"Login with Facebook, Login with Twitter" <- these are your new single sign on providers. I wonder if in the future they'll try to standardize these login providers and the information they share, we can call the new standard Open...something...ID...no...OpenLogin, there we go.
Google Account auth is nice too. It actually uses OpenID in the background, but the user doesn't have to understand what OpenID is. As it should be.
So the worlds biggest advertiser knows that it's the same you on stackoverflow, linkedin and 'very small penis porn com"
The only ultimate, secure, technically valid solution to single sign-on is 2-way SSL. Unfortunately, for this to work, several things need to happen: 1) Users need to learn what a private key is. 2) Browsers need to provide flexible, intuitive, easy-to-use user key support that's not tucked away in 3 levels of dialogs/tabs. 3) We need good key-management tools so I can log on to sites from internet cafes, etc (perhap…
Uses the site's domain as a salt though which isn't exactly secure if whoever hacks the database decides to ignore the low-hanging unencrypted fruit and crack your password. You can configure the encryption settings a bit though and add your own pre-salt kinda deal.
The only ultimate, secure, technically valid solution to single sign-on is 2-way SSL. Unfortunately, for this to work, several things need to happen: 1) Users need to learn what a private key is. 2) Browsers need to provide flexible, intuitive, easy-to-use user key support that's not tucked away in 3 levels of dialogs/tabs. 3) We need good key-management tools so I can log on to sites from internet cafes, etc (perhap…
Anything that starts with, users need to learn seems doomed to fail.
"one of the worst executed visions of all times" What could have been done better? I spent a couple of years advocating for OpenID adoption, because I believed that the alternative (one or two companies controlling login for the entire Web, ala Microsoft Passport or Facebook Connect) would be a massive blow to the decentralised nature of the internet. I believed that OpenID's usability issues could be resolved if eno…
"one of the worst executed visions of all times" What could have been done better? I'll tell you what it should look like (the fact that it's impossible is not the point): whenever I land on a site that asks me to login, I get a menu of all my possible accounts, I pick one, and I'm in. End of the story. Kind of like Dropbox being simple and intuitive when everyone else was building overly complex stuff.
Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.
I suspect single-sign-on won't take off until we have some browser support for it.
That particular holy grail is a poisoned chalice and it's claimed plenty of victims, anyone remember Sxip? It's not a technical problem, it's power, control and ownership. Anyone in a position to allow a platform to get serious traction isn't going to give that control up and anyone that isn't can't make a system with enough traction. Then there's issues of trust, delegation and longevity. I'd love someone to do it w…
The department of commerce wants to create such an identity system. I'm not sure I like the idea, but it would be "single sign on". I think it is a safe bet that their intention is to eventually make it mandatory, and they have the "ownership", presumed trust, and longevity, not to mention the ability to pass laws "encouraging" adoption. There are probably better news reports out there, but this is what I found with…
Putting it in the hands of the government actually fails the trust requirement. Trust is not a binary "this entity is trustworthy", trust is a set of relationships between two entities, and not everyone will trust the US Government, nor will everybody be trusted by the US Government. Even in a perfect world with a perfect US Government, that is the correct answer; not everyone is under US jurisdiction, after all, so we don't even need to get into the political issues. If made mandatory (and the only option), this is a critical failure on the trust front. It can't work, you can't tie your login system to only the US login system, and if you have to have other login systems, US citizens will be able to use those too.
The only ultimate, secure, technically valid solution to single sign-on is 2-way SSL. Unfortunately, for this to work, several things need to happen: 1) Users need to learn what a private key is. 2) Browsers need to provide flexible, intuitive, easy-to-use user key support that's not tucked away in 3 levels of dialogs/tabs. 3) We need good key-management tools so I can log on to sites from internet cafes, etc (perhap…
Anything that starts with, users need to learn seems doomed to fail.
It is doomed to fail. It is also the only actual solution. Therefore, there is no possible successful solution. Sometimes things work out that way.
The only ultimate, secure, technically valid solution to single sign-on is 2-way SSL. Unfortunately, for this to work, several things need to happen: 1) Users need to learn what a private key is. 2) Browsers need to provide flexible, intuitive, easy-to-use user key support that's not tucked away in 3 levels of dialogs/tabs. 3) We need good key-management tools so I can log on to sites from internet cafes, etc (perhap…
Anything that starts with, users need to learn seems doomed to fail.
Not if it provides a significant-enough benefit. How many people had "passwords" as a daily part of their life before 1995 or so?
Every technology is new at some point. My thesis is that keys are not that hard and technical people should actually try to push understanding of them into the non-techie realm. If they fail, they fail, but if they succeed, it would make all computing so much more secure.
Edit: I should also point out that it's not really any more complicated than OpenID, and people seemed willing to give that a fair shake, at least to the extent that a lot of sites implemented it.
The problem is that the number of people hosting their own OpenID solutions is, and will be, rather insignificant.
It doesn't matter when yahoo, google, aol and more offer openid, it's just a click on a button, what could be easier than that? I agree that entering a whole URL is horrible though but that's not how I use openid, I just click on the google button and that's it, just like facebook or twitter connect.
Many of these providers have bugs and quirks. It is nontrivial to support them all.