• Lemmayng@lemmy.world
    link
    fedilink
    English
    arrow-up
    13
    ·
    16 hours ago

    This is gonna be limited to the official app, right? In that case, I use Pixelix, so hoping that doesn’t get infected with Google proprietary blob slop.

    • fakeman_pretendname@feddit.uk
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 hours ago

      I think it’s also just an optional sign-on method - I don’t think you have to use it. It sounds like you can register and select servers etc in the normal way, and this is just an extra option for people who… like to do it that way?

    • it_depends_man@lemmy.world
      link
      fedilink
      English
      arrow-up
      27
      ·
      edit-2
      15 hours ago

      For your and everyone else’s information, in case you or they don’t know, that’s not how it works.

      Single sign on goes:

      1. you ask [website] to login, the [website] sends you to google.
      2. You log into google and give access.
      3. google sends you back to [website], with the authentication that you’re [specific google user]. And now you’re logged in.

      The whole thing requires extremely regular and normal https requests. There is no need for any proprietary blob. The thing that shows up on the website is often a picture that acts as a link. Companies offering single sign on usually ask websites who want to use it, to use specifically prepared images for branding and for users to recognize and go “I have used [company] single sign on before, I can use this safely!”

      The only downside to single sign on is that [google] knows that you, [google user] are using [website].

      • andyburke@fedia.io
        link
        fedilink
        arrow-up
        20
        ·
        14 hours ago

        Your final sentence is an issue as big as any imagined binary blob yet you present it as no big deal.

        The problem with the web has been centralization. SSO is centralization.

        • it_depends_man@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          edit-2
          8 hours ago

          The problem with the web has been centralization. SSO is centralization.

          Yes, but the reason people still use SSO is that security is hard. If a website uses SSO, they don’t need to store any password information. Reuse of tech and keeping the number of sources that have sensitive data small, are good.

          Your final sentence is an issue as big as any imagined binary blob yet you present it as no big deal.

          Priorities and orders of magnitude. If we can get people to quit instagram and to join pixelfed, I think that’s a relative improvement, even if the google SSO is still not ideal. You are right, SSO with google is not ideal.

      • altphoto@lemmy.today
        link
        fedilink
        English
        arrow-up
        2
        ·
        11 hours ago

        Guy at Google… Yes officer, let’s take a look at Robert O’s whereabouts on the night when it all happened. Ah yes, here we see him login in the the usual por sites, pifed, and AliExpress. Yeah, he’s a good guy, he didn’t do it.