if I don't think I will.
- alokm 12y agoI see apps trying to overcome this trust deficit by using phrases like. "We wont post anything on your feed" . "No posts. We promise". Even if it isn't a legal commitment, It might go a long way in convincing users. Especially if there is a brand involved.
- bbwharris 12y agoOpenID was the solution to this. It just never caught on. When Facebook released connect it was game over.
- wfunction 12y agoFor one thing, websites ask to view your email address with OAuth. That kinda defeats the point of not wanting to give them your email.
- Nursie 12y agoIt's not just that - why should facebook know about all these other things I'm doing?
- nly 12y agoNot just know, have access.
- danielweber 12y agoBecause years of anti-phishing training has taught us that typing their FB password in the wrong place gives out complete control of our FB account. So the only safe thing is abstinence. Don't type your FB password anywhere but when logging in directly to https://facebook.com https://facebook.com As you say, the whole point of OAuth is that you can safely use your FB account to log in to this other site. But -- to take this metaphor even further -- each time I encounter one of those things I always feel like a teenager being pressured into sex and being told "don't worry, this is safe, I promise, I love you." And I simply just don't know. I'm confident I could recognize that www.facebook.com.scottba.io isn't Facebook, and I could probably train my parents on how to recognize that. But there has been extremely little user education on just what a "safe OAuth" site looks like. It's now putting an asterisk on all the old rules.
- jrochkind1 12y agoTheoretically, if you are using OAuth facebook login, then on the page you are prompted for a Facebook login, you should be seeing facebook.com in your browser location bar, with the trusted https "green bar". But I realize this kind of anti-phishing checking is beyond most users, and "Just don't enter your facebook password anywhere but when you are logging into facebook" probably IS a good heuristic for them. I also don't know if some facebook oauth login paths use some kind of fancy ajax window-in-a-window so you _don't_ actually see facebook.com in your address bar -- which would make it pretty impossible for users to know if they're being phished or not.
- scrollaway 12y ago> I also don't know if some facebook oauth login paths use some kind of fancy ajax window-in-a-window so you _don't_ actually see facebook.com in your address bar This can never happen, because of the situation you highlighted. Most browsers do not let you do that anymore.
- danielweber 12y agoThe site could be faking the chrome so it looks like a separate pop-up, when it's actually just a div. Most of us would smell something wrong because it wouldn't be quite right but you could get reasonably close for non-developers. I went looking for sites using facebook logins and found this one just as the first unlucky example: http://www.nydailynews.com/login http://www.nydailynews.com/login Once you know the browser and OS, it wouldn't be too hard to get something mostly like that pop-up into a div.
- Vik1ng 12y agoOr you know people care about their privacy...
- xor-ed-wolf 12y agoAlso why should I connect some (possibly clingy and untrustworthy) site with my facebook account even if there is a fat chance that I use it for the fist and the last time?
- mhurron 12y agoWhy would you sign into a site were that was possible? Maybe I'm strange but I don't create credentials (no facebook so that's not going to be used) on a site or for a service unless I've become sure that I'm going to use it. If I have to sign in before I can see anything about it, I leave.
- xor-ed-wolf 12y agoYou seem like a soothsayer to me as you know beforehand if you will use some site regularly or not possibly even before accessing its functionality (which is applicable to many sites with login requirements).
- acheron 12y agoExactly. As far as I'm concerned, the only reason some app would ask for my FB account info is so it can post shit as me. Thanks but no thanks.
- gdilla 12y agoPeople blame the third party app for being spammy, not nec facebook. I know I deleted apps in a rage if i saw one unexpected post on my feed. But i'm still a facebook user.
- brudgers 12y agoIt's not unfortunate. People use the internet in different ways because they're different. Today I got an email from Atlassian, saying "Your repository, blog, has missed you." Some people will think this is great. Some will be irritated. I was amused by the anthromorphication of a file structure in an attempt to lay a guilt trip on me in order to bump numbers for the expected IPO. Bitbucket is just a tool in the toolbox. I've got a steering wheel puller that I bought when I had to replace the ignition cylinder of my 1974 Monte Carlo. I haven't used it since 1986. Heartless? that I am. So color me skeptical. It's good that I don't use Facebook or Twitter to log into your site. They successfully filter me out from the sort of site designed by people whose business needs are met better by social login. Yes, it's not you, it's me. I am only hindering your growth. So fly away freely. Come back only if our true love was meant to be. Segmentation is a good thing, so long as it's recognized as segmentation.
- wintermute306 12y agoNo one likes registering for anything, that is pretty well known. Getting users to do this though is part of my job and my job is often made easier either by auto-fill options in browsers and good form design. URL based autho systems are pretty limited in their applications as anything on the other side would have to be of little importance. The security implications of such a system are massive...What if you need to log into an account and you use a work computer? Surely all someone needs to do is press ctrl-h(or access server logs) and visit the same url to gain access to your information.
- rrss1122 12y agoSigning up via Google give me no creeps. The real annoying thing is that after you sign in with Google, when a website still wants you to "complete registration" by giving all the normal information you would have given at registration. I guess for me, the reason why signing up via Google is not as creepy feeling inducing as Facebook is because Google gives you the option of putting on Google+ whether or not you sign in to a given website. The default is still to put it in your feed, but at least you can choose not to put it in your feed.