If I had a “Login with Twitter” button on a website, I’d be doing everything to get rid of it TODAY.

Twitter is so fucked and they don’t have the slightest idea why.

https://adamchandler.me/blog/2023/01/17/technology-what-about-log-in-with-twitter/

Technology: What about “Log in with Twitter”?

Via Twitter’s Developer Site: “Use Log in with Twitter, also known as Sign in with Twitter, to place a button on your site or application which allows Twitter users to enjoy the benefits of a regis…

Adam Chandler's Blog

If you know how “Login with XXXX” works, you will probably avoid it.

There are a lot of folks who don’t have that knowledge and love it because it reduces friction to gain access.

Everyone is about to learn a hard lesson…

The lesson is that you have to trust XXXX to never fail, or to ever change their policies. Forever.

That’s a big ask given the speed at which things change in this industry.

Like a narcissistic asshole buying Twitter last year. Who had that on their Bingo card?

@chockenberry to be fair, Dorsey is also a narcissistic asshole, but he’s too self-absorbed to do more than navel-gaze. His lack of motivation was probably his best quality.
@bynkii @chockenberry he was also not the sole owner.
Multiple assholes is preferable to a single all-powerful one.
@chockenberry In retrospect, the narcissistic asshole part kinda seems inevitable.
@chockenberry I had narcissistic prick. Do I get half a point?
@chockenberry This is why I never used any of those Login With systems. But then again, I keep all of my work as plaintext, so I’m definitely a weirdo.
@chockenberry i usually just use it on accounts i dont care much about anyways. But usually i use the google or microsoft one only.
@chockenberry Does this apply to “Login with Apple" as well, or is Apple an exception?

@markveldhuis @chockenberry #Apple #AppStore Review Guidelines mandate that if your app offers third-party sign in, such as with #Facebook, #Google, #Teitter, #LinkedIn, #Amazon, or #LinkedIn, you have to have #SignInWithApple as well. Otherwise they won’t approve your app.

https://developer.apple.com/app-store/review/guidelines/#sign-in-with-apple

App Review Guidelines - Apple Developer

The App Review Guidelines provide guidance and examples across a range of development topics, including user interface design, functionality, content, and the use of specific technologies. These guidelines are designed to help you prepare your apps for the approval process.

Apple Developer
@chockenberry I guess I am confused. I use login with GitHub and have implemented hundreds of integrations with Okta using the same basic protocols to secure corporate assets. What risks am I missing?

@chockenberry wait, are they seriously shutting of Login with Twitter too?

Oh this will be chaos.

@ezhik @chockenberry It wasn't explicitly mentioned, they just tweeted that they would make all API access paid. I think they forgot that this exists and will maybe post a clarification in a few days, or maybe a week after this goes into effect, who knows ¯\_(ツ)_/¯
@mackuba @ezhik Yeah, any developer who trusts Twitter at this point is either a fanboi or an idiot. Probably both.
@chockenberry Link to 'explanation' please?
@chockenberry I've used Sign in with Apple sparingly, on throwaway accounts, and that's the ONLY one I remotely trust.
@chockenberry irrespective of the provider (apple, google, microsoft), I _never_ use them on a 3rd party. When the disappear, you are in big doo doo as a user.
@chockenberry I don’t think there is anything inherently wrong with third party federation… especially against trusted IdPs and companies that have an idp history… but people should understand what it is
@chockenberry I have a lot of sites still attached to "login with google", and I doubt that's going away because Google knows people love their SSO. But I should probably detach most or all of those, way too much power for Google to have and I get roughly the same convenience from Bitwarden.
@chockenberry I *always* choose to create an account by email because of the possibility of this exact scenario. The time saved by signing up with a social media account isn’t that much and certainly not worth the potential agro in the future.
@chockenberry are there any “login with XXXX” that you would use?
@chockenberry many student capstone design projects seem to spend a disproportionate amount of time implementing a login flow and I just don't want them to do that. We used to make campus authentication available to student projects and that was good while it worked.
@chockenberry you also need to hope you’re not banned by your XXXX provider
@chockenberry openID was such a nice idea. But this is why we can’t have nice things.
@chockenberry I soooo want to see this happen starting today!! Boosting
@chockenberry At this point, they’re just flipping random switches and seeing what happens. 🤦

@chockenberry This is exactly why I have avoided all of the 'Login with' things and gone with my own email/pw/pw manager. I have never trusted them for exactly this reason.

As deeply dug into the Apple and Google ecosystems as I am, there is no way I am using them (or Facebook, or anything else) as a Login with...

@chockenberry Yes! The latest API nonsense finally motivated me to get the one Twitter authenticated service I have migrated to a different authentication method
@chockenberry oh yeah , I hadn’t thought about Login with Twitter.

@chockenberry

We have removed all Twitter links from our #NeoFinder web pages since December 2022, and from the upcoming #NeoFinder 8.3.

#Twitter is definitely no longer a safe place, and certainly not a viable business partner to trust login or other data...

@chockenberry don’t know why anyone would log in to any site this way. Laziness?
@chockenberry If I'm given an option to sign up with an email and password instead of with Twitter, Facebook, or Google, I'll take that option every time!

@chockenberry

If and when that Login Feature collapses or is switched off there will be a lot of people wishes they used their email address 🫤

@chockenberry I was exactly thinking about this in relation to Substack today. What'll probably happen is Substack won't allow it with free accounts, you must monetize to use the integration.
@chockenberry what’s the betting his mad plan accidentally breaks the login with twitter button
@chockenberry And Liberal “Influencers”: QUIT POSTING ON THERE! Traffic makes it more attractive to sponsors thus lining Melon’s pockets!
@chockenberry coming soon: Log in with Twitter (for $5 per login).
@chockenberry @kstewart Wow, yeah. I hadn't thought of that. There are a handful of sites I log into with Twitter. The problem is I'm not entirely sure which ones...
#sessionize is one though. Time to add a username/password.