The article references oAuth (http://oauth.net/) as one technical solution to the problem–essentially getting temporary permission from users to view their address book via APIs. Users would only enter their password on the providers site.
Someone made the comment about IM clients asking for email/password. For some reason I don’t have a problem with putting my details into Adium, or Pidgin, or even a web service like Meebo. Yet when Facebook asked me for the same details when signing up for an account I stopped short. Why?
I think the problem isn’t so much that a site might want you to enter your user/pass per se, but whether it is an appropriate context for it to ask you. A complementary issue is that individual services, such as maintaining a set of contacts for you or an IM account, aren’t sufficiently decoupled from the email accounts they pertain to. If you had a separate user/pass for the particular service you were accessing, you wouldn’t mind so much when prompted for those. I applaud the use of OAuth to combat the password anti-pattern (and decry the essentially spammy practice by Facebook, Yelp etc of doing it in the first place), but there are occasions, even with the advent of these good new conventions, when most people will still give their credentials to third-party sites. Should Meebo implement OAuth rather than ask for my Gmail account details so I can use Google Talk? Where do we draw the line?
Secret passwords should never be given out to anyone. All you are doing is lowering the guard of unsuspecting Users and making it acceptable to hand these passwords out when asked.
Isn’t this a solved problem? When I switched from Yahoo email to Gmail, I just clicked to export my Yahoo contacts as a CSV file, then uploaded the file to Gmail. Both email providers made this easy for me.
Any reason why I can’t do the same for a social site? They could include easy-to-follow instructions…
@J Liles “Not suggesting this is a solution to the overall problem, but I’m hearing a lot of “OMG, they’re going to store my password on an unsecured database somewhere and it will be hacked by the Russian mob and my identity will be stolen” sorts of fears. snip Perhaps I am not paranoid enough, but personally, if a legitimate site explained to me that they were not actually storing my email and password anywhere on their servers, I would consider providing the information.”
I’m just wonder what constitutes a “legimate site”.
While I’m concerned about the “Russian mob” and all other “mobs” looking to get my info, I’m far more concerned about “Bob the employee” getting it since it is considerably easier to get at something inside the house if I’m inside the house than if I have to break in the house.
Anytime a website starts asking me for info, I’m concerned. Obviously there has to be some level of trust on the part of the information provider. But sometimes I suspect they ask me for info because it is convenient and useful for THEM not so my personal experience will be better. I’m not paranoid, but I do question the motivation of some sites.
So why do you trust that “treasure trove of highly sensitive financial and personal information” of yours to Google? How much do you really know about how carefully Google guards your personal data, or how many of its employees have access to it? Why is it safer to trust Google with access to this information than Facebook, for example?
Someone mentioned Adium (instant messaging client). Of course it’s OK to enter all your accounts into Adium. The developers of Adium don’t see your passwords. AOL doesn’t see your MSN password. Google doesn’t see your Yahoo password. Etcetera. They are stored encrypted on your hard drive and only given out to the originating services.
It’s crazy how important your email address is when you stop to think about it. I never like those forms either. You hear stories in the news all the time about ‘lost laptops’ containing ‘thousands of users information’ and such. The last thing I need is someone getting into my email and gaining access to all my information.
Great post. Not only is it a bad idea to give out your e-mail password to just any site, but its also a bad idea to use your e-mail password as your login password on a new site when your username on that site will be your e-mail address. The next logical step for anyone who gains access to that database is to guess that your password for their site is also your e-mail password (as I blogged about, similar to your post here - http://bryanhales.com/archive/2008/04/11/an-easy-way-to-have-your-identity-stolen.aspx)
amen. so many projects i’ve worked on recently list this as a necessary feature. i try to convince them that it’s a bad idea but i rarely win the argument. i’m told it’s a necessary feature since everyone else does it.
FAIL
Imma head outside now and tell people, YOU MIGHT HAVE FRIENDS WITH THE SAME BANK ACCOUNT BALANCE AS YOU! GIVE ME YOUR CARD AND PIN FOR 10 MINUTES AND ILL CHECK TO SEE WHO DOES!
The Yelp-ers are ex-PayPal-ers, and they will remember exactly the difficulty PayPal had in their pre-part-of-eBay years getting users to supply their eBay signon information. PayPal was able to do a great many useful things for people if they could sign on to eBay on their users behalf - monitor auctions, send invoices automatically, provide statements with details, etc - but there was a security risk involved.
However signing on to someone’s eBay account isn’t as dramatic as signing on to someone’s email account. If I log in as you into eBay, about the worst thing I can do is screw up your eBay reputation (that is not nothing, but it isn’t that bad). However if I log in as you into your email account, I can learn all sorts of things about you, personal and business, and probably recover a whole bunch of your passwords to other sites. I agree I would never do this.
According to the screen then don’t keep your email credentials. They likely do a one-time lookup and then cross reference to people in your address book. Then they throw away the credentials info. Sure, you have to trust that they are telling the truth. But why would they lie about it?
There is something you can do. I work in an environment where sharing your credentials isn’t only a bad idea, but its a crime. However there are other government site that still ask for your credentials to verify this or that thing. In the event this happens and I can’t avoid it, I hand over the credentials and promptly change my password.
The same rule can be applied to yelp and its ilk. If you are REALLY attached to your password, you can change it first, hand it over, then change it back.
Not ideal and you are right, its bad form to ask for full credentials, but there is a way around the individual security flaw.
However as you said, this practice is training users to hand over the keys and think its normal and ok.
“Only slightly less well known,” and not nearly as sinister, but still a potential breach of security at most and bad netiquette at least is all those grapevine emails that contain dozens of email addresses from people who have 2 or more degrees of separation. I wouldn’t expect anyone’s grandmother to know how to edit that stuff out, but where are the email settings that at least hide and best remove all those headers? Better yet, how about “Use BCC when I forward to this group”?