Conversation
Notices
-
Embed this notice
Blurry Moon (sun@shitposter.world)'s status on Thursday, 23-Oct-2025 18:25:01 JST
Blurry Moon
@AVincentInSpace @raccoon I don’t want to use an ad company for my identity -
Embed this notice
Vincent Sparks (avincentinspace@furry.engineer)'s status on Thursday, 23-Oct-2025 18:25:02 JST
Vincent Sparks
@raccoon this is a good meme and all, but is terrible cybersecurity practice
as a programmer, i do NOT want to store your password. that is WAY too easy to do slightly wrong in a way that will leave everyone vulnerable if i ever experience a data breach and is definitely something best left to the professionals, like google and github and whatnot. they let you log in through their website, they store your password using their billions of dollars of infrastructure that they use to keep passwords safe that i do not have, and they pass me an auth token, which if it gets leaked in a data breach, is pretty much useless outside of my website. also, if you want to delete your account from my website, you don't even have to go to my website, you can just log into google's OAuth management system and say "i don't want to be associated with this website anymore" and it'll zap the OAuth key and unless i kept your email address i won't be able to interact with you at all anymore.
botvolution repeated this. -
Embed this notice
Blurry Moon (sun@shitposter.world)'s status on Thursday, 23-Oct-2025 18:27:43 JST
Blurry Moon
@raccoon @AVincentInSpace just use generic oauth or indieauth instead of forcing me to pick from a list of shitty companies I wish was dead -
Embed this notice
Trash Panda (raccoon@hollow.raccoon.quest)'s status on Thursday, 23-Oct-2025 18:27:44 JST
Trash Panda
@sun@shitposter.world @AVincentInSpace@furry.engineer
Bro wants to force people to accept third party TOS to use his website. -
Embed this notice
Trash Panda (raccoon@hollow.raccoon.quest)'s status on Wednesday, 31-Dec-2025 03:47:41 JST
Trash Panda
@AVincentInSpace@furry.engineer
They may spend millions of dollars, but they still fuck up and passwords and personal data leak everyfuckingwhere.
I don't use google and I don't use discord and those, sadly, are the two most common options.
I'm not making an account on either just to use a website I can live without.
Not to mention, if someone wants to take users data they're more likely to try and get it from those companies with a shitload of users rather than the small, obscure website with a few thousands users, if that.
Furthermore, google and discord will try to get more out of users than just a username and password, they'll try to get location, maybe even ID and more.
The small obscure website will do with just username and password.
If you want the user to be extra safe force them to use extra security, personally I like aegis.
But only giving me the option to use discord or google? That's when I just don't use the website, period.
I know that as a programmer you know a lot more than me, but I DO NOT trust google and discord, no matter how much they allegedly spend in security, it's that simple.
-
Embed this notice