Live data from Hacker News

37Signals to retire OpenID for logins on May 1

productblog.37signals.com

21–30 of 118 posts

Re: 37Signals to retire OpenID for logins on May 1

#21

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

I don't know why this couldn't be done via the normal RFC process. I can imagine a version of this done with something based (very roughly) on DNS.

Re: 37Signals to retire OpenID for logins on May 1

#22
post #14

I think I'm starting to understand 37signals advertising strategy through DHH tweets, that admittedly only works because they have listeners. 1) Tweet negative/positive questions about x. 2) Tweet negative/positive observations about x. 3) Tweet negative/positive observation backed by data about x. 4) Tweet article about how positive/negative x is on blog. 5) Take action about positive/negative x. Usually over the sp…

I wish I could brand that as a fancy marketing scheme, but I think the answer is much simpler. It's simply transparent discovery and thinking. If it happens to work as advertising, that's a positive side-effect, but the main dish is coming to good conclusions. I certainly grew more confident in the decision to dump OpenID after talking with lots and lots of people on Twitter about it. You get to test your ideas, see…

It's authenticity is what makes it so effective. You share your thoughts in process, and people accompany you on your intellectual journey -- and their feedback helps to shape the conclusion. So it functions as great brand marketing for 37signals: you're the kind of company who takes what people say seriously.

Re: 37Signals to retire OpenID for logins on May 1

#24
post #10

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

"one of the worst executed visions of all times" What could have been done better? I spent a couple of years advocating for OpenID adoption, because I believed that the alternative (one or two companies controlling login for the entire Web, ala Microsoft Passport or Facebook Connect) would be a massive blow to the decentralised nature of the internet. I believed that OpenID's usability issues could be resolved if eno…

"one of the worst executed visions of all times" What could have been done better?

I'll tell you what it should look like (the fact that it's impossible is not the point): whenever I land on a site that asks me to login, I get a menu of all my possible accounts, I pick one, and I'm in. End of the story.

Kind of like Dropbox being simple and intuitive when everyone else was building overly complex stuff.

Re: 37Signals to retire OpenID for logins on May 1

#25
post #8

I don't understand. They use single text box of OpenID login. They have it separated from login page in another page. How do they want it to be successful and where is their ultimate usability mastery? There is no way OpenID can be improved when there is no interest in solving global internet issues. Neither Facebook for implementing the own mechanism nor 37signals would get medal of honor for uniting the internet.

The key problem didn't come from people NOT using OpenID, but from the people who did. Supporting OpenID is a nightmare. You have different relaying services that go up and down (OpenID's answer is: "use more than one" - ha!), various levels of incompatibility, and a generally user hostile experience. If OpenID usage had been in any serious numbers, our support department would have revolted. If you're trying to buil…

For any individual company, economics favor a proprietary single sign-on (37signals ID).

OpenID was not successful in changing that equation.

RPX, by contrast, appears to have done so successfully for a lot of people.

Re: 37Signals to retire OpenID for logins on May 1

#26
post #8

I don't understand. They use single text box of OpenID login. They have it separated from login page in another page. How do they want it to be successful and where is their ultimate usability mastery? There is no way OpenID can be improved when there is no interest in solving global internet issues. Neither Facebook for implementing the own mechanism nor 37signals would get medal of honor for uniting the internet.

The key problem didn't come from people NOT using OpenID, but from the people who did. Supporting OpenID is a nightmare. You have different relaying services that go up and down (OpenID's answer is: "use more than one" - ha!), various levels of incompatibility, and a generally user hostile experience. If OpenID usage had been in any serious numbers, our support department would have revolted. If you're trying to buil…

The worst part the description of what OpenID is design for is too much promising. Those who retire OpenID never going to give another chance. Everybody will be waiting for new alternative but that's kind of everything from the beginning.

The story of OpenID (not)success sounds like the html compatibility issue. Overall, time pass by and it starts shaping up. But probably no lessons learned from it (yet).

And when the big players are giving up on it no way small startups will be able to maintain, improve and support OpenID features.

Re: 37Signals to retire OpenID for logins on May 1

#27

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

I was always worried it'd be trivially easy to phish OpenID... I never even signed up for one.

not really. Consider for example yahoo's implementation: when I get redirected to Y! for login, I have my personal login seal on the page that grants me that I am actually talking to yahoo and not some scam site.

Re: 37Signals to retire OpenID for logins on May 1

#28

"Login with Facebook, Login with Twitter" <- these are your new single sign on providers. I wonder if in the future they'll try to standardize these login providers and the information they share, we can call the new standard Open...something...ID...no...OpenLogin, there we go.

I actually like this model too ... you're never going to get everybody to use one provider for storing their identities, because nobody will go and create one unless they absolutely need to.

So, it makes sense to go where users are. What I think needs to be done is standardize an api for the sites like twitter, facebook, Google and who-knows-what-in-the-future to use in providing accessing to user information to developers ...

That way, when superdupersocialnetworking.com explodes and has 1 billion users, providing sign on access to its users for your app is as simple as changing one or two lines of code.

That would be really awesome

Re: 37Signals to retire OpenID for logins on May 1

#29
post #11

"Login with Facebook, Login with Twitter" <- these are your new single sign on providers. I wonder if in the future they'll try to standardize these login providers and the information they share, we can call the new standard Open...something...ID...no...OpenLogin, there we go.

I think providing Facebook/Twitter logins for other social media sites make a lot of sense. Want to login to post on Yelp? Done. Want to checkin at 4sq? Gotcha. But using those services to check into the applications running your business? Fuck no. I'm certainly not going to let anyone depend on their ability to get paying work done by whether Twitter is up or not. And I know of plenty of people who aren't interested…

Facebook has a registration tool, too, now: http://swombat.com/2011/1/24/facebook-registration-tool

This might be the good middle ground between facebook login and an entirely new login... a facebook-assisted signup procedure.

Re: 37Signals to retire OpenID for logins on May 1

#30
post #20

What exactly are OpenID usability issues? I personaly prefer to use OpenID where it is available, yet I don't use any login provider but a php script on my own website.

The problem is that the number of people hosting their own OpenID solutions is, and will be, rather insignificant.
Post reply on HN