Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It definitely does address some of these problems, but raises others.

First and foremost is denial of service. If the identity toolkit goes, so does access to everything it issues tokens for.

To be absolutely fair, I've not used the toolkit so don't know whether I could use a Hotmail account when my Gmail account is inaccesible.

A business risk you take on is reliance on their T&Cs. It may (or not) be worthwhile planning a mitigation or contingency, depending on the value of your service.

The other part is that anything from Google is, by way of Google's business model, spyware. This is my (note: very personal) preference, but I don't use any Google products, services, or products or services that make use of anything from Google.



Regarding denial of service, does that not apply to any identity provider? OAuth, Facebook/Twitter sign in, all suffer the same problem. Perhaps I have too much faith in their systems, but I don't imagine downtime occurring in reality.

You are correct in assuming you can't use your hotmail address when Gmail is inaccessible, unless it was planned beforehand. As in, you can auth a second identity provider for the same account - which would be possible, but not as an afterthought - so probably useless.

I guess a careful read of their T&C's is a good idea, but what would you envisage as warning signals?

Spyware, well, if users signed up using gmail, google would know. That's most users anyway these days. But you're right, in using google analytics I'm providing them all this information anyway, so perhaps I'm less concerned.

Personally, I think the benefits outweigh the problems you've raised, but perhaps I'm being an optimist. If something did happen down the line, I would have to issue all users with a new password down the line, that would be frustrating, but not the end of the world as a mitigation strategy.


Having spoken to the product manager at google, I got the following response:

While there is no service level agreement (SLA) for the Google Identity Toolkit, Google itself uses the same infrastructure as GITKit to support federated login for Google accounts. Google users can even opt-in to use an Account Chooser in place of the traditional Google login box.

https://code.google.com/apis/identitytoolkit/v1/learnmore.ht...


Sorry for the delayed reply. When I mentioned T&Cs I meant the risk that the provider you use changes the terms and conditions some time after you've deployed and have an established user base that relies on the provider's service.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: