Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What me frightens a little with this move (OK, I acknowledge that OpenID2.0 is deprecated and should be updated to something new), is that Google talks only about "Google+ Signin". And OK, as I read in previous discussion, Google will also in the future support logins from people with normal eMail account.

Still, I am worried, since Google does not clearly communicate these facts, but when you look at their communications, you read only about "Google+ Signin" and you have to search to find that you do not need Google+ but just the new protocol OpenID connect.

I don't like to see such communications from a company, that once claimed (long, long time ago!! Do you remember Google?) "Don't be evil".

It is OK, when they move away from an old protocol, but it is not OK, when they (and it very much looks that way to me!) use it as vehicle to market their products. Google has troubled people enough with forcing G+ on them -- so I even find it more troublesome, how they do it now (as it seems to me currently).

I fear, Google is still hunting after Facebook and is by the way inheriting its bad habits.

As I see now, they also want that a new button is used -- something with G+ on it. I see, they really lay the pressure on the people -- many people will think, that they need a Google+ account to use this feature (even if not required). I would say, Google you are going to hurt yourself!

I myself, was thinking about using a "Login with Google" button in my application ... but now, with things changed, I will think twice, before I do such a move!



Google have never properly supported federated login. You should be able to login to Google services with an external account and not need to sign up with Google at all. Their Authentication and Authorization APIs have always been about pushing Google Services.


That is right. But till now, I could use a simple Google acount (not G+) to login for example at Stackoverflow.com.

In future the button will change from "G"-Login to "G+"-Login. As somebody else stated, Google said, that a normal Google account will suffice in the future, but alone the wording and the new button will alienate people.


Google+ Sign-In is an implementation of OpenID Connect, with some nice features built on top:

"Google+ Sign-In is built on the OAuth 2.0 and OpenID Connect protocols. It supports over-the-air installs, social features, and a sign-in widget on top of standardized OpenID Connect sign-in flows. Google+ Sign-In works for all users with a Google account, whether or not they have upgraded to Google+." [0]

I don't understand where all your other conclusions came from.

[0]: https://developers.google.com/accounts/docs/OAuth2LoginV1


From this Link:

https://developers.google.com/accounts/docs/OpenID#shutdown-...

and from common sense.

BTW: Maybe you should also read my full post, before answering.


> BTW: Maybe you should also read my full post, before answering.

Heh, I see that you edited it to add more since I originally pressed "Reply".

You imply Google is "evil" because they write "only about Google+ SignIn", but I'm not seeing that. The link that you provided has two sections, migrating to Google+ SignIn if you are already using a Sign In with Google button, and a section on how to migrate to just basic OpenID Connect. It doesn't seem hidden away like you are implying.


Where does it talk only about Google+ Sign-in as the migration from OpenID 2.0?

On the same page, they list how to migrate to OAuth 2.0/OpenID Connect, and even say "If your OpenID 2.0–based app does not need social features or is on a platform not supported by Google+ Sign-In, or if you want to work directly with the OAuth 2.0 REST APIs, then we recommend migrating to Google's OAuth 2.0 login (OpenID Connect) solution, as described below."


Google's documentation is so confusing. I just wanted a simple tutorial which would tell how to get the name and email address of the person with the new API. That is all I need.

But the name Google+ Signin implies that this is related to Google Plus which I did not want. So I thought I have to use some other API for my simple needs, after wasting lot of time I realised I have to use Google+ login even for my simple needs. Couple of head banging sessions later, I realized this is just a vehicle to market their product.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: