4 ms·
As someone who plays online games, I get really, really annoyed when I'm forced to create a password to log in. ALL non-secure online sites that need to identi
by SomeCallMeTim 12y ago
As someone who plays online games, I get really, really annoyed when I'm forced to create a password to log in.
ALL non-secure online sites that need to identify users should allow for Google or Facebook authentication, or I will never try to access the game from my phone or tablet.
I refuse to use the same password everywhere, but that means I have a password vault on my computer. If I need to create a password and I'm on my phone, I simply click "close" (and uninstall if necessary). I sympathize with those "precompromised accounts," given that it's such a user interface failure (not to mention arrogant) to require a new password for every single little service/game/whatever.
OTOH, if I can "login with Google" and/or Facebook, both of those are already authenticated on my phone, and through the magic of OAUTH I can securely connect to your game without needing to generate a password. Certainly having the OPTION to create a password is fine; there will be people who hate Google/Facebook/whatever and who won't use them. But not having the option is an instant fail for me.
Not saying you're doing it wrong, since I don't know what game you're talking about, but I've certainly encountered many games that have no OAUTH options.
- blazespin 12y agoI (and probably the vast majority of the world) have a single separate password for sites I couldn't care less about being compromised or really serve no purpose for anyone to compromise.
- jwr 12y agoSome of us use password managers like 1Password and get really, really annoyed when we're forced to use Google or Facebook to log in. There are two sides to this - some prefer convenience and are happy to give up some control. Others do not want to depend on a third party and want to have control themselves.
- SomeCallMeTim 12y agoI already mentioned that I use a password manager. The problem comes if I have to create a password on my phone, where I have a read-only copy of the password vault. OAUTH is a far better solution in general. If there were a standard privacy-respecting third-party to replace the Google and Facebook options, I'd be all over it. But I'll happily let Google know that I'm playing a game in exchange for not having to manage yet-another-password.
- aftbit 12y agoIt's a real shame that the only widely deployed OpenID support is tied heavily to Google or Facebook. Actually, is that still even OpenID? Or is it something more proprietary?
- geoka9 12y agoOAuth2
- mynameishere 12y agoSo, having large corporations (google, facebook, etc) know everything you're doing all the time at every site and in every app is better than...having to keep track of various passwords? I don't get it. I find 3rd party authentication without the slightest appeal. Maybe it's a teensy bit easier.
- SomeCallMeTim 12y agoEverything? Hardly. Certainly everything important lives in the password vault. But playing games? Why do I care if Facebook or Google knows I play a particular game? On Android Google is going to know what games I have anyway. "MAYBE" it's easier? On a PHONE?! Let's see, I can click "Google" to log in, and I'm done, or I can...open my key vault, enter my 16-character-random-password into my key manager using a touch keyboard, and then do the copy/paste of the user name and the password. What? I don't have a password for this site yet? Then I have to get my computer and generate the password there, because I don't trust "the cloud" with my critical password vault, encrypted or not. It's so much easier to use OAUTH it's not even a close comparison.
- Spooky23 12y agoFind a better vault solution. Keepassx is available for every platform out there, and when combined with a file sync solution like dropbox, box, etc can be trivially used on iOS or android.
- SomeCallMeTim 12y agoI do use Keepass, but I don't want to need to trust Dropbox etc. I know the Keepass file is nominally password protected, but once I upload a Keepass file with all my important passwords to a site like Dropbox, there's no way to ever recall it reliably. So if there's a Dropbox security hole, someone can potentially grab a copy. And then if there's a Keepass security hole (or if they otherwise acquire my password), then all my important passwords are compromised. To me it's a form of "two factor" authentication for my passwords: One factor is the passphrase, the other is the physical file itself. And one of those is defeated if I upload the file to some cloud service.
- Spooky23 12y agoMy assumption is that a skilled attacker targeting me in particular will be able to compromise my access to services. Easiest vector is probably compromising email and doing password resets. IMO the security controls that I have in place for my vault files are strong enough to make it too expensive for a general attack on files in Dropbox to be cost effective.