Social login

Social login is a form of single sign-on using existing information from a social networking service such as Facebook, Twitter or Google, to login to a third party website instead of creating a new login account specifically for that website. It is designed to simplify logins for end users as well as provide more reliable demographic information to web developers.[1]

How social login works

Social login links accounts from one or more social networking services to a website, typically using either a plug-in or a widget.[2] By selecting the desired social networking service, the user simply uses his or her login for that service to sign on to the website. This, in turn, negates the need for the end user to remember login information for multiple electronic commerce and other websites while providing site owners with uniform demographic information as provided by the social networking service. Many sites which offer social login also offer more traditional online registration for those who either desire it or who do not have an account with a compatible social networking service (and therefore would be precluded from creating an account with the website).

Application

Social login can be implemented strictly as an authentication system using standards such as OpenID or SAML. For consumer websites that offer social functionality to users, social login is often implemented using the OAuth standard. OAuth is a secure authorization protocol which is commonly used in conjunction with authentication to grant 3rd party applications a "session token" allowing them to make API calls to providers on the user's behalf. Sites using the social login in this manner typically offer social features such as commenting, sharing, reactions and gamification.

While social login can be extended to corporate websites,[3] the majority of social networks and consumer-based identity providers allow self-asserted identities. For this reason, social login is generally not used for strict, highly secure applications such as those in banking or health.

Advantages of social login

Studies have shown that website registration forms are inefficient as many people provide false data, forget their login information for the site or simply decline to register in the first place. A study conducted in 2011 by Janrain and Blue Research found that 77 percent of consumers favored social login as a means of authentication over more traditional online registration methods.[4] Additional benefits:

Targeted Content
Web sites can obtain a profile and social graph data in order to target personalized content to the user. This includes information such as name, email, hometown, interests, activities, and friends. However, this can create issues for privacy, and result in a narrowing of the variety of views and options available on the internet.
Multiple Identities
Users can log into websites with multiple social identities allowing them to better control their online identity.[5]
Registration Data
Many websites use the profile data returned from social login instead of having users manually enter their PII (Personally Identifiable Information) into web forms. This can potentially speed up the registration or sign-up process.
Pre-validated Email
Identity providers who support email such as Google and Yahoo! can return the user's email address to the 3rd party website preventing the user from supplying a fabricated email address during the registration process.
Account linking
Because social login can be used for authentication, many websites allow legacy users to link pre-existing site account with their social login account without forcing re-registration.

Disadvantages of social login

Utilizing social login through platforms such as Facebook may unintentionally render third-party websites useless within certain libraries, schools, or workplaces which block social networking services for productivity reasons. It can also cause difficulties in countries with active censorship regimes, such as China and its "Golden Shield Project", where the third party website may not be actively censored, but is effectively blocked if a user's social login is blocked.[6]

There are several other risks that come with using social login tools. These logins are also a new frontier for fraud and account abuse as attackers use sophisticated means to hack these authentication mechanisms.[7] This can result in an unwanted increase in fraudulent account creations, or worse; attackers successfully stealing social media account credentials from legitimate users. One such way that social media accounts are exploited is when users are enticed to download malicious browser extensions that request read and write permissions on all websites. These users are not aware that later on, typically a week or so after being installed, the extensions will then download some background Javascript malware from its command and control site to run on the user's browser. From then on, these malware infected browsers can effectively be controlled remotely. These extensions will then wait until the user logs into a social media or another online account, and using those tokens or credentials will sign up for other online accounts without the rightful user's express permission.

Security

In March 2012, a research paper[8] reported an extensive study on the security of social login mechanisms. The authors found 8 serious logic flaws in high-profile ID providers and relying party websites, such as OpenID (including Google ID and PayPal Access), Facebook, Janrain, Freelancer, FarmVille, Sears.com, etc. Because the researchers informed ID providers and the third party websites that relied on the service prior to public announcement of the discovery of the flaws, the vulnerabilities were corrected, and there have been no security breaches reported.[9] This research concludes that the overall security quality of SSO deployments seems worrisome.

Moreover, social logins are often implemented in an insecure way. Users, in this case, have to trust every application which implemented this feature to handle their identifier confidentially. [10]

Furthermore, by placing reliance on an account which is operable on many websites, social login creates a single point of failure, thus considerably augmenting the damage that would be caused were the account to be hacked.

List of providers

Here is a list of services that provide social login features which they encourage other websites to use. Related are federated identity login providers.

See also

References

  1. ^ Social Login: A Data Capture Game Changer(accessed 21 December 2011).
  2. ^ Ngemera, Eusebius (2017-01-31). "Social Logins—what info you give away!". eusebius.tech. Retrieved 2017-05-06.
  3. ^ "Integrate Social Networks with your Corporate Website with Social Sign On" - Altimeter Group, September 27, 2010
  4. ^ Social Media Marketing: Social login or traditional website registration? MarketingSherpa, January 12, 2012
  5. ^ "The Social Web's Big New Theme for 2011: Multiple Identities for Everyone" - AllThingsD, January 1, 2011
  6. ^ Laurenson, Lydia (3 May 2014). "The Censorship Effect". TechCrunch. Retrieved 27 February 2015.
  7. ^ Safruti, Ido (18 October 2017). "Simple Social Login for Users and Attackers". infosecurity. Retrieved 14 November 2017.
  8. ^ Rui Wang; Shuo Chen & XiaoFeng Wang (May 2012). "Signing Me onto Your Accounts through Facebook and Google: a Traffic-Guided Security Study of Commercially Deployed Single-Sign-On Web Services".
  9. ^ "OpenID: Vulnerability report, Data confusion" - OpenID Foundation, March 14, 2012
  10. ^ "Social Login Setups – The Good, the Bad and the Ugly" - CloudRail, August 2, 2016

Further reading

Read other articles:

Park Hyun-binInformasi latar belakangNama lahirPark Ji-woongLahir28 Oktober 1982 (umur 41)GwangmyeongGenreTrotPekerjaanPenyanyiTahun aktif2006–sekarangNama KoreaHangul박현빈 Hanja朴炫彬 Alih AksaraBak Hyeon(-)binMcCune–ReischauerPak HyŏnbinNama lahirHangul박지웅 Hanja朴智雄 Alih AksaraBak Ji(-)ungMcCune–ReischauerPak Chiung Ini adalah nama Korea; marganya adalah Park. Park Hyun-bin (박현빈; lahir 18 Oktober 1982) adalah seorang penyanyi trot dari Korea Selatan.[...

Irish politician Emma SheerinMLASheerin in 2021Member of the Legislative Assemblyfor Mid UlsterIncumbentAssumed office 4 December 2018Preceded byIan Milne Personal detailsBorn1991 or 1992 (age 30–32)County Londonderry, Northern IrelandNationalityIrishPolitical partySinn FéinResidenceBallinascreen Emma Sheerin (born 1991/92)[1] is an Irish Sinn Féin politician from Draperstown, County Londonderry, Northern Ireland. Since 2018 she has been MLA for Mid Ulster. ...

Copa Mundial de FútbolCopa Mundial de la FIFA Colombia 86' XIII edición Datos generalesSede  ColombiaAsociación FIFACategoría Absoluta de seleccionesDatos estadísticosParticipantes 24 [editar datos en Wikidata] La XIII Copa Mundial de Fútbol estaba prevista a desarrollarse en Colombia, entre el 31 de mayo y el 29 de junio de 1986. Sin embargo, Colombia declinó luego de ser escogida como sede, marcando un hecho inédito y no repetido en la historia de los Mundiales. Méxi...

Mal Ciputra SemarangLokasiSemarangAlamatJalan Simpang Lima No. 1, Pekunden, Semarang Tengah, Semarang, Jawa TengahTanggal dibuka12 Desember 1993PengembangCiputra DevelopmentPemilikGrup CiputraJumlah lantai3 Mal Ciputra Semarang (Hanacaraka: ꦩꦭ꧀​ꦕꦶꦥꦸꦠꦿ​ꦱꦼꦩꦫꦁ) adalah sebuah pusat perbelanjaan di Semarang, Indonesia. Pusat perbelanjaan ini berdiri pada tanggal 12 Desember 1993. Terletak di sudut utara Simpang Lima Semarang, Mal Ciputra didirikan sebagai bagian dar...

الإشعاع الحراري للكون عند 2.7 كلفن وهو يماثل التوزيع الكهرومغناطيسي لبلانك، ووضع قانونه، قانون بلانك سابقا في عام 1900 بصفة عامة لجميع الأجسام الساخنة. تمت قياسات هذا الرسم البياني للكون في أواخر القرن العشرين. الإشعاع الحراري هو أحد صور انبعاث الطاقة وانتقالها، وكمية الطاقة

Singapura padaOlimpiade Musim Panas 1976Kode IOCSINKONDewan Olimpiade Nasional SingapuraSitus webwww.singaporeolympics.comPenampilan pada Olimpiade Musim Panas 1976 di MontrealPeserta4 (3 putra dan 1 putri) dalam 4 cabang olahragaPembawa benderaKoh Eng KianMedali 0 0 0 Total 0 Penampilan pada Olimpiade Musim Panas (ringkasan)1948195219561960196419681972197619801984198819921996200020042008201220162020Penampilan terkait lainnya Malaysia (1964) Singapura berkompetisi pada Olimpiade Musim Pa...

القسم الخامس : مشهد من مقبرة رمسيس الخامس والسادس. (مقبرة 9 في وادي الملوك، الغرفة هـ، الجدار الأيمن) جزء من سلسلة مقالات حولديانة قدماء المصريين مفاهيم الحياة الآخرة دوات ماعت الأساطير الأرقام الفلسفة الروح طقوس الجنائزية القرابين المعابد الأهرامات الآلهةثامون هيرموب...

  Selenicereus ocamponis Estado de conservaciónPreocupación menor (UICN)[1]​TaxonomíaReino: PlantaeSubreino: TracheobiontaDivisión: MagnoliophytaClase: MagnoliopsidaSubclase: CaryophyllidaeOrden: CaryophyllalesFamilia: CactaceaeSubfamilia: CactoideaeTribu: HylocereeaeGénero: SelenicereusEspecie: S. ocamponis(Salm-Dyck) D.R.Hunt, 2017Sinonimia Cereus ocamponis Salm-Dyck, 1850 (basónimo) Hylocereus bronxensis Britton y Rose, 1920 Hylocereus ocamponis (Salm-Dyck) Britton y Rose,...

QobuzTipeLayanan musikTanggal diluncurkan18 September 2007; 16 tahun lalu (2007-09-18)Situs webqobuz.com Qobuz adalah toko musik digital dan layanan streaming Prancis, diluncurkan pada tahun 2007 oleh Alexandre Leforestier dan Yves Riesel.[1] Qobuz kini dimiliki oleh Xandrie SA. Qobuz menawarkan lebih dari 100 juta lagu dalam CD dan kualitas Hi-Res (24 bit hingga 192 kHz). Lagu yang dibeli ditawarkan tanpa batasan DRM apa pun.[2] Semua musik tersedia dalam format MP3 deng...

Art movement drawing upon Islamic calligraphy Not to be confused with Hurufism. The Hurufiyya movement (Arabic: حروفية ḥurufiyyah, adjectival form ḥurufī, 'letters' (of the alphabet) is an aesthetic movement that emerged in the second half of the twentieth century amongst Muslim artists, who used their understanding of traditional Islamic calligraphy within the precepts of modern art. By combining tradition and modernity, these artists worked towards developing a culture specific v...

German-American physicist, Nobel laureate (1921–2020) Jack SteinbergerSteinberger in 2008BornHans Jakob Steinberger(1921-05-25)May 25, 1921Bad Kissingen, GermanyDiedDecember 12, 2020 (aged 99)Geneva, SwitzerlandNationalityAmerican[5]EducationUniversity of ChicagoKnown forDiscovery of the muon neutrinoSpouse(s)Cynthia Alff; Joan Beauregard (1920-2009)Children4, including Joseph, Ned, Julia, and JohnAwardsNobel Prize in Physics (1988)National Medal of Science (1988)Matteucci Meda...

Music genre Anime songNative nameアニメソングOther namesAnison (アニソン)Stylistic originsKayōkyokuCultural origins1970s, JapanDerivative formsDenpa songmoe songOther topics J-pop Japanese rock Video game music Anime song (アニメソング, anime songu, also shortened to anison (アニソン)) is a genre of music originating from Japanese pop music. Anime songs consist of theme, insert, and image songs for anime, manga, video game, and audio drama CD series, as well as any other ...

Всего 273-й истребительный авиационный полк формировался 2 раза. См. список других формирований 273-й истребительный авиационныйполк Вооружённые силы ВС СССР Вид вооружённых сил ВВС Род войск (сил) истребительная авиация Формирование 01.03.1941 г. Расформирование (преобразован...

American daily newspaper founded in 1940 This article is about the Long Island newspaper. For the offshoot New York daily (1985–1995), see New York Newsday. For other uses, see Newsday (disambiguation). NewsdayFebruary 21, 2012, front pageTypeDaily newspaperFormatTabloidOwner(s)Newsday Media(Patrick Dolan)PublisherDebby KrenekEditorDon HudsonFoundedSeptember 3, 1940; 83 years ago (1940-09-03)Headquarters6 Corporate Center Drive[1]Melville, New York, U.S. 11747Circu...

Constituency of the National Assembly of France 2nd constituency of VendéeinlineConstituency of the National Assembly of FranceVendée's 2nd Constituency shown within VendéeDeputyBéatrice BellamyHDepartmentVendéeCantonsChantonnay, Mareuil-sur-Lay-Dissais, La Mothe-Achard, Moutiers-les-Mauxfaits, La Roche-sur-Yon Sud, Talmont-Saint-HilaireRegistered voters109665[1] Politics of France Political parties Elections Previous Next The 2nd constituency of Vendée is a French legislative c...

Jamaican association football club Football clubSantos F.C.Full nameSantos Football ClubFounded1964; 59 years ago (1964)GroundBell/Chung oval Kingston, JamaicaCapacityUnknownLeagueKSAFA Super League2010–20115th Home colours Santos Football Club is a Jamaican professional football club that competes in the KSAFA Super League. The team is based in Kingston, Jamaica. History Founded on April 16, 1964, by former Jamaica national team coach Winston Chung Fah, the name and symbo...

American baseball player (born 1974) Not to be confused with Jamie Wright. Baseball player Jamey WrightWright with the Tampa Bay RaysPitcherBorn: (1974-12-24) December 24, 1974 (age 48)Oklahoma City, Oklahoma, U.S.Batted: RightThrew: RightMLB debutJuly 3, 1996, for the Colorado RockiesLast MLB appearanceSeptember 27, 2014, for the Los Angeles DodgersMLB statisticsWin–loss record97–130Earned run average4.81Strikeouts1,189 Teams Colorado Rockies (1996–19...

Ancient Indo-European language SideticRegionAncient southwestern AnatoliaExtinctafter the third century BCELanguage familyIndo-European AnatolianLuwicSideticEarly formsProto-Indo-European Proto-Anatolian Writing systemSidetic scriptLanguage codesISO 639-3xsdLinguist ListxsdGlottologside1240 The Sidetic language is a member of the extinct Anatolian branch of the Indo-European language family known from legends of coins dating to the period of approximately the 5th to 3rd centuries BCE found in...

British politician (born 1979) Paul BristowMPOfficial portrait, 2020Member of Parliamentfor PeterboroughIncumbentAssumed office 12 December 2019Preceded byLisa ForbesMajority2,580 (5.4%) Personal detailsBorn (1979-03-27) 27 March 1979 (age 44)York, EnglandPolitical partyConservativeSpouse Sara Petela ​(m. 2019)​[1]Children2Alma materLancaster UniversityWebsitewww.paulbristow.org.uk Paul Bristow (born 27 March 1979) is a British politician who has ...

This article needs additional citations for verification. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: Ideal TV series – news · newspapers · books · scholar · JSTOR (March 2017) (Learn how and when to remove this template message) British TV series or programme IdealIdeal title card for Series 6Created byGraham DuffStarringJohnny VegasCountry of origin...