Just like apps and websites implement “Sign in with Apple” and Google couldn’t we build some kind of federated authentication provider? Then everyone creates an account there and fedi apps can implement an easy way to authenticate users. Even non fedi apps could use it. I imagine user interaction between different fediverse platforms would be much easier too.

I guess could run an auth instance. Ideally everyone would run their own, keeping your data safe.

Is there something likes this already? Saw some discussion here but not much else https://socialhub.activitypub.rocks/t/single-sign-on-for-fediverse/712

  • HiddenTower@lemmy.world
    link
    fedilink
    English
    arrow-up
    61
    ·
    13 hours ago

    Since I’ve moved to a password manager I find these social logins less useful. Personal opinion.

    • Saleh@feddit.org
      link
      fedilink
      English
      arrow-up
      14
      ·
      12 hours ago

      Yeah, also if the one login gets compromised, oh boy…

      Anecdote time. My first e-mail account got hacked. I still had my Steam account attached to it. Now i have a VAC Ban in CS2 because some chinese kid used it for hacking ingame.

      • tomatol@lemm.eeOP
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        2
        ·
        11 hours ago

        Your password manager’s login can also get compromised

        • 4am@lemm.ee
          link
          fedilink
          English
          arrow-up
          4
          ·
          9 hours ago

          So we should make a remote single point of failure, maintained by someone who probably isn’t a security expert or working on it full time?

          No, this is unfortunately the opposite of what we should be doing.

          • tomatol@lemm.eeOP
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            8 hours ago

            Not a single point but multiple points. Anyway I’m not gonna pretend I’m an expert in security! I just think it’s a feature worth exploring.

    • z3r0@lemmy.zip
      link
      fedilink
      English
      arrow-up
      3
      ·
      12 hours ago

      Also doesn’t this comes against the decentralization principles of the fediverse?

        • forrgott@lemm.ee
          link
          fedilink
          English
          arrow-up
          4
          ·
          11 hours ago

          I have a hard time wrapping my head around this one. If you “federate” authentication, wouldn’t that just open it up to bad actors?

          • tomatol@lemm.eeOP
            link
            fedilink
            English
            arrow-up
            2
            arrow-down
            1
            ·
            edit-2
            11 hours ago

            Well right now Pixelfed has a sign in with mastodon button for example. Admittedly, I don’t know the details but I don’t think anything is stopping me from running my own mastodon instance just to sign up for Pixelfed.

            I agree it might be a nightmare to manage tho if everyone has their own instance but that would probably not be the case.

    • tomatol@lemm.eeOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      11 hours ago

      I agree but I also thought this could solve things like mentioning a user across platforms for example.