I am not talking about the gateways. I am talking about the identity providers. If your identity provider goes out of business, revokes your access, or any number of other things, you lose your credentials to all sites.
For instance, here's a site with a guy trying to sell you on using IDPs from a big company rather than a small. One of his points though is that the IdP is a single point of failure, exactly my point:
I know that it's not necessarily tied to Gmail. My point was that now my site is dependent on their relationship to whatever they authenticated against. It might be gmail, it might be Facebook, it might be anything. If that thing either goes away, or revokes their access, they're gone from my site as well. That doesn't sit well with me.
> They put their internet life into the hands of Google or Yahoo or whatever by choosing such an email provider that may go down at any time. It's completely reasonable and does not actually put YOU in a position where your sites locks users into a third party, you are just giving more choice.
It's not reasonable. Not to me anyway. And isn't putting your internet life into the hands of any single place exactly antithetical to the entire idea of decentralization?
> it may not be perfect, but it is far better than what is currently taking over the entire web.
It's better than Facebook Connect or things like that, sure. But we aren't comparing it to that, we're comparing it to individual logins. Individual logins put the relationship into the hands of the users and me. That's where it should be.
KeePass and apps like that provide all of the major benefits to users without any of the downsides.
I keep digging (since the site isn't breaking, yay!) but it just keeps not looking good.
On the github, in the last month, a total of four people have committed code eleven times. One committed more than all the others combined.
Also, I originally said:
> Feel free to try and convince me, but I have never seen the point in tying my uptime to the uptime of a third party, and allowing a third party to revoke my users account if they so wish.
How does Persona not fall foul of both of these? Let's say that I implement Persona and someone uses their Gmail to create an account. Gmail goes down. Can they sign into my site or is my site effectively down for all gmail users?
What if that same user is booted off of Gmail or closes their Gmail account for whatever reason? Are they not then booted off of my site by accident?
Sent some feelers out to devs I respect. Verdict is mostly negative on Persona.
Seems like Mozilla is merely providing bare bones support for Persona these days, and has stopped funding it: http://identity.mozilla.com/
Further, and this is the real nail in the coffin for me, it seems like if you wish to change your email address or lose access to it, there's no way to migrate all accounts at once. It's up to the implementor to support that: https://developer.mozilla.org/en-US/Persona/The_implementor_...
Fun note: Until recently, Email wasn't even required to sign up for GS. A Hacker News user pointed out that without this there's no way to let a user reset their password, so I made it required (though there's still no actual way to reset your password yet. Eeps!) https://news.ycombinator.com/item?id=8521505
I'll look into Persona. It probably won't be today as I'm trying to be extra attentive to the site while I'm drumming up traffic, but it's on my list now.
In theory you could build it in one sitting then share it. And I suppose there's use there. I don't particularly like the idea of people not being (necessarily) able to edit after the fact. That might not be as big of a downside as I think it is though. I'll mull that over as well. It works for imgur, after all, and even though I have an account I fairly often use it without signing in...
Yes, you have to log in to create a deck. You're the second person I've seen suggest being able to make decks without being logged in. There's too many potential headaches as far as cookies expiring, losing the super secret url, etc. to make me actually want to implement this.
I am planning on turning on HTTPS soon, but I despise third party authentication as a rule. Feel free to try and convince me, but I have never seen the point in tying my uptime to the uptime of a third party, and allowing a third party to revoke my users account if they so wish.
I can't now because it was years ago I was having problems. I'm starting to think that it was a different Lisp and not Common Lisp I was looking at, too. Too long ago to remember for sure.
So I just looked up Common Lisp string handling and none of it looks familiar. It's possible what I was trying to use before wasn't Common Lisp. It's also possible I was trying to learn from a site that was just doing a horrible job of it. It's possible things have gotten much much better since I last tried to learn it.
Whatever the cause, I was under the impression that you essentially had to treat strings as lists of characters and that there really weren't any built-in functions to handle strings as strings. It seems that's wrong at least in modern day.
That's quite interesting! I tried to learn Lisp a while back and found the string handling to be horrible, and it's such a huge part of modern development.
It sounds like there's someone with a lot of skill working to fix exactly this.
> I think Twitter is defined by the fact that it's about broadcast.
Writing on a blog with comments off is 100% broadcast with no built-in solution for conversations to form. Twitter has a (flawed) way, so twitter is actually LESS about broadcast than this blog.
> Communities are, above all else, defined by membership, the ability for people to identify as a part of one, and to participate in activities, and share things and experiences with the group.
How does a reader proclaim membership in this blog. Sign up for comments? Post comments? Nope. How does a reader participate? How does a reader share their experiences with the group? Far easier on Twitter than here.
> Every user floats by themselves, interacting with who they please.
Every reader of the blog floats by themselves, interacting with nobody.
> Try following a multi-party conversation using any of the official clients;
How is THIS possible on the blog? You can email the author, sure, but you aren't going to see or be able to reply to anyone else that emailed him.
There's also the widely-repeated quote of "If I had more time, I would have written a shorter letter." Length is not necessarily indicative of amount of thought.
Eh. I'm definitely a part of several communities on Twitter. It's just that they're micro-communities that are fluid in size and shape. If I'm talking business stuff I'll @shazow usually. If it's coding, usually @wolever, sometimes @shazow or @lnxprgr3, depending on the language/platform/etc.
The whole hashtag thing is ... pretty hit or miss. I wouldn't mind a better solution to that. But as weak as it is, it's how I found some of my closest twitter-friends, so it can definitely work.
Thankfully I haven't had to deal with any harassment issues (not famous, nor a noticeable minority), though sadly I don't doubt that they exist to some degree.
And just to be snippy, I find it amusing that he's so against comments on blogs, preferring that you write your own blog post. Isn't that exactly like Twitter? Everyone has their own medium, none of which are explicitly connected...
It's not just early adopters vs late adopters. And nobody is saying to disregard all of IE, only very old versions.
We're talking about dropping support for a browser that is mostly used on a thirteen year old operating system that even Microsoft has dropped support for.
My site is unlikely to ever have a significant number of IE8 users. It revolves around a nerdy hobby that people easily spend $500/year on, often in big chunks. They aren't letting their tech get that out of date.
I fully admit that this isn't every market, but you absolutely CAN make decisions about your specific market and decide that IE8 just simply is not and never will be worth it.
On the other hand, there are certain markets that will probably have to worry about IE8 for ten more years.
Does that 20% come from your own stats or a third party? Most of the third parties look at worldwide market share. IE8 is disproportionately represented in third-world countries which you may or may not care about in your business.
Best I can tell IE8 is somewhere around 6% in the US (these numbers are rough to find because most of the places that collect statistically significant numbers charge for the info). On my site (which centers around a first-world disposable-income-heavy hobby) IE8 is basically non-existent. Your mileage may vary.
In theory, I'm right in your target market. I've been considering a good way to keep my handful of users up to date with small changes that aren't big enough to be immediately visible.
But I'm just not feeling it.
In the FAQ, you try to distance yourself from the way that blog posts are used. But, and this is big, blog posts can be used exactly like it seems VisionHistory is designed to be used. I could post nothing but a bullet list on a blog. Just because most people don't doesn't remove that possibility.
I was intrigued enough, given my current desire to have/make a solution to this, to check out the pricing page. So it's not that I was completely uninterested. But I wasn't interested enough to pay the prices listed and I don't know what you could add that would change that. It just seems to solve too small of a problem.
It could be a regional thing, or it's possible that I am unusual myself, but I've never thought twice about metered electricity, but that's largely because I've never been hit with anything I consider unfair like I have with both mobile phones and home Internet.
I don't think it's fair to say that consumers overall like either one more than the other, it depends on what we're paying FOR.
Why are consumers okay with paying a metered fee for electricity, water, and gasoline?
There's competition and/or regulations pushing those prices into reasonable ranges. Usage is fairly predictable. These are things that are horrible to have suddenly shut off without warning (like what effectively happens when you're throttled into unusability). They are things that people need in order to be a functioning member of society in the majority of places on Earth (in places with good public transit, gasoline gets removed from this list).
Aside from point #1, those also sound like the Internet.
Another shitty() reality is that companies love putting clauses in contracts that won't hold up in court because MANY people just assume that it must be legal and the rest of the contract is still binding, just not the illegal parts.
() This is really done to protect mom and pop business. If they accidentally put in a clause that's not legal, it'd really suck if the entire contract were nullified. But big companies with bajillion dollar lawyers use this loophole to essentially intimidate their customers.
I honestly haven't had anyone needing to reset their password yet. In my particular case it's not really the end of the world if someone gets locked out, but I should probably think what I'd do in that case...
Let's be real. Most users reuse their password for everything anyway. Those that don't likely use a password manager of some sort.
I doubt that any site needs a profile picture. Even Twitter gives you a default if you don't want to set it.
The alternative we have is what we did before social was a thing. The Internet existed before Twitter. The very site we're on doesn't require a social pairing to sign up for it!
For my own site, I have four form fields on the signup page. Username, Password x2 and an optional email. That, IMO, is actually easier than the twitter flow.
With the twitter flow, I have to click to sign in, then read what permissions you're requesting (from another comment I hear that you aren't requesting permission to tweet for me, which is GOOD), then click to accept.
Since I personally don't require email, the user actually has to give me zero personal information. Using twitter, on the other hand, I have to give you my twitter handle, which might actually be personal information. I don't know how you're going to USE that information, so if it's personal, I'm not sure if that information is going to be shown to everyone in the community or not.
For instance, here's a site with a guy trying to sell you on using IDPs from a big company rather than a small. One of his points though is that the IdP is a single point of failure, exactly my point:
https://www.tbray.org/ongoing/When/201x/2013/08/14/FC2-Singl...
Under the heading "Other Failures."