\n\ntfr","local":false,"banner":"https://cdn.masto.host/tootworks/accounts/headers/109/270/372/781/957/605/original/fba8611adadf9e0f.png","deleted":false,"inbox_url":"https://toot.works/users/joe/inbox","shared_inbox_url":"https://toot.works/inbox","matrix_user_id":null,"admin":false,"bot_account":false,"ban_expires":null,"instance_id":407},"post":{"id":8352,"name":"[@protonprivacy](https://lemmy.world/c/protonprivacy) Any plans to tackle identity? For SSO purposes I’m stuck with say, google but would love to move over to proton.","url":null,"body":"[@protonprivacy](https://lemmy.world/c/protonprivacy) Any plans to tackle identity? For SSO purposes I’m stuck with say, google but would love to move over to proton.","creator_id":59259,"community_id":7,"removed":false,"locked":false,"published":"2024-01-10T19:12:02","updated":null,"deleted":false,"nsfw":false,"embed_title":null,"embed_description":null,"embed_video_url":null,"thumbnail_url":null,"ap_id":"https://infosec.exchange/users/theomegabit/statuses/111733238807503394","local":false,"language_id":0,"featured_community":false,"featured_local":false},"community":{"id":7,"name":"protonprivacy","title":"Proton ","description":"Empowering you to choose a better internet where privacy is the default. Protect yourself online with \nProton Mail, Proton VPN, Proton Calendar, Proton Drive. Proton Pass and SimpleLogin.\n\nProton Mail is the world's largest secure email provider. Swiss, end-to-end encrypted, private, and free.\n\nProton VPN is the world’s only open-source, publicly audited, unlimited and free VPN. Swiss-based, no-ads, and no-logs. \n\nProton Calendar is the world's first end-to-end encrypted calendar that allows you to keep your life private.\n\nProton Drive is a free end-to-end encrypted cloud storage that allows you to securely backup and share your files. It's open source, publicly audited, and Swiss-based.\n\nProton Pass Proton Pass is a free and open-source password manager which brings a higher level of security with rigorous end-to-end encryption of all data (including usernames, URLs, notes, and more) and email alias support. \n\nSimpleLogin lets you send and receive emails anonymously via easily-generated unique email aliases.\n","removed":false,"published":"2023-06-26T16:15:22.431165","updated":"2023-07-17T21:36:15.824194","deleted":false,"nsfw":false,"actor_id":"https://lemmy.world/c/protonprivacy","local":false,"icon":"https://lemmy.world/pictrs/image/cd304a0c-e258-4a87-86cd-7ce21eb70191.png","banner":"https://lemmy.world/pictrs/image/cdb7e0f7-d192-4ea4-85c1-4b2fe002aae1.jpeg","hidden":false,"posting_restricted_to_mods":false,"instance_id":6},"counts":{"id":10278,"comment_id":12165,"score":2,"upvotes":2,"downvotes":0,"published":"2024-01-10T19:31:53","child_count":0},"creator_banned_from_community":false,"subscribed":"NotSubscribed","saved":false,"creator_blocked":false,"my_vote":null},{"comment":{"id":12175,"creator_id":15106,"post_id":8352,"content":"I think that @theomegabit@infosec.exchange is asking for Proton to become an OAuth/OIDC provider. This would allow you to sign into any service, app, platform, etc. that supports it using your Proton account. Some common providers that are widely supported are Google, Apple, Github, Facebook, and Microsoft.\n\nIt is generally considered more secure than using \"regular credentials\" like username/email and password when using several services. There are a few downsides to this though. One of those downsides is that your OAuth/OIDC provider will have record of all your accounts used through OAuth/OIDC. For example, @theomegabit@infosec.exchange would like to avoid Google knowing about the various services used.","removed":false,"published":"2024-01-10T23:20:20.034156","updated":null,"deleted":false,"ap_id":"https://lemmy.ml/comment/7240876","local":false,"path":"0.12170.12175","distinguished":false,"language_id":37},"creator":{"id":15106,"name":"rhymepurple","display_name":null,"avatar":null,"banned":false,"published":"2021-11-29T02:42:02.614199","updated":null,"actor_id":"https://lemmy.ml/u/rhymepurple","bio":null,"local":false,"banner":null,"deleted":false,"inbox_url":"https://lemmy.ml/u/rhymepurple/inbox","shared_inbox_url":"https://lemmy.ml/inbox","matrix_user_id":null,"admin":false,"bot_account":false,"ban_expires":null,"instance_id":3},"post":{"id":8352,"name":"[@protonprivacy](https://lemmy.world/c/protonprivacy) Any plans to tackle identity? For SSO purposes I’m stuck with say, google but would love to move over to proton.","url":null,"body":"[@protonprivacy](https://lemmy.world/c/protonprivacy) Any plans to tackle identity? For SSO purposes I’m stuck with say, google but would love to move over to proton.","creator_id":59259,"community_id":7,"removed":false,"locked":false,"published":"2024-01-10T19:12:02","updated":null,"deleted":false,"nsfw":false,"embed_title":null,"embed_description":null,"embed_video_url":null,"thumbnail_url":null,"ap_id":"https://infosec.exchange/users/theomegabit/statuses/111733238807503394","local":false,"language_id":0,"featured_community":false,"featured_local":false},"community":{"id":7,"name":"protonprivacy","title":"Proton ","description":"Empowering you to choose a better internet where privacy is the default. Protect yourself online with \nProton Mail, Proton VPN, Proton Calendar, Proton Drive. Proton Pass and SimpleLogin.\n\nProton Mail is the world's largest secure email provider. Swiss, end-to-end encrypted, private, and free.\n\nProton VPN is the world’s only open-source, publicly audited, unlimited and free VPN. Swiss-based, no-ads, and no-logs. \n\nProton Calendar is the world's first end-to-end encrypted calendar that allows you to keep your life private.\n\nProton Drive is a free end-to-end encrypted cloud storage that allows you to securely backup and share your files. It's open source, publicly audited, and Swiss-based.\n\nProton Pass Proton Pass is a free and open-source password manager which brings a higher level of security with rigorous end-to-end encryption of all data (including usernames, URLs, notes, and more) and email alias support. \n\nSimpleLogin lets you send and receive emails anonymously via easily-generated unique email aliases.\n","removed":false,"published":"2023-06-26T16:15:22.431165","updated":"2023-07-17T21:36:15.824194","deleted":false,"nsfw":false,"actor_id":"https://lemmy.world/c/protonprivacy","local":false,"icon":"https://lemmy.world/pictrs/image/cd304a0c-e258-4a87-86cd-7ce21eb70191.png","banner":"https://lemmy.world/pictrs/image/cdb7e0f7-d192-4ea4-85c1-4b2fe002aae1.jpeg","hidden":false,"posting_restricted_to_mods":false,"instance_id":6},"counts":{"id":10285,"comment_id":12175,"score":3,"upvotes":3,"downvotes":0,"published":"2024-01-10T23:20:20.034156","child_count":0},"creator_banned_from_community":false,"subscribed":"NotSubscribed","saved":false,"creator_blocked":false,"my_vote":null},{"comment":{"id":12177,"creator_id":59259,"post_id":8352,"content":"[@helenslunch](https://feddit.nl/u/helenslunch) Nobody uses a good privacy/security focused IdP because one doesn’t exist for consumer / smb besides a small handful (many which you noted).","removed":false,"published":"2024-01-11T11:05:07","updated":null,"deleted":false,"ap_id":"https://infosec.exchange/users/theomegabit/statuses/111736986522255978","local":false,"path":"0.12176.12177","distinguished":false,"language_id":0},"creator":{"id":59259,"name":"theomegabit","display_name":"theOmegabit","avatar":"https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/298/658/059/972/311/original/dee98bb28b4e6aca.jpeg","banned":false,"published":"2022-11-06T00:00:00","updated":null,"actor_id":"https://infosec.exchange/users/theomegabit","bio":"AWS SA Pro | CISSP / CCSP | Security Engineer / Team Lead | Tech enthusiast | Photographer 📸","local":false,"banner":"https://media.infosec.exchange/infosec.exchange/accounts/headers/109/298/658/059/972/311/original/5a36f06e6d467b7a.jpg","deleted":false,"inbox_url":"https://infosec.exchange/users/theomegabit/inbox","shared_inbox_url":"https://infosec.exchange/inbox","matrix_user_id":null,"admin":false,"bot_account":false,"ban_expires":null,"instance_id":326},"post":{"id":8352,"name":"[@protonprivacy](https://lemmy.world/c/protonprivacy) Any plans to tackle identity? For SSO purposes I’m stuck with say, google but would love to move over to proton.","url":null,"body":"[@protonprivacy](https://lemmy.world/c/protonprivacy) Any plans to tackle identity? For SSO purposes I’m stuck with say, google but would love to move over to proton.","creator_id":59259,"community_id":7,"removed":false,"locked":false,"published":"2024-01-10T19:12:02","updated":null,"deleted":false,"nsfw":false,"embed_title":null,"embed_description":null,"embed_video_url":null,"thumbnail_url":null,"ap_id":"https://infosec.exchange/users/theomegabit/statuses/111733238807503394","local":false,"language_id":0,"featured_community":false,"featured_local":false},"community":{"id":7,"name":"protonprivacy","title":"Proton ","description":"Empowering you to choose a better internet where privacy is the default. Protect yourself online with \nProton Mail, Proton VPN, Proton Calendar, Proton Drive. Proton Pass and SimpleLogin.\n\nProton Mail is the world's largest secure email provider. Swiss, end-to-end encrypted, private, and free.\n\nProton VPN is the world’s only open-source, publicly audited, unlimited and free VPN. Swiss-based, no-ads, and no-logs. \n\nProton Calendar is the world's first end-to-end encrypted calendar that allows you to keep your life private.\n\nProton Drive is a free end-to-end encrypted cloud storage that allows you to securely backup and share your files. It's open source, publicly audited, and Swiss-based.\n\nProton Pass Proton Pass is a free and open-source password manager which brings a higher level of security with rigorous end-to-end encryption of all data (including usernames, URLs, notes, and more) and email alias support. \n\nSimpleLogin lets you send and receive emails anonymously via easily-generated unique email aliases.\n","removed":false,"published":"2023-06-26T16:15:22.431165","updated":"2023-07-17T21:36:15.824194","deleted":false,"nsfw":false,"actor_id":"https://lemmy.world/c/protonprivacy","local":false,"icon":"https://lemmy.world/pictrs/image/cd304a0c-e258-4a87-86cd-7ce21eb70191.png","banner":"https://lemmy.world/pictrs/image/cdb7e0f7-d192-4ea4-85c1-4b2fe002aae1.jpeg","hidden":false,"posting_restricted_to_mods":false,"instance_id":6},"counts":{"id":10287,"comment_id":12177,"score":0,"upvotes":1,"downvotes":1,"published":"2024-01-11T11:05:07","child_count":1},"creator_banned_from_community":false,"subscribed":"NotSubscribed","saved":false,"creator_blocked":false,"my_vote":null},{"comment":{"id":12178,"creator_id":45045,"post_id":8352,"content":"No, no one uses them for the same reason they don't use any other privacy/security-focused product: No demand. There's a small niche of consumers who do care and use products like Proton but it's an absolutely miniscule fraction of the populace who simply don't care, or don't care enough to actually do anything about it. ","removed":false,"published":"2024-01-11T17:41:21.500582","updated":null,"deleted":false,"ap_id":"https://feddit.nl/comment/5942810","local":false,"path":"0.12176.12177.12178","distinguished":false,"language_id":37},"creator":{"id":45045,"name":"helenslunch","display_name":null,"avatar":"https://feddit.nl/pictrs/image/b7be0730-a300-4c79-bf07-a4d81a633e17.png","banned":false,"published":"2023-10-21T20:55:47.738179","updated":null,"actor_id":"https://feddit.nl/u/helenslunch","bio":null,"local":false,"banner":null,"deleted":false,"inbox_url":"https://feddit.nl/u/helenslunch/inbox","shared_inbox_url":"https://feddit.nl/inbox","matrix_user_id":"@ulrich:nope.chat","admin":false,"bot_account":false,"ban_expires":null,"instance_id":51},"post":{"id":8352,"name":"[@protonprivacy](https://lemmy.world/c/protonprivacy) Any plans to tackle identity? For SSO purposes I’m stuck with say, google but would love to move over to proton.","url":null,"body":"[@protonprivacy](https://lemmy.world/c/protonprivacy) Any plans to tackle identity? For SSO purposes I’m stuck with say, google but would love to move over to proton.","creator_id":59259,"community_id":7,"removed":false,"locked":false,"published":"2024-01-10T19:12:02","updated":null,"deleted":false,"nsfw":false,"embed_title":null,"embed_description":null,"embed_video_url":null,"thumbnail_url":null,"ap_id":"https://infosec.exchange/users/theomegabit/statuses/111733238807503394","local":false,"language_id":0,"featured_community":false,"featured_local":false},"community":{"id":7,"name":"protonprivacy","title":"Proton ","description":"Empowering you to choose a better internet where privacy is the default. Protect yourself online with \nProton Mail, Proton VPN, Proton Calendar, Proton Drive. Proton Pass and SimpleLogin.\n\nProton Mail is the world's largest secure email provider. Swiss, end-to-end encrypted, private, and free.\n\nProton VPN is the world’s only open-source, publicly audited, unlimited and free VPN. Swiss-based, no-ads, and no-logs. \n\nProton Calendar is the world's first end-to-end encrypted calendar that allows you to keep your life private.\n\nProton Drive is a free end-to-end encrypted cloud storage that allows you to securely backup and share your files. It's open source, publicly audited, and Swiss-based.\n\nProton Pass Proton Pass is a free and open-source password manager which brings a higher level of security with rigorous end-to-end encryption of all data (including usernames, URLs, notes, and more) and email alias support. \n\nSimpleLogin lets you send and receive emails anonymously via easily-generated unique email aliases.\n","removed":false,"published":"2023-06-26T16:15:22.431165","updated":"2023-07-17T21:36:15.824194","deleted":false,"nsfw":false,"actor_id":"https://lemmy.world/c/protonprivacy","local":false,"icon":"https://lemmy.world/pictrs/image/cd304a0c-e258-4a87-86cd-7ce21eb70191.png","banner":"https://lemmy.world/pictrs/image/cdb7e0f7-d192-4ea4-85c1-4b2fe002aae1.jpeg","hidden":false,"posting_restricted_to_mods":false,"instance_id":6},"counts":{"id":10288,"comment_id":12178,"score":1,"upvotes":1,"downvotes":0,"published":"2024-01-11T17:41:21.500582","child_count":0},"creator_banned_from_community":false,"subscribed":"NotSubscribed","saved":false,"creator_blocked":false,"my_vote":null}]}]}
@protonprivacy Any plans to tackle identity? For SSO purposes I’m stuck with say, google but would love to move over to proton.
Empowering you to choose a better internet where privacy is the default. Protect yourself online with Proton Mail, Proton VPN, Proton Calendar, Proton Drive. Proton Pass and SimpleLogin.
Proton Mail is the world’s largest secure email provider. Swiss, end-to-end encrypted, private, and free.
Proton VPN is the world’s only open-source, publicly audited, unlimited and free VPN. Swiss-based, no-ads, and no-logs.
Proton Calendar is the world’s first end-to-end encrypted calendar that allows you to keep your life private.
Proton Drive is a free end-to-end encrypted cloud storage that allows you to securely backup and share your files. It’s open source, publicly audited, and Swiss-based.
Proton Pass Proton Pass is a free and open-source password manager which brings a higher level of security with rigorous end-to-end encryption of all data (including usernames, URLs, notes, and more) and email alias support.
SimpleLogin lets you send and receive emails anonymously via easily-generated unique email aliases.
They could make an SSO but who would use it? Proton users make up such a small portion of the web that it wouldn’t be worth the effort and they might as well include 8541705317 other accounts at that point, as far as they’re concerned.
They use SSO because almost everyone already has 1 or more accounts with Google, Amazon, Microsoft, etc.
@helenslunch Nobody uses a good privacy/security focused IdP because one doesn’t exist for consumer / smb besides a small handful (many which you noted).
No, no one uses them for the same reason they don’t use any other privacy/security-focused product: No demand. There’s a small niche of consumers who do care and use products like Proton but it’s an absolutely miniscule fraction of the populace who simply don’t care, or don’t care enough to actually do anything about it.
You mean like something to compete with services like DeleteMe, Incogni and Aura?
I’d be down for that, I’d like it to be included with proton family, that would give me a good reason to bite the bullet and pay the extra money for it.
I think that @theomegabit@infosec.exchange is asking for Proton to become an OAuth/OIDC provider. This would allow you to sign into any service, app, platform, etc. that supports it using your Proton account. Some common providers that are widely supported are Google, Apple, Github, Facebook, and Microsoft.
It is generally considered more secure than using “regular credentials” like username/email and password when using several services. There are a few downsides to this though. One of those downsides is that your OAuth/OIDC provider will have record of all your accounts used through OAuth/OIDC. For example, @theomegabit@infosec.exchange would like to avoid Google knowing about the various services used.
@theomegabit @protonprivacy Adding @protonmail to get their attention.
@theomegabit @protonprivacy