Live data from Hacker News

37Signals to retire OpenID for logins on May 1

productblog.37signals.com

61–70 of 118 posts

Re: 37Signals to retire OpenID for logins on May 1

#61

Earlier quoted context omitted.

I was always worried it'd be trivially easy to phish OpenID... I never even signed up for one.

not really. Consider for example yahoo's implementation: when I get redirected to Y! for login, I have my personal login seal on the page that grants me that I am actually talking to yahoo and not some scam site.

What about man in the middle?(Go to yahoo get your image and display it for you.) Heck even pass your credentials through to yahoo to verify that you gave me the correct credentials.

Re: 37Signals to retire OpenID for logins on May 1

#62
post #18
post #10

Earlier quoted context omitted.

"one of the worst executed visions of all times" What could have been done better? I spent a couple of years advocating for OpenID adoption, because I believed that the alternative (one or two companies controlling login for the entire Web, ala Microsoft Passport or Facebook Connect) would be a massive blow to the decentralised nature of the internet. I believed that OpenID's usability issues could be resolved if eno…

For most users I talk to, an email address (rather than a URL) is how they think of identifying themself in a cross-system way. Orienting the spec around that would have made a huge difference. Were there HCI experts a big part of the community that put together the vision and architecture? How diverse (tech background, language, age) was the original community? Both of those are areas that could have made a big diff…

Why haven't more people migrated to WebFinger for identity?

http://www.readwriteweb.com/archives/google_enables_webfinge...

It uses your email address, and seems to offer a good way to get access to an OpenID-like sign in (maybe this is using OpenID or OAuth under the covers?)

Re: 37Signals to retire OpenID for logins on May 1

#64

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

I think Zed Shaw is on this for some time.

http://autho.me/

Re: 37Signals to retire OpenID for logins on May 1

#65
post #63

This is apparently their reaction to this support ticket - http://answers.37signals.com/basecamp/4899-openid-having-iss... - in which they say "Something changed with the MyOpenID provider recently and we're tracking the issue as we look for a fix."

That was just the latest in a long string of issues with OpenID. Hardly the sole reason.

Re: 37Signals to retire OpenID for logins on May 1

#66

Earlier quoted context omitted.

The real answer is that for the web to continue as it is, no such system must exist. If you require a single authentication, the web stops being a loosely couple system and becomes dependent on a single entity.

But the value of OpenID is that it isn't a single system. Anybody can be an OpenID provider, including me with the box sitting in my basement.

I believe that part of that design is what's so confusing to non-technical users. If somebody were to tell them that 'the box in your basement' could be used to verify access to their banking website, you'd completely lose them. Granted, its an implementation they'd likely never encounter, but the fact that its possible just contributes to the noise around OpenID.

Re: 37Signals to retire OpenID for logins on May 1

#67
I just skimmed the comments thread and have a vague idea of what OpenID is but haven't gotten around to it yet.

Sounds great, Yahoo/Google/Facebook take your pick with a button or if you're hacker/paranoid enough to have your own infrastructure the slightly complexity of using a URL?

Main complaint seems to be it's URL and not user@host? Couldn't one just add support for user@host into the next iteration of the standard? Maybe using something like DNS SRV records that seem to work well enough for XMPP?

Decentralisation is important and more cultural than technical. We need to keep working for it and it's not a short term goal--if it happens over decades so be it, but we shouldn't give up ground where we don't have to, especially with things trending against at the moment.

Re: 37Signals to retire OpenID for logins on May 1

#68
post #60

Earlier quoted context omitted.

It doesn't matter when yahoo, google, aol and more offer openid, it's just a click on a button, what could be easier than that? I agree that entering a whole URL is horrible though but that's not how I use openid, I just click on the google button and that's it, just like facebook or twitter connect.

Many of these providers have bugs and quirks. It is nontrivial to support them all.

Couldn't that be obviated by wrapping it much as jQuery makes browser support less painful?

Re: 37Signals to retire OpenID for logins on May 1

#69
I'm surprised that 37signal's thought process is so utterly flawed. Blaming a technology for implementation problems just doesn't make sense. Using this logic, we would have concluded in 1997 that since Geocities pages were ugly and slow, HTTP was a waste of time.

StackOverflow demonstrates aptly that OpenID is a technology that can work really well. You just need to: - Funnel users to pervasive, competent providers like Google, Facebook, Verisign - Make the integration experience as smooth as possible.

If your implementation of OpenID requires users to enter URLs and encourages users to use random providers, than yes, it sucks.

Re: 37Signals to retire OpenID for logins on May 1

#70

Now if we could just kill off this facebook/twitter/nextbigthing login nonsense and use email like proper gentlemen things will be just peachy.

Until you change ISPs and your ISP provided email address goes away. Sure you could say use gmail or yahoo mail, and that is obviously just fine until they become "evil" or go out of business. Or heck you get your own domain and want to migrate over to using it for email. I have had a number of email addresses over the years and most of the old ones I have lost access to, how does that work again?
Post reply on HN