Earlier quoted context omitted.
I was always worried it'd be trivially easy to phish OpenID... I never even signed up for one.
not really. Consider for example yahoo's implementation: when I get redirected to Y! for login, I have my personal login seal on the page that grants me that I am actually talking to yahoo and not some scam site.
37Signals to retire OpenID for logins on May 1
61–70 of 118 posts
Re: 37Signals to retire OpenID for logins on May 1
#62Earlier quoted context omitted.
"one of the worst executed visions of all times" What could have been done better? I spent a couple of years advocating for OpenID adoption, because I believed that the alternative (one or two companies controlling login for the entire Web, ala Microsoft Passport or Facebook Connect) would be a massive blow to the decentralised nature of the internet. I believed that OpenID's usability issues could be resolved if eno…
For most users I talk to, an email address (rather than a URL) is how they think of identifying themself in a cross-system way. Orienting the spec around that would have made a huge difference. Were there HCI experts a big part of the community that put together the vision and architecture? How diverse (tech background, language, age) was the original community? Both of those are areas that could have made a big diff…
http://www.readwriteweb.com/archives/google_enables_webfinge...
It uses your email address, and seems to offer a good way to get access to an OpenID-like sign in (maybe this is using OpenID or OAuth under the covers?)
Re: 37Signals to retire OpenID for logins on May 1
#63Re: 37Signals to retire OpenID for logins on May 1
#64Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.
Re: 37Signals to retire OpenID for logins on May 1
#65This is apparently their reaction to this support ticket - http://answers.37signals.com/basecamp/4899-openid-having-iss... - in which they say "Something changed with the MyOpenID provider recently and we're tracking the issue as we look for a fix."
Re: 37Signals to retire OpenID for logins on May 1
#66Earlier quoted context omitted.
The real answer is that for the web to continue as it is, no such system must exist. If you require a single authentication, the web stops being a loosely couple system and becomes dependent on a single entity.
But the value of OpenID is that it isn't a single system. Anybody can be an OpenID provider, including me with the box sitting in my basement.
Re: 37Signals to retire OpenID for logins on May 1
#67Sounds great, Yahoo/Google/Facebook take your pick with a button or if you're hacker/paranoid enough to have your own infrastructure the slightly complexity of using a URL?
Main complaint seems to be it's URL and not user@host? Couldn't one just add support for user@host into the next iteration of the standard? Maybe using something like DNS SRV records that seem to work well enough for XMPP?
Decentralisation is important and more cultural than technical. We need to keep working for it and it's not a short term goal--if it happens over decades so be it, but we shouldn't give up ground where we don't have to, especially with things trending against at the moment.
Re: 37Signals to retire OpenID for logins on May 1
#68Earlier quoted context omitted.
It doesn't matter when yahoo, google, aol and more offer openid, it's just a click on a button, what could be easier than that? I agree that entering a whole URL is horrible though but that's not how I use openid, I just click on the google button and that's it, just like facebook or twitter connect.
Many of these providers have bugs and quirks. It is nontrivial to support them all.
Re: 37Signals to retire OpenID for logins on May 1
#69StackOverflow demonstrates aptly that OpenID is a technology that can work really well. You just need to: - Funnel users to pervasive, competent providers like Google, Facebook, Verisign - Make the integration experience as smooth as possible.
If your implementation of OpenID requires users to enter URLs and encourages users to use random providers, than yes, it sucks.
Re: 37Signals to retire OpenID for logins on May 1
#70Now if we could just kill off this facebook/twitter/nextbigthing login nonsense and use email like proper gentlemen things will be just peachy.