Live data from Hacker News

37Signals to retire OpenID for logins on May 1

productblog.37signals.com

71–80 of 118 posts

Re: 37Signals to retire OpenID for logins on May 1

#71
post #10

Earlier quoted context omitted.

"one of the worst executed visions of all times" What could have been done better? I spent a couple of years advocating for OpenID adoption, because I believed that the alternative (one or two companies controlling login for the entire Web, ala Microsoft Passport or Facebook Connect) would be a massive blow to the decentralised nature of the internet. I believed that OpenID's usability issues could be resolved if eno…

"one of the worst executed visions of all times" What could have been done better? I'll tell you what it should look like (the fact that it's impossible is not the point): whenever I land on a site that asks me to login, I get a menu of all my possible accounts, I pick one, and I'm in. End of the story. Kind of like Dropbox being simple and intuitive when everyone else was building overly complex stuff.

The potential problem with this solution, although I do like it, is that your accounts can be attacked by someone who has any one of your login/pw combinations. You must treat them all as equally valuable. I'm not sure people on the web are at that point yet.

With that said... isn't that really like OpenId?

Re: 37Signals to retire OpenID for logins on May 1

#72
post #20

What exactly are OpenID usability issues? I personaly prefer to use OpenID where it is available, yet I don't use any login provider but a php script on my own website.

I'm not sure myself. I've used claimid.com for years and have never had a problem -- love that it's saved me creating dozens of one-off accounts.

Re: 37Signals to retire OpenID for logins on May 1

#73

Earlier quoted context omitted.

not really. Consider for example yahoo's implementation: when I get redirected to Y! for login, I have my personal login seal on the page that grants me that I am actually talking to yahoo and not some scam site.

What about man in the middle?(Go to yahoo get your image and display it for you.) Heck even pass your credentials through to yahoo to verify that you gave me the correct credentials.

I believe that falls out of the definition of "trivially easy to phish"

Re: 37Signals to retire OpenID for logins on May 1

#74
post #50

Earlier quoted context omitted.

StackOverflow is a good example (IMHO) of OpenID login done right. It's so easy to sign up for a StackOverflow account, and I don't have to remember or write down yet another fucking password ! IMHO, one of the things they do correctly is that the user doesn't have to remember an OpenID url in most cases, just click on the logo for which of your likely ID providers (Google, Facebook, Yahoo, etc.) that you want to use…

StackOverflow is a good example (IMHO) of OpenID login done right. The problem is that StackOverflow is also about the only example of OpenID done right, or done at all... Yes, there are a few others. But at least in my internet usage I hardly ever run into one. I can't remember having used my OpenID for any site other than SO in the past couple years.

Other examples of user-friendly OpenID login pages:

* Tripit.com only supports Google, Google Apps, and Facebook, but it's very end-user friendly to use any of those three.

* Catch.com, like Tripit, supports Google and Facebook OpenID logins.

* mindmeister.com supports Google, Google Apps, or a generic OpenID login.

* springnote.com supports a number of openID providers including generic OpenID. This one is actually an even better example than StackOverflow of an end-user friendly OpenID login/signup page.

Those are just ones I pulled from my Google account settings page. I'm sure there are other good examples out there.

Re: 37Signals to retire OpenID for logins on May 1

#75
post #53

I think that I speak for all when I say "NOOOOOOOOOOOOOO!!!" (think skywalker) Maybe the execution was not crystal perfect, but I think all of us would have liked OpenID (or some other free and open standard) to succeed. Open world 0 : Corporate overlords 1

I wonder if it's reasoning like this that has kept OpenID alive when it should have died a long time ago. You want the Open world to win over the corporate overloads, build a technology that actually works. A lot of effort has been put into evangelizing OpenID because it's a technology that nobody would want on their own.

The problem was the underlying concept is not sound and no amount of layer on more features was ever going to solve it. What we need now is to get the browser makers involved in a secure authentication system and start it first inside of smartphones.

Re: 37Signals to retire OpenID for logins on May 1

#76
post #50

Earlier quoted context omitted.

StackOverflow is a good example (IMHO) of OpenID login done right. It's so easy to sign up for a StackOverflow account, and I don't have to remember or write down yet another fucking password ! IMHO, one of the things they do correctly is that the user doesn't have to remember an OpenID url in most cases, just click on the logo for which of your likely ID providers (Google, Facebook, Yahoo, etc.) that you want to use…

StackOverflow is a good example (IMHO) of OpenID login done right. The problem is that StackOverflow is also about the only example of OpenID done right, or done at all... Yes, there are a few others. But at least in my internet usage I hardly ever run into one. I can't remember having used my OpenID for any site other than SO in the past couple years.

It shows that it's possible. The question is then why others don't implement it well. Obviously it's not worth it to them, but I think that say more about those doing the poor implementations than it does about OpenID.

Re: 37Signals to retire OpenID for logins on May 1

#77
post #59
post #54

Earlier quoted context omitted.

Anything that starts with, users need to learn seems doomed to fail.

Not if it provides a significant-enough benefit. How many people had "passwords" as a daily part of their life before 1995 or so? Every technology is new at some point. My thesis is that keys are not that hard and technical people should actually try to push understanding of them into the non-techie realm. If they fail, they fail, but if they succeed, it would make all computing so much more secure. Edit: I should al…

Most people in my country of adult age. PIN (bank ID code) are effectively passwords.

Re: 37Signals to retire OpenID for logins on May 1

#78
post #64

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

I think Zed Shaw is on this for some time. http://autho.me/

Shouldn't his login page be HTTPS? Or does the cryptography make that redundant?

Re: 37Signals to retire OpenID for logins on May 1

#79
I use openid not to have a single signon to 37signals apps. I use to to have a single signon period. Not just 37signals but a ton of other apps use it as well (and I wish all of them did).

Every time I see a web app supporting openid Im glad that I don't have to invent yet another user/password combo. again.

As to failing openid providers I have a good suggestion - use OpenId delegation to have a single openid that you can reroute to any openid provider you want. all it takes is a domain name and a very small file hosted on S3 (for example). Then you can switch providers at will.

Re: 37Signals to retire OpenID for logins on May 1

#80

Now if we could just kill off this facebook/twitter/nextbigthing login nonsense and use email like proper gentlemen things will be just peachy.

Until you change ISPs and your ISP provided email address goes away. Sure you could say use gmail or yahoo mail, and that is obviously just fine until they become "evil" or go out of business. Or heck you get your own domain and want to migrate over to using it for email. I have had a number of email addresses over the years and most of the old ones I have lost access to, how does that work again?

Exactly as well as OpenID, only it's a much better understood problem and avoids a ton of confusion?
Post reply on HN