Why you should never use Facebook or Google to log in to third party websites - what to do instead

Ғылым және технология

login with Facebook buttons. this needs updating. But nobody read the descriptions anyway. I can write anything here... I believe in aleins. Little green men live on my street. Why are you still reading this? It's rubbish. You silly billy.
Subscribe - / @simoncaine9515
Chapters -
📺 0:00 - Intro - What is the Login with Facebook Button / OAuth 2.0 /
📺 0:29 - Part 1 - Your Data // What data do these "Click to Log in" buttons take from you
📺 1:16 - Part 2 - How do these buttons work?
📺 3:21 - Part 3 - Advantages for Facebook
📺 5:10 - Part 4 - The Negative Impact // What can we do about it?
OTHER VIDEOS -
Facebook -
👉 The Evil Business Model of WhatsApp - • Why you should delete ...
👉 How Facebook uses your period data to sell you stuff - • How Facebook is using ...
👉 Facebook Shadow Profiles explained - • How Facebook Meta make...
👉 Every toxic thing Facebook did in 2021 - • Every Toxic Thing Face...
👉 Can Facebook be forced to delete the algorithm? Yes, here's why. • This STUDY Changes EVE...
👉 • Why you should never u...
Amazon -
👉 Amazon Go's toxic longterm plan - • Amazon's Product Strat...
👉 Every toxic thing Facebook did in 2021 - • Every Toxic Thing Amaz...
Twitter -
👉 Why is Twitter so toxic - • Context Collapse: The ...
Everything else -
👉 Why Tinder ruined your dating life - • Tinder's algorithm: Th...
👉 The Rise of Dark Patterns - • The truth about dark p...
👉 All the privacy issues in Clubhouse app - • Should you be worried ...
👉 8 counter-arguments to common privacy misconceptions - • 8 counter-arguments to...
👉 You're wrong about the value of NFTs - • NFTs explained in 5 mi...
👉 How social media has changed how we talk - • How social media has c...
👉 Here's why you don't read the terms of service - • Video
------------
💬 let's chat about data / privacy / the internet on Reddit - / theinternetexplorers
💬 I've also got a Discord - / discord
✍️ Follow on Twitter / thismademecool
📧 Join the mailing list - bit.ly/30eHZ7I
✨ Join the internet explorers on Patreon - / simoncaine
🎧 My podcast - podcasts.apple.com/gb/podcast...
------------
All elements were created by me, comedian Simon Caine.
------------
#facebooklogin #META #oauth
------------
My gear (affiliate links)
Camera - amzn.to/2YezaZl
Lens - amzn.to/2Y1yjuQ
Ring light/stand - amzn.to/3gTKhiI
Software - amzn.to/2Y449Hr
Graphic Tablet - amzn.to/3gOXGbX
Green screen - amzn.to/3ePYD1H
Phone - amzn.to/323MtPF
------------
This is the best for the algorithm... no need to read it (I've been told it's important / helpful)
Simon Caine is an English award-winning comedian, writer, author, podcaster and human based in Edinburgh Scotland. He makes a video a week, released every Sunday.
Over the last decade, he's performed all over the world, from London to NYC to Australia. His most recent show "every room becomes a panic room when you overthink enough" got 5* reviews at the Edinburgh Fringe where he sold out the run.
Previously he opened for Trevor Lock, Ben Miller and Henry Ginsberg as well as gigged on the same bill as people like Terry Alderton, Mark Dolan, Matthew Crosby and Bec Hill.
He's been featured in the Huffington Post “Tweets of the Week” feature several times and had jokes/writing appeared in The Poke and other publications. He hates writing in the third person.

Пікірлер: 64

  • @simoncaine9515
    @simoncaine951510 ай бұрын

    Thanks for watching. I hope you enjoyed it. If you haven't already please subscribe for more and... Join the subreddit - www.reddit.com/r/TheInternetExplorers/ Maybe become a patron - www.patreon.com/SimonCaine Share this with a friend? Or just comment below for the algorithm. Godspeed.

  • @duser
    @duser10 ай бұрын

    This is the name of the game here: convenience. Everybody likes privacy, but nobody likes privacy with a ton of inconvenience. A password is inconvenient enough and the surveillance companies take advantage of that to get you to "one click sign up/sign in." Now its inconvenient to even side step these companies online; i was pressured into making a facebook because that is where all my old friends still are after 10 years and nobody stuck with using signal. In the end, i see only the most motivated users jumping ship and ditching these companies for good. For wider, systemic change the best we can do is spread awareness, like you are Simon, and keep the snowball rolling. Hopefully in a few years time, we have enough momentum for some more user-protecting laws to be passed internationally.

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    Thank you so much. That's very kind. And I completely agree. I'm tempted to do an explainer video on the Privacy Paradox which is exactly what you're talking about here... We all want it. But can't be arsed to defend it. If that might be of interest...? Godspeed 😎

  • @duser

    @duser

    10 ай бұрын

    @@simoncaine9515 I'm 100% interested!

  • @mayasela1957

    @mayasela1957

    10 ай бұрын

    Yes, that is the wall I hit every so often. Plus, we need our family and friends to cooperate. And good luck with that

  • @VulpeX2Triumph
    @VulpeX2Triumph10 ай бұрын

    A point - like they say in french - this is surveillance capitalism at work.

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    Preach 🙌

  • @LeoKearse
    @LeoKearse10 ай бұрын

    Great video Simon!

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    Thank you Leo. Appreciate it 🙂

  • @ericcarabetta1161
    @ericcarabetta116110 ай бұрын

    Did the little green men just move in, or have they been there for a while? If they're new neighbors, you should bring them a MANGO to say, "Welcome to earth. Here's some fruit. Please don't harvest my brain."

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    People actually read the descriptions?! I'm leaving it as it is. I forgot to fill that bit out so wrote rubbish just so it didn't say "put description here" haha. But in short, I moved into their neighbour. They've been very welcoming but truth be told I think they're not a fan of my banana bread 🍞

  • @deepansharya1111
    @deepansharya111110 ай бұрын

    Valid point. I use an alt account to log in to such services where I don't care for them to access my data.

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    Fair! But what a ballache to have to run a fake account 😁

  • @andregt4561
    @andregt456110 ай бұрын

    I read in the thumbnail "Never lick cheese"

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    I also endorse this message 😅

  • @sanketm1663
    @sanketm166310 ай бұрын

    Mango lmao

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    🥭🥭🥭

  • @deptofcarstereorepair
    @deptofcarstereorepair10 ай бұрын

    go man go!

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    *puts running shoes on*

  • @onestopviewfiles
    @onestopviewfiles10 ай бұрын

    2:46 what music is that?

  • @tirikitirka2968
    @tirikitirka296810 ай бұрын

    Can you do more crap flat bingo episodes ? Thanks!

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    Thank you! I am going to do more but I'm working out if I do it on a different channel or something. As it doesn't feel like it fits this place right now 😀

  • @ciso
    @ciso10 ай бұрын

    Btw people actually read the description...

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    I'm genuinely shocked 😳😂

  • @MonsterJuiced
    @MonsterJuiced10 ай бұрын

    I fucking hate the internet

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    It's not all bad 😂

  • @nothingcorporate2
    @nothingcorporate210 ай бұрын

    What really makes me sad is when sites only option is a "log in with" button...that and pictures of Mark Zuckerberg.

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    Same! At least give me the option to fill out a form. Maybe I like forms 😅

  • @MegaLokopo
    @MegaLokopo10 ай бұрын

    What about the benefits I receive from seeing useful ads, and not having to pay thousands of dollars to use amazing tools like google maps? I am fine with the trade off. I would hate to have to navigate using and find and buy paper maps.

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    Absolutely! 1) targeted ads, if you're cool with it, that's cool. I don't like them selling the data on and not being transparent about what they're doing with it. 2) "free" services are great. It's just a shame their business model is unsustainable and means they need to get more and more invasive. 3) I love Google maps.

  • @MegaLokopo

    @MegaLokopo

    10 ай бұрын

    @@simoncaine9515 In terms of targeted adds, I would prefer if I could always just use my preferences to determine what adds I see, but them tracking and selling my data which is likely already available for free to everyone on the web due to any number of data breaches, I don't really see as an issue. They aren't really the only source of your data, they are the easy source of your data. I don't think their business model is unsustainable by itself. I think many consumers are simply too picky. If you don't want to pay for a service you should watch ads or not use the service, if you don't want to see generic irrelevant ads, then you should allow them to give you targeted ads, or as I call them useful ads, I get ads all the time for services I use frequently and I can instantly know when a better alternative or a discount is available. But you have so many people who don't want to pay for a service, they don't want to see generic ads, and they don't want to either allow tracking and they don't want to give the advertisers their preferences so the advertisers can give them useful adds. As far as I can tell they are only more invsive because people have stopped interacting with ads and are constantly fighting them, but then refuse to pay for the services they use. I don't get why so many people don't believe youtube of all the streaming services is not worth paying 10 bucks a month for because 10 goes to youtube and 10 goes to the creators.

  • @VectorM
    @VectorM10 ай бұрын

    Been creating these login buttons for my web apps cos we're to lazy to register 🤣. I use them as a user but I'm trying to stop.

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    I'm going to make a short / Tiktok about this. But thank you for your honesty. I get it, they're amazing in terms of frictionless sign up. But the longterm issues are... Well... Not great 😅

  • @NewToWeb3-lz3xf
    @NewToWeb3-lz3xf10 ай бұрын

    Kilt protocol is a startup tackling this issue.

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    Oooh, I'll give them a Google. Thank you!

  • @pawepiat6170

    @pawepiat6170

    10 ай бұрын

    How so? The problem they are solving (if any) is basically doing what public key cryptography has done for years, isn't it? (self-issuing, verifiable, decentralized) I do not see how putting your login on blockchain somehow solves this apparent issue with OAuth, and I do not see how involving blockchain is better then any other federalized or cryptographic methods. After reading some on their website, I am somewhat convinced its a scam lol. From what I gather its just an attestation service for your socials lmao. Basically a paid SSL cert but for your twitter, and instead of having trusted attesters sign it with their keys you somehow get the hash from the blockchain? Lets say i have paid them for that twitter SSL, now I can present it to some 3rd party website to prove that I indeed have ownership of this twitter account. Cool. How is that different to OAuth? The only difference is that with OAuth the 3rd party service can request some extra data, which it cannot do with this kilt certifiacte. I need to login with their certificate instead of twitters authentication methods (so from user side it behaves like a password manager), and then 3rd party service can not do any meaningful integration with twitter, because they only know i have an account, but have no access to it. This setup is achievable with OAuth, and is in fact quite common. So, as a user i need to use your special password manager, and then I cannot even tweet from inside this 3rd party app. If not tweeting is a feature, cool, but it is achievable with OAuth aswell. Its like blaming the car for having a ability to drive in to the tree, so you invent a train that instead goes between 2 points only, is it not?

  • @frederikmetz709
    @frederikmetz7099 ай бұрын

    what about apple?

  • @DoctorLawful
    @DoctorLawful9 ай бұрын

    MANGO

  • @simoncaine9515

    @simoncaine9515

    9 ай бұрын

    WELL SPOTTED 😄

  • @honeycheerios42
    @honeycheerios4210 ай бұрын

    Mangooooo

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    YESSSSSSSSS

  • @IntellectualBadass
    @IntellectualBadass10 ай бұрын

    Mango 🥭

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    Mango to you too 🤣

  • @jorgemartin3057
    @jorgemartin305710 ай бұрын

    Im sorry but as a software developer that works on systems like the ones described in this video, I can say that 90% of the shit said in this video is false. Most of the time all an app would gain access to from a provider such as Facebook would be an email, a name, maybe a profile picture and an access token (including maybe some session state i.e last login time). Thats it. There is 0 incentive for Facebook to give up their own data which is worth billions for free. Next time try spending some more time doing some indepth research instead of trying to work on your reddit-level humor.

  • @danygagnon8446
    @danygagnon844610 ай бұрын

    No, this isn't true. You must provide scopes, which EXPLICITLY detail what they use (they can't access more than what's specified). This video is simply providing false information... The point about providing information to third parties like GOOGLE is more valid, but they likely already have all that extensive data on you, since you use their service anyway

  • @simoncaine9515

    @simoncaine9515

    10 ай бұрын

    Hello! Sorry, are you saying that when you click "login with Facebook" it asks you what data they can have access to? Because that's my point. And I agree with you. But that's not consent. As you can't say "you get none of my data". And some sites make you login via a social network so you're kept out unless you giveaway your privacy. I'm very open to hearing your thoughts. I'm very much replying in good faith - and I know tone is lost written down 😁

  • @ciso

    @ciso

    10 ай бұрын

    ​@@simoncaine9515Yes if you use OAuth you'll have a section where the app either tells you what data it can access or even allows you to choose. It is also possible to view the privileges that other apps have in your Google, Github, etc. account settings and just remove them if you don't want them anymore.

  • @danygagnon8446

    @danygagnon8446

    10 ай бұрын

    ​ @simoncaine9515 Hello Simon! I get where you're coming from regarding the "login with Facebook" or any other third-party service. Yes, when users opt for such services, they are presented with a list of data that will be accessed or shared. This is a form of transparency. It's an explicit acknowledgment, where the service tells you, "Hey, if you proceed, this is the data we will be accessing." The users are not left in the dark with what data is being shared. I use OAuth logins for my company website and I only collect the name, the email and that's it. This data is essential for us to create a user profile in our database. It would be counterproductive, not to mention likely a breach of the third-party terms of service, for us to request access to something like a friends list when it's not relevant or needed for our services. Same here, replying in good faith :)

  • @ciso

    @ciso

    10 ай бұрын

    ​@@simoncaine9515The sections in the settings are called "Third-party apps and services" for Google and "Integrations > Applications" for GitHub, which allow for fine grained control over the data third parties can access. (I don't use Facebook so I have no idea how that works)

  • @pawepiat6170

    @pawepiat6170

    10 ай бұрын

    @@simoncaine9515 you said that it's buried in TOS - it's not. Logging with Google clearly states what data will be shared with Spotify or whatever 3rd party i am going to. There is this big screen with nice icons, labels, and sometimes even descriptions. There is big OK and CANCEL buttons, all on Googles side of OAuth. I am only half way thru your video, but near beggining you say it grants access to cameras. What is your source that those buttons can give access to cameras and microphones? You bring up screenshot of an unrelated hardware product doing that, not those buttons...

Келесі