Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I know, but it's so much easier. It's not like I can't look up someones email account manually without federated login, plus then I no longer have to store passwords.

Of course, aside from my own projects, the only service I've seen that exclusively does this is Fancy Hands.



I agree that it's easier, and if you're only getting a unique identifier from that service (as well as a token), then it's really not unsafe. For the purposes of login, data sharing is unidirectional.

The problem is that Facebook totally mismanaged their apps when they first launched, and a lot of people were permanently turned off to "Connect to Facebook" functionality by random apps posting under the user's name.

My account was recently abused by Glassdoor, which fervently promised not to post anything to my friends, and then immediately did so.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: