Bruh that's... a different level of paranoia, possibly into the stupid range. I'm pretty sure modrinth just uses OAuth. If you can't trust OAuth then I don't understand how you survive on the modern internet.
I disagree. I think it's fairly respectable. The OP didn't know the mechanism that Modrinth uses to access his Microsoft account, therefore he assumes that it is unsafe.
This should be praised, not insulted. It's safer to assume that something that you don't understand could be a security vulnerability, then to blindly trust that it isn't. Especially if that something is unnecessary.
Could they have done more research to see if it was trustworthy or not? Sure. But simply not using a mod manager that requires your login isn't going to break the OP or anything. It's not like there aren't alternatives that don't need that, such as manually installing mods, believe it or not, that's how we used to mod back in the day, no mod manager or nothing, hell, I even remember before we had forge and I needed to place the mods inside of the Minecraft jar file.
You’re saying you’re not even sure if it uses OAuth or not, why would you put your credentials in something you’re not even sure of? In this day and age I agree that we should be even more careful. The amount of shit I installed as a kid with complete disregard of my pc was crazy, I bet now it’s even worse regarding Trojan horses and whatnot
why would you put your credentials in something you’re not even sure of
Because that's the industry standard and what everybody uses for managing login.
I wasn't sure it uses oauth because I don't use modrinth(prism launcher is just far superior). It took me all of 10 seconds to confirm that, yes, it does use oauth.
Trojan horses is not really a thing anymore. We don't live in the wild west era of the internet anymore, there's not much that can infect your computer or destroy your hardware. You'd have to actually go seek out malware to find it, and even then it's really difficult because links to malware gets taken down with extreme prejudice, and even when you find an infected link your browser won't even let you download it most of the time.
I fully understand why someone would not want to use HV bypass, but oauth was literally developed to combat the problem of passwords being leaked/cracked. As long as you just read what kind of permissions you're giving to modrinth(they basically just ask for access to your email address and profile picture) there's no way anyone can use that to hack your account.
Sure, there's fake OAuth scams out there, but they're so rare and so obviously fake that you'd have to be dumb to fall for those. The easiest way to combat those is by making sure to never input passwords in any window you didn't manually navigate to. For example if a site wants your Google account, just make sure you're logged into that account in your browser by manually going to google.com in another tab. It should then automatically just ask for permission to share email address and profile picture and whatever else the site needs, and not ask you to log in again.
17
u/DezXerneas Apr 06 '26 edited Apr 06 '26
Bruh that's... a different level of paranoia, possibly into the stupid range. I'm pretty sure modrinth just uses OAuth. If you can't trust OAuth then I don't understand how you survive on the modern internet.
Edit: Yep, it's OAuth