They have access to brilliant engineers
Not really.
Comment on A Researcher Figured Out How to Reveal Any Phone Number Linked to a Google Account
malloc@lemmy.world 9 months ago
Google, Apple, and rest of big tech are pregnable despite their access to vast amounts of capital, and labor resources.
I used to be a big supporter of using their “social sign on” (or more generally speaking, single sign on) as a federated authentication mechanism. They have access to brilliant engineers thus naively thought - "well these companies are well funded, and security focused. What could go wrong having them handle a critical entry point for services?”
Well as this position continues to age poorly, many fucking aspects can go wrong!
Which is why my new position is for federated authentication protocols. Similar to how Lemmy and the fediverse work but for authentication and authorization.
Having your own IdP won’t fix the 3rd issue, but at least it will alleviate 1st and 2nd concerns
They have access to brilliant engineers
Not really.
Paradox@lemdro.id 9 months ago
The sad thing is, we had federated auth before social sign on. OpenID was a thing before oauth