Live data from Hacker News

37Signals to retire OpenID for logins on May 1

productblog.37signals.com

31–40 of 118 posts

Re: 37Signals to retire OpenID for logins on May 1

#31
post #10

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

"one of the worst executed visions of all times" What could have been done better? I spent a couple of years advocating for OpenID adoption, because I believed that the alternative (one or two companies controlling login for the entire Web, ala Microsoft Passport or Facebook Connect) would be a massive blow to the decentralised nature of the internet. I believed that OpenID's usability issues could be resolved if eno…

The real answer is that for the web to continue as it is, no such system must exist. If you require a single authentication, the web stops being a loosely couple system and becomes dependent on a single entity.

Re: 37Signals to retire OpenID for logins on May 1

#32
post #11

"Login with Facebook, Login with Twitter" <- these are your new single sign on providers. I wonder if in the future they'll try to standardize these login providers and the information they share, we can call the new standard Open...something...ID...no...OpenLogin, there we go.

I think providing Facebook/Twitter logins for other social media sites make a lot of sense. Want to login to post on Yelp? Done. Want to checkin at 4sq? Gotcha. But using those services to check into the applications running your business? Fuck no. I'm certainly not going to let anyone depend on their ability to get paying work done by whether Twitter is up or not. And I know of plenty of people who aren't interested…

If you can't trust Google, who can you trust?

Re: 37Signals to retire OpenID for logins on May 1

#33

I think I'm starting to understand 37signals advertising strategy through DHH tweets, that admittedly only works because they have listeners. 1) Tweet negative/positive questions about x. 2) Tweet negative/positive observations about x. 3) Tweet negative/positive observation backed by data about x. 4) Tweet article about how positive/negative x is on blog. 5) Take action about positive/negative x. Usually over the sp…

"and I don't know if its intentional"

Surely you jest :) If there's one thing 37signals do extremely well it's getting people to talk/write about them.

Re: 37Signals to retire OpenID for logins on May 1

#34
post #10

Earlier quoted context omitted.

"one of the worst executed visions of all times" What could have been done better? I spent a couple of years advocating for OpenID adoption, because I believed that the alternative (one or two companies controlling login for the entire Web, ala Microsoft Passport or Facebook Connect) would be a massive blow to the decentralised nature of the internet. I believed that OpenID's usability issues could be resolved if eno…

The real answer is that for the web to continue as it is, no such system must exist. If you require a single authentication, the web stops being a loosely couple system and becomes dependent on a single entity.

But the value of OpenID is that it isn't a single system. Anybody can be an OpenID provider, including me with the box sitting in my basement.

Re: 37Signals to retire OpenID for logins on May 1

#35
post #15
post #5

Earlier quoted context omitted.

That particular holy grail is a poisoned chalice and it's claimed plenty of victims, anyone remember Sxip? It's not a technical problem, it's power, control and ownership. Anyone in a position to allow a platform to get serious traction isn't going to give that control up and anyone that isn't can't make a system with enough traction. Then there's issues of trust, delegation and longevity. I'd love someone to do it w…

The department of commerce wants to create such an identity system. I'm not sure I like the idea, but it would be "single sign on". I think it is a safe bet that their intention is to eventually make it mandatory, and they have the "ownership", presumed trust, and longevity, not to mention the ability to pass laws "encouraging" adoption. There are probably better news reports out there, but this is what I found with…

Yet another (scary) example of the U.S. trying to act more like China (with regards to the internet): http://www.futuregov.asia/articles/2010/oct/22/chinas-real-n...

The previous example being the DHS censoring web sites such as The Pirate Bay and Wikileaks.

Re: 37Signals to retire OpenID for logins on May 1

#36
post #14

I think I'm starting to understand 37signals advertising strategy through DHH tweets, that admittedly only works because they have listeners. 1) Tweet negative/positive questions about x. 2) Tweet negative/positive observations about x. 3) Tweet negative/positive observation backed by data about x. 4) Tweet article about how positive/negative x is on blog. 5) Take action about positive/negative x. Usually over the sp…

I wish I could brand that as a fancy marketing scheme, but I think the answer is much simpler. It's simply transparent discovery and thinking. If it happens to work as advertising, that's a positive side-effect, but the main dish is coming to good conclusions. I certainly grew more confident in the decision to dump OpenID after talking with lots and lots of people on Twitter about it. You get to test your ideas, see…

Yea thats definitely it, just something I've noticed over time. Its a great strategy for getting people on your side, I think I see gruber doing the same thing from time to time, with less transparency though.

Re: 37Signals to retire OpenID for logins on May 1

#38
It's a shame that CAS for multitenant apps never really took off. We have an integrated CAS and OpenID server to handle single-sign on for all our apps, and losing OpenID will mean an additional username/password for our people to remember for Highrise. We are probably going to write our own CRM at this point.

Re: 37Signals to retire OpenID for logins on May 1

#39
post #15
post #5

Earlier quoted context omitted.

That particular holy grail is a poisoned chalice and it's claimed plenty of victims, anyone remember Sxip? It's not a technical problem, it's power, control and ownership. Anyone in a position to allow a platform to get serious traction isn't going to give that control up and anyone that isn't can't make a system with enough traction. Then there's issues of trust, delegation and longevity. I'd love someone to do it w…

The department of commerce wants to create such an identity system. I'm not sure I like the idea, but it would be "single sign on". I think it is a safe bet that their intention is to eventually make it mandatory, and they have the "ownership", presumed trust, and longevity, not to mention the ability to pass laws "encouraging" adoption. There are probably better news reports out there, but this is what I found with…

That might make it a viable single-identity system. As long as you only want U.S. users.

Re: 37Signals to retire OpenID for logins on May 1

#40
post #10

Earlier quoted context omitted.

"one of the worst executed visions of all times" What could have been done better? I spent a couple of years advocating for OpenID adoption, because I believed that the alternative (one or two companies controlling login for the entire Web, ala Microsoft Passport or Facebook Connect) would be a massive blow to the decentralised nature of the internet. I believed that OpenID's usability issues could be resolved if eno…

"one of the worst executed visions of all times" What could have been done better? I'll tell you what it should look like (the fact that it's impossible is not the point): whenever I land on a site that asks me to login, I get a menu of all my possible accounts, I pick one, and I'm in. End of the story. Kind of like Dropbox being simple and intuitive when everyone else was building overly complex stuff.

Ok, it's impossible. Now tell me how you're going to do it anyway and laugh all the way to the bank.

The fact that you can conceive of it means that it likely isn't impossible, merely very difficult and possibly non-obvious. But that's how pretty much every real success story starts. You really may be on to something here.

Post reply on HN