Live data from Hacker News

37Signals to retire OpenID for logins on May 1

productblog.37signals.com

1–10 of 118 posts

Re: 37Signals to retire OpenID for logins on May 1

#2
I don't understand. They use single text box of OpenID login. They have it separated from login page in another page. How do they want it to be successful and where is their ultimate usability mastery?

There is no way OpenID can be improved when there is no interest in solving global internet issues. Neither Facebook for implementing the own mechanism nor 37signals would get medal of honor for uniting the internet.

Re: 37Signals to retire OpenID for logins on May 1

#3
Totally understandable, one of the worst executed visions of all times.

I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

Re: 37Signals to retire OpenID for logins on May 1

#4
"Login with Facebook, Login with Twitter" <- these are your new single sign on providers. I wonder if in the future they'll try to standardize these login providers and the information they share, we can call the new standard Open...something...ID...no...OpenLogin, there we go.

Re: 37Signals to retire OpenID for logins on May 1

#5

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

That particular holy grail is a poisoned chalice and it's claimed plenty of victims, anyone remember Sxip? It's not a technical problem, it's power, control and ownership. Anyone in a position to allow a platform to get serious traction isn't going to give that control up and anyone that isn't can't make a system with enough traction. Then there's issues of trust, delegation and longevity. I'd love someone to do it well, I'd love the ability to have anonymous, durable, cryptographically verifiable identities online that could be optionally tied to meatspace identifiers but I just don't see it happening.

Re: 37Signals to retire OpenID for logins on May 1

#6

I don't understand. They use single text box of OpenID login. They have it separated from login page in another page. How do they want it to be successful and where is their ultimate usability mastery? There is no way OpenID can be improved when there is no interest in solving global internet issues. Neither Facebook for implementing the own mechanism nor 37signals would get medal of honor for uniting the internet.

37signals doesn't want the "medal of honor for uniting the Internet".

Re: 37Signals to retire OpenID for logins on May 1

#7

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

I think the problem lies in how those iedentities are established. A prolific Twitter or Facebook account makes a good identity precisely because you have spent time pouring your identity into it. Your family photos, relationships, residence and work history on your Facebook page. Your daily thoughts and actions cataloged on your Twitter feed. While not perfect, they're the best thing we have right now to externally verify that you are who you claim to be. They provide context to the authentication. Any external service that implemented the authentication standard that may arise out of this situation lacks that identifying context and the best case scenarion only serves to prove that the user authenticating is the user who setup the account. Taking away Facebook's and Twitter's context makes spoofing that authentication much easier.

Solving that in a way that doesn't violate the privacy concerns of your users seems like something of a holy grail. Panacea if it exists, but far from demonstrated.

Re: 37Signals to retire OpenID for logins on May 1

#8

I don't understand. They use single text box of OpenID login. They have it separated from login page in another page. How do they want it to be successful and where is their ultimate usability mastery? There is no way OpenID can be improved when there is no interest in solving global internet issues. Neither Facebook for implementing the own mechanism nor 37signals would get medal of honor for uniting the internet.

The key problem didn't come from people NOT using OpenID, but from the people who did. Supporting OpenID is a nightmare. You have different relaying services that go up and down (OpenID's answer is: "use more than one" - ha!), various levels of incompatibility, and a generally user hostile experience.

If OpenID usage had been in any serious numbers, our support department would have revolted.

If you're trying to build a profitable online business, cutting your support costs is key. And the easiest way to cut your support costs is to dump confusing features or technologies that people constantly write in about.

Same reason we originally dumped FTP in favor of hosting files ourselves. The support costs were way too high.

Re: 37Signals to retire OpenID for logins on May 1

#9

"Login with Facebook, Login with Twitter" <- these are your new single sign on providers. I wonder if in the future they'll try to standardize these login providers and the information they share, we can call the new standard Open...something...ID...no...OpenLogin, there we go.

Google Account auth is nice too. It actually uses OpenID in the background, but the user doesn't have to understand what OpenID is. As it should be.

Re: 37Signals to retire OpenID for logins on May 1

#10

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

"one of the worst executed visions of all times"

What could have been done better?

I spent a couple of years advocating for OpenID adoption, because I believed that the alternative (one or two companies controlling login for the entire Web, ala Microsoft Passport or Facebook Connect) would be a massive blow to the decentralised nature of the internet. I believed that OpenID's usability issues could be resolved if enough smart people got involved in figuring them out.

Clearly I was wrong on that last point.

And yes, my latest project (lanyrd.com) uses Twitter rather than OpenID for authentication. From a developer point of view, that gets me the benefits I hoped for with OpenID (SSO, portable identities, instant contact lists) without having to wait for the world to agree on the standards. I just wish we could have figured out a decentralised solution.

Post reply on HN