Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Account creation section #1723

Merged
merged 1 commit into from
Jan 4, 2023
Merged

Conversation

razac-elda
Copy link
Contributor

New section to discuss the various aspect of creating new accounts.
The idea came from the discussion about Single sign-on #1609 and suggestions from @matchboxbananasynergy on his passwords knowledge base #1706 .

As of now I added some general ideas for the page, feel free to give me you opinion.

@razac-elda razac-elda temporarily deployed to preview September 6, 2022 17:51 Inactive
@github-actions
Copy link

github-actions bot commented Sep 6, 2022

🎊 PR Preview 9da5318 has been successfully built and deployed to https://privacyguides-privacyguides-org-preview-pr-1723.surge.sh

🕐 Build time: 105.415s

🤖 By surge-preview

@jonaharagon jonaharagon added the c:guides full-length guides and content label Sep 6, 2022
@razac-elda razac-elda temporarily deployed to preview September 8, 2022 19:13 Inactive
@razac-elda razac-elda temporarily deployed to preview September 8, 2022 19:16 Inactive
@razac-elda razac-elda temporarily deployed to preview September 13, 2022 23:06 Inactive
@razac-elda razac-elda temporarily deployed to preview September 13, 2022 23:51 Inactive
@razac-elda razac-elda temporarily deployed to preview September 14, 2022 23:21 Inactive
@razac-elda razac-elda temporarily deployed to preview September 15, 2022 11:41 Inactive
@razac-elda razac-elda temporarily deployed to preview September 15, 2022 12:04 Inactive
@razac-elda razac-elda temporarily deployed to preview September 15, 2022 12:09 Inactive
@razac-elda razac-elda temporarily deployed to preview September 15, 2022 12:26 Inactive
@razac-elda razac-elda temporarily deployed to preview September 15, 2022 12:49 Inactive
@razac-elda
Copy link
Contributor Author

I have some questions:

  1. The email alias section is a quick descritpion since it's already described in the recommendation page, should we leave it like this?
  2. I know some services offer phone number aliases and Mozilla will also add it to Relay, it is worth mentioning? I don't have much knowledge about this type of alias.
  3. I added links to some recommendations pages, would it be better to have buttons instead(md-button)?

Any suggestions are welcome.

@@ -7,17 +7,17 @@ Whenever you have to create a new account for a service you are required to read

## Terms of Service(ToS)

Terms of Service(ToS) are one of the most ignored aspect when creating a new account. They are the legal agreements for using the service including how your data will be used, often referred to as the **Privacy Policy**.
Terms of Service(ToS) are one of the most ignored aspect when creating a new account. They are the legal agreements in order to use the service and also include how your data will be used, often referred to as the **Privacy Policy**.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

? I don't think this is correct. I am not talking about the correction but the Privacy Policy is a legal agreement? Also in the way that the sentences follow up it looks like Privacy Policy is some part of ToS which often isn't the case.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I thought it was part of the ToS it's just different document, Wikipedia also says so. ToS are the legal agreements and the Privacy Policy is a legal document. Perhaps someone with a legal background can clarify this point.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well a privacy policy legally cannot be part of the ToS. Doesn't mean that it doesn't happen but the GDPR has set strict rules on accessibility to privacy information and therefore it cannot be hidden in a ToS.

Copy link
Contributor Author

@razac-elda razac-elda Sep 15, 2022

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To avoid any confusion I can talk about it separately but I still think that it's part of the ToS. It is a separate document for easier access, following GDPR rules. If you have a look at some ToS privacy section you can find links to the Privacy Policy.

All the websites I checked asked you to accept the ToS and only sometimes they mentioned the PP during registration. You do not accept the PP, only the ToS. So if I accept the ToS I also accept the PP but not vice versa.

For example ProtonMail ToS says "...By agreeing to the present Terms and to be able to use the Services, you also agree to our Privacy Policy." and inside the Privacy Policy "...This privacy policy is to be read and understood as being a complement to our terms of service."

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry but none of this is right. Under GDPR data processors are required to ask for consent to the data subject. I highly doubt the legality of putting it in the ToS.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we are both missing something here, I do agree that consent must be given.
The way it's given is different form website to website. Some ask only for ToS, some for ToS and tell you to read the PP(linked in the form or inside the ToS), others want you to accept everything(ToS, PP, cookies...). I found a few, like banks, that you need to give consent on each type of data process.

The European Commission website has a lot of guidelines on how to implement GDPR, including consent for data collection, but there is a lot to unwarp here. Maybe someone will chime in to help us understand.

To avoid getting too much off topic I think it would be a good choice to discuss ToS and PP separately in this page and advise users to read both.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I already do understand :) but I agree with the latter.

Copy link
Member

@jonaharagon jonaharagon Sep 16, 2022

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Typically the Terms of Service are things you are agreeing to do when using a site, and the Privacy Policy is the site agreeing to only do certain things with the data you give it. I think I agree with just discussing both of them independently of each other.

@razac-elda razac-elda temporarily deployed to preview September 18, 2022 13:43 Inactive
@razac-elda razac-elda temporarily deployed to preview September 19, 2022 18:33 Inactive
@razac-elda razac-elda temporarily deployed to preview September 19, 2022 19:42 Inactive
@razac-elda razac-elda temporarily deployed to preview September 19, 2022 21:59 Inactive
@razac-elda razac-elda temporarily deployed to preview September 20, 2022 18:18 Inactive
@razac-elda razac-elda marked this pull request as ready for review September 20, 2022 18:21
@razac-elda
Copy link
Contributor Author

@Redre1l Thanks, I don't always get along with english grammar 😅

@razac-elda razac-elda temporarily deployed to preview September 22, 2022 09:55 Inactive
@netlify
Copy link

netlify bot commented Nov 1, 2022

Deploy Preview for privacyguides ready!

Name Link
🔨 Latest commit 0d59716
🔍 Latest deploy log https://app.netlify.com/sites/privacyguides/deploys/63b571bcb410ad000b67940e
😎 Deploy Preview https://deploy-preview-1723--privacyguides.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

@ghost
Copy link

ghost commented Dec 10, 2022

One thing that we could mention here is that the way services use email is essentially a crappy version of SSO, since if your email account is compromised you essentially can access any account that uses that email. So I wouldn't put that as a disadvantage for SSO, since email has the same problem but worse. It's actually superior in this regard IMO.

@matchboxbananasynergy
Copy link
Contributor

One thing that we could mention here is that the way services use email is essentially a crappy version of SSO, since if your email account is compromised you essentially can access any account that uses that email. So I wouldn't put that as a disadvantage for SSO, since email has the same problem but worse. It's actually superior in this regard IMO.

There also a potential security advantage if you use Google's SSO for example while securing your Google account with a hardware key, for example, whereas whatever service you're using may not implement it.

docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
@ghost ghost self-assigned this Dec 11, 2022
@razac-elda
Copy link
Contributor Author

razac-elda commented Dec 13, 2022

@mfwmyfacewhen Thanks for your contributions.

One thing that we could mention here is that the way services use email is essentially a crappy version of SSO, since if your email account is compromised you essentially can access any account that uses that email. So I wouldn't put that as a disadvantage for SSO, since email has the same problem but worse. It's actually superior in this regard IMO.

They share this problem, but with emails it can be mitigated if you setup 2FA for your accounts. If SSO security is breached, not much can be done.

There also a potential security advantage if you use Google's SSO for example while securing your Google account with a hardware key, for example, whereas whatever service you're using may not implement it.

I like the idea to leverage on SSO providers security features if other services lacks them.

Edit: would you like to explain it yourself or should I write a rough draft?

docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
@dngray dngray force-pushed the account-creation branch 3 times, most recently from a333784 to f04be34 Compare January 1, 2023 17:56

## Terms of Service & Privacy Policy

Terms of Service(ToS) and Privacy Policy are two of the most ignored aspects of creating a new account. The ToS are the rules that you agree to follow when using the service. Breaking them could result in account termination or other action, so it's important to be familiar with them. The Privacy Policy is how the service will use your data. Sometimes critical privacy issues can be hidden here, so you should take the time to read it. A company or organization might not be legally obligated to follow everything in it; you should check your local laws and see what they legally must do to protect your data, or what data they might be legally required to collect.
The ToS (Terms of Service) are the rules that you agree to follow when using the service. With larger services these rules are often enforced by automated systems. Sometimes these automated systems can make mistakes such as if the account is new, you use a VPN or a phone number not tied to a real mobile service (such as a virtual number). Appealing such bans is often difficult, and involves an automated process too, which isn't always successful. This would be one of the reasons why we wouldn't suggest using Gmail for email as an example. Email is crucial for access to other services you might have signed up for.
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ToS (Terms of Service)

It's best to put the abbreviation inside the brackets .

if the account is new

I don't think this is relevant. You can break ToS at any time, not just with new accounts.

Copy link
Member

@dngray dngray Jan 2, 2023

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's best to put the abbreviation inside the brackets .

Thinking we can just remove the bracketed version afterwards, because it does have the mouse over abbreviation. It's also in the heading.

It is, because you may not necessarily break the ToS, but can still have accounts locked, due to them being new, using a VPN, or using VOIP numbers.

I don't think this is relevant. You can break ToS at any time, not just with new accounts.

These are all things often "recommended" by the privacy community for "privacy".

docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
docs/basics/account-creation.en.md Outdated Show resolved Hide resolved
dngray added a commit to razac-elda/privacyguides.org that referenced this pull request Jan 4, 2023
Co-authored-by: matchboxbananasynergy <107055883+matchboxbananasynergy@users.noreply.github.com>
Co-authored-by: mfwmyfacewhen <94880365+mfwmyfacewhen@users.noreply.github.com>
Co-authored-by: Daniel Gray <dngray@privacyguides.org>
Co-authored-by: matchboxbananasynergy <107055883+matchboxbananasynergy@users.noreply.github.com>
Co-authored-by: mfwmyfacewhen <94880365+mfwmyfacewhen@users.noreply.github.com>
Co-authored-by: Daniel Gray <dngray@privacyguides.org>
@dngray dngray merged commit 0d59716 into privacyguides:main Jan 4, 2023
@razac-elda razac-elda deleted the account-creation branch January 4, 2023 13:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
c:guides full-length guides and content
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

7 participants