←back to thread

659 points louis-paul | 1 comments | | HN request time: 0.207s | source
Show context
littlecranky67 ◴[] No.43629616[source]
Still can't wrap my head around that TS does not allow to signup with your custom email/password combination but forces you to use bigtech (GitHub, Apple, Meta etc.) to login. Running your custom OIDC provider as a small, private person does not make any sense either.
replies(2): >>43629788 #>>43675451 #
dijit ◴[] No.43629788[source]
I think that's quite smart, and OIDC is an open standard at least.

Securing usernames/passwords and handling second factors etc; is already done so well and it's hard to do.

Having a clear 'this is where we can be secure' stances is what makes me want to trust them more.

replies(3): >>43630167 #>>43630553 #>>43630731 #
lo0dot0 ◴[] No.43630731[source]
Why is that smart? I signed up for a Microsoft Account with my email and I can use Microsoft Account to log in to Tail scale but I can't use the email directly? How does the middle man bring anything to the table?
replies(1): >>43631327 #
dijit ◴[] No.43631327[source]
Because then tailscale doesn’t store a username and password for you, so unless microsoft is hacked you won’t be- theoretically.
replies(3): >>43631548 #>>43632133 #>>43641572 #
1. lo0dot0 ◴[] No.43632133[source]
Thank God Microsoft never got hacked