Live data from Hacker News

37Signals to retire OpenID for logins on May 1

productblog.37signals.com

91–100 of 118 posts

Re: 37Signals to retire OpenID for logins on May 1

#91
post #5

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

That particular holy grail is a poisoned chalice and it's claimed plenty of victims, anyone remember Sxip? It's not a technical problem, it's power, control and ownership. Anyone in a position to allow a platform to get serious traction isn't going to give that control up and anyone that isn't can't make a system with enough traction. Then there's issues of trust, delegation and longevity. I'd love someone to do it w…

Anyone in a position to allow a platform to get serious traction isn't going to give that control up and anyone that isn't can't make a system with enough traction.

InfoCard is surprisingly non-evil, and I also think Firefox is ideally placed to work on this (oh look, here's the solution: http://www.azarask.in/blog/post/identity-in-the-browser-fire... ), but they don't seem to care enough.

Re: 37Signals to retire OpenID for logins on May 1

#92
post #39
post #15

Earlier quoted context omitted.

The department of commerce wants to create such an identity system. I'm not sure I like the idea, but it would be "single sign on". I think it is a safe bet that their intention is to eventually make it mandatory, and they have the "ownership", presumed trust, and longevity, not to mention the ability to pass laws "encouraging" adoption. There are probably better news reports out there, but this is what I found with…

That might make it a viable single-identity system. As long as you only want U.S. users.

If NSTIC works, it's likely that other countries will adopt it.

Re: 37Signals to retire OpenID for logins on May 1

#93
post #92
post #39

Earlier quoted context omitted.

That might make it a viable single-identity system. As long as you only want U.S. users.

If NSTIC works, it's likely that other countries will adopt it.

I can already see the early adopters: Russia, China, France, Germany...

Even if you do it so that the actual data stores are separate and you manage to keep the APIs the same, lots of countries will have huge issues with adopting U.S. policies.

Re: 37Signals to retire OpenID for logins on May 1

#94

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

I suspect single-sign-on won't take off until we have some browser support for it.

How about Verisign's Firefox extension: https://pip.verisignlabs.com/seatbelt.do

Re: 37Signals to retire OpenID for logins on May 1

#95
post #10

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

"one of the worst executed visions of all times" What could have been done better? I spent a couple of years advocating for OpenID adoption, because I believed that the alternative (one or two companies controlling login for the entire Web, ala Microsoft Passport or Facebook Connect) would be a massive blow to the decentralised nature of the internet. I believed that OpenID's usability issues could be resolved if eno…

> What could have been done better?

I'd have tested the UI on my mom.

Re: 37Signals to retire OpenID for logins on May 1

#96
post #88

Earlier quoted context omitted.

a. Open ID is a protocol not an api ... I'm talking about something more akin to the old way twitter used to verify twitter logins in their api b. Open ID deals mainly with authentication ... I'm talking about both authenticating and providing access to limited user information ... email, name, phone ... that sort of thing. I just think Open ID was over elaborate, I'm hoping something simpler could succeed where it h…

You think OpenID was over elaborate but want to provide the user's phone number?

You're missing the point. I'm advocating for a general direction ... I don't have specifics..

Its not crazy. Facebook just announced something along those lines today http://marketaire.com/2010/12/23/facebook-registration-tool/

Re: 37Signals to retire OpenID for logins on May 1

#97
post #69

I'm surprised that 37signal's thought process is so utterly flawed. Blaming a technology for implementation problems just doesn't make sense. Using this logic, we would have concluded in 1997 that since Geocities pages were ugly and slow, HTTP was a waste of time. StackOverflow demonstrates aptly that OpenID is a technology that can work really well. You just need to: - Funnel users to pervasive, competent providers…

Really? Because yesterday I went to Meta StackOverflow and was utterly confused why I was getting new openid requests. (It was because MetaSO is different that SO.) Then I went to SO and was still confused because I thought I used yahoo but actually used google. Then, after I logged in with yahoo, I tried to change from google to yahoo and ended up with both, and now I can't remove the google openid. Very confusing.

Instead of managing 1 SO and 1 MetaSO login, I'm managing a connection from SO to one of many providers and MetaSO to one of many providers. Best case, that's 3 pages (SO, MetaSO and Yahoo) to manage logins to 2 sites.

Re: 37Signals to retire OpenID for logins on May 1

#98
post #18
post #10

Earlier quoted context omitted.

"one of the worst executed visions of all times" What could have been done better? I spent a couple of years advocating for OpenID adoption, because I believed that the alternative (one or two companies controlling login for the entire Web, ala Microsoft Passport or Facebook Connect) would be a massive blow to the decentralised nature of the internet. I believed that OpenID's usability issues could be resolved if eno…

For most users I talk to, an email address (rather than a URL) is how they think of identifying themself in a cross-system way. Orienting the spec around that would have made a huge difference. Were there HCI experts a big part of the community that put together the vision and architecture? How diverse (tech background, language, age) was the original community? Both of those are areas that could have made a big diff…

> For most users I talk to, an email address (rather than a URL)

Hits nail on head. It's unbelievable how dumb geeks who try to design UX experiences can be (and I say this as one of them). The first day I saw OpenID I was amazed that anybody would try and use a URL as an identifier.

Why would anybody put something that no normal person understands front and center of their UX? This is like opening a shoe shop and putting a quiz about 2nd order differential equations on the front door. Guess what - nobody is going into your store!!!

It was already a huge challenge to get people to understand the concept of using a login from one site to login to another. But it was doomed from the start the minute someone said you should have "http:// in front of your username.

Re: 37Signals to retire OpenID for logins on May 1

#99
post #78
post #64

Earlier quoted context omitted.

I think Zed Shaw is on this for some time. http://autho.me/

Shouldn't his login page be HTTPS? Or does the cryptography make that redundant?

I actually don't have HTTPS on autho.me on purpose to make sure nobody uses it for anything serious. When I get serious about it it'll be SSL encased properly.

This also lets you dump the protocol and watch what I'm doing so that you can make sure the SRP is not sending your password and information.

And I need to get back to working on that.

Re: 37Signals to retire OpenID for logins on May 1

#100
post #90
post #66

Earlier quoted context omitted.

I believe that part of that design is what's so confusing to non-technical users. If somebody were to tell them that 'the box in your basement' could be used to verify access to their banking website, you'd completely lose them. Granted, its an implementation they'd likely never encounter, but the fact that its possible just contributes to the noise around OpenID.

If you were to tell people in 1985 that they would be able to see their credit card balance on an LCD of a mobile phone while jogging, you'd completely lose them too.

I would think that you would lose them on 'mobile phone' instead.
Post reply on HN