Discussion about this post

User's avatar
Danger Casey's avatar

Two things not considered in either post:

- account access

- IDP trust

Account Access:

- There are a number of social providers out there who have locked/revoked people's accounts without warning. There's no appeal and no way to get help and instead, you hope you can backdoor your network to someone in support. (I'm looking at you Google.) If they are your sole social auth approach, your account is gone.

- Alternatively, if your account is compromised, you again have no help but now the attacker has access to your downstream accounts.

Which gets to the other idea of IDP trust:

- When you add social providers, you're now inheriting all of their compromises. Unless you can layer an additional auth method/factor on top - both at linking time and occasionally later - you're at their mercy.

Expand full comment
1 more comment...

No posts

Ready for more?