The thing I don't especially like at this approach is that this is restricted to only pixelfed.social. Was Piefed doing the exact same thing? I remember Kbin and now Mbin allows for every instance to use their desired SSO.
Pixelfed instance I've chosen went down for like a week already. Dark side of decentralised web 😑
Idea of not distributing registrations is dumb. Sounds like they didn’t even tried to find something better. This defeats purpose of federation. Everyone will land on one instance because hashtags don’t federate and people will start moving to big instances.
We don’t need corpo sso. We need federated auth providers and org which can fund instances which want to be on “trusted list”
Wasn't that the idea behind OpenID?
It’s possible with OpenID. All you need is extract domain from login id and get provider configuration at https:///.well-known/openid-configuration. Problem is that if it’s down you can’t login into same account using another provider.
Technically same way as google or apple SSO works just fixed list of domains. Another problem with using whatever domain user supplied is that some domains are more trusted than others, or rather owners. I don’t mean from privacy perspective I mean stability and security. It’s much easier to hijack domain of small server which struggles to pay for domain name consistently than google.
If Fediverse want to use OpenID for login someone have to vet trusted auth providers.
Otherwise we need someway to federate user logins. Maybe literally have replicated users credentials across instances. Then all federed instances can authenticate users from any federed instance.
This is gonna be limited to the official app, right? In that case, I use Pixelix, so hoping that doesn't get infected with Google proprietary blob slop.
I think it's also just an optional sign-on method - I don't think you have to use it. It sounds like you can register and select servers etc in the normal way, and this is just an extra option for people who... like to do it that way?
For your and everyone else's information, in case you or they don't know, that's not how it works.
Single sign on goes:
- you ask [website] to login, the [website] sends you to google.
- You log into google and give access.
- google sends you back to [website], with the authentication that you're [specific google user]. And now you're logged in.
The whole thing requires extremely regular and normal https requests. There is no need for any proprietary blob. The thing that shows up on the website is often a picture that acts as a link. Companies offering single sign on usually ask websites who want to use it, to use specifically prepared images for branding and for users to recognize and go "I have used [company] single sign on before, I can use this safely!"
The only downside to single sign on is that [google] knows that you, [google user] are using [website].
Your final sentence is an issue as big as any imagined binary blob yet you present it as no big deal.
The problem with the web has been centralization. SSO is centralization.
But it only happens if you choose it.
The problem with the web has been centralization. SSO is centralization.
Yes, but the reason people still use SSO is that security is hard. If a website uses SSO, they don't need to store any password information. Reuse of tech and keeping the number of sources that have sensitive data small, are good.
Your final sentence is an issue as big as any imagined binary blob yet you present it as no big deal.
Priorities and orders of magnitude. If we can get people to quit instagram and to join pixelfed, I think that's a relative improvement, even if the google SSO is still not ideal. You are right, SSO with google is not ideal.
SSO doesn't need to be centralized, at least not like how Google is centralized.
Guy at Google.... Yes officer, let's take a look at Robert O's whereabouts on the night when it all happened. Ah yes, here we see him login in the the usual por sites, pifed, and AliExpress. Yeah, he's a good guy, he didn't do it.
Fediverse memes
Memes about the Fediverse.
Rules
General
- Be respectful
- Post on topic
- No bigotry or hate speech
- Memes should not be personal attacks towards other users
- We are not YPTB. If you have a problem with the way an instance or community is run, then take it up over at !yepowertrippinbastards@lemmy.dbzer0.com.
- Addendum: Yes we know that you think ml/hexbear/grad are tankies and or .world are a bunch of liberals but it gets old quickly. Try and come up with new material.
- This is not the place to start flamewars between Lemmy, Mbin and Piefed.
Elsewhere in the Fediverse
Other relevant communities:
- !fediverse@lemmy.world
- !yepowertrippinbastards@lemmy.dbzer0.com
- !lemmydrama@lemmy.world
- !fediverselore@lemmy.ca
- !bestofthefediverse@lemmy.ca
- !fedigrow@lemmy.zip