This is just the beginning. Facebook and Spotify set a nice precedent there to make it en-vogue to just provide a Facebook login for services in the future.
For whoever builds the service, it's (marginally) easier to just use FB as an authentication provider and they even get to spin it as "with us, you don't need to store the 1000st password - you can just use Facebook".
For Facebook, of course, it's great too as it is one more thing to force people to stay logged in, which in turn is much better data for them.
The end users probably wouldn't care either as they are mostly logged into Facebook anyways and if not, it's easy for them to just log in.
The only losers are us professionals who know about the implications of such a move and who care about the loss of privacy.
And of course the people who had their facebook account suspended for either legitimate reasons or just some oversensitive SPAM protection algorithm. These people are now locked out of their, possibly even paid, account, unable to access it (and remove credit card info). Of course these will be the minority and people won't care.
Until it's them that are affected.
I can understand that in this day and age you want to provide the users with an option to authenticate with something else than yet another username and password. Google, Twitter, Yahoo or even any OpenID provider (maybe your own). Sure.
But just Facebook? This is trouble waiting to happen.
I'm saying this as somebody who can't have Spotify anyways due to the complete brokenness of the licensing market, but this still concerns me as it's just another precedent and I'm just waiting for another service I love to force me to use Facebook.
I'm start to see a trend (very very early stages) of sites that simply don't require a login at all. I'm thrilled about this, as the need to login to every website has gone too too far in my opinion. If you absolutely must maintain state through sessions, simply send the user an email with a temporary token to create a new session (Staticloud is one that does this). Email is the universal identity controlled by no one entity.
> The only losers are us professionals who know about the implications of such a move and who care about the loss of privacy.
You're right. But there is salvation on the music front: Use Streamripper to download music from a diversity of Internet Radios, and listen to it on your leisure, radically deleting everything that doesn't appeal to you. I guess you'll discover some new music, too! (I did). Somafm.com and Schizoid are good places to start. Streamripper also interprets metadata and will name the downloaded MP3 tracks in a recognizable way.
It's also not very hard to hack something up to download from pandora/grooveshark and keep the files, or even play them back into the browser. I've been hacking away on a pandora player which is certainly not ready for any 'real' use. http://github.com/dekz/pianode
Interesting, I see you've written it in Coffeescript. It's the first time I've looked at Coffeescript and what I see pleases me: Javascript with Python-style identation.
The immediate losers are those that shun facebook, but anyone that cares about their data is a potential loser, depending on what facebook does in the future.
Google, Twitter, Yahoo ... Sure. But just Facebook? This is trouble waiting to happen.
Is Facebook any different than those others? Google, Twitter, and Yahoo also all want to slurp up all personal user data that they can collect, and represent a single-point-of-failure for a spam detection false positive or account compromisation.
I think you missed the point. If I can use any OpenID provider I can use my Google, Twitter, Yahoo (but NOT Facebook accounts, very intentionally [it used to be an identity provider but they removed it when they introduced Connect]). But more importantly, if it's generic OpenID/BrowserID, I can truly own my identity. As long as Facebook continues to get their proprietary tentacles in everything, they continue to own my identity and make me indebted to their stewardship.
If it's my http://firstname.lastname.com OpenID identity, I will always own and control it, even if Zuckerberg goes off the deep end and tracks me even when I'm not logged in and shares these details with non-Facebook sites, etc.
For whoever builds the service, it's (marginally) easier to just use FB as an authentication provider and they even get to spin it as "with us, you don't need to store the 1000st password - you can just use Facebook".
For Facebook, of course, it's great too as it is one more thing to force people to stay logged in, which in turn is much better data for them.
The end users probably wouldn't care either as they are mostly logged into Facebook anyways and if not, it's easy for them to just log in.
The only losers are us professionals who know about the implications of such a move and who care about the loss of privacy.
And of course the people who had their facebook account suspended for either legitimate reasons or just some oversensitive SPAM protection algorithm. These people are now locked out of their, possibly even paid, account, unable to access it (and remove credit card info). Of course these will be the minority and people won't care.
Until it's them that are affected.
I can understand that in this day and age you want to provide the users with an option to authenticate with something else than yet another username and password. Google, Twitter, Yahoo or even any OpenID provider (maybe your own). Sure.
But just Facebook? This is trouble waiting to happen.
I'm saying this as somebody who can't have Spotify anyways due to the complete brokenness of the licensing market, but this still concerns me as it's just another precedent and I'm just waiting for another service I love to force me to use Facebook.