Live data from Hacker News

Yet Another Sign Up (Why Isn't Open ID More Popular By Now?)

blog.amir.rachum.com

31–39 of 39 posts

Re: Yet Another Sign Up (Why Isn't Open ID More Popular By Now?)

#31

And why wouldn't I prefer to have a set of fully independent, unlinked accounts at different sites? If I understand correctly, using OpenID means that Site A can confirm that User X is the same as User X on Site B, using OpenID? I can see where that's a win for sites A & B. I can also see many instances where that is not a win for me.

Exactly. This reminds me of facebook and every site with "login with facebook" implemented. For example, I choose not to log into hulu with facebook because I'm sure its great for facebook to know what bad shows I watch to serve me better ads. But i don't need all of my friends and family seeing that information on their news feed. I believe Spotify forces this on their users and as a result i get the joy of seeing every song my friends listen to on Spotify.

Re: Yet Another Sign Up (Why Isn't Open ID More Popular By Now?)

#32

Earlier quoted context omitted.

How is this different than correlating user names or email addresses? Especially given that most of the OpenIds out in the wild are specifically keyed off of email addresses anyway.

Who says I use the same user names or email addresses (particularly when making a concerted effort to divide my identities).

... Then you would have OpenIDs for those email accounts. Or you could just as trivially make throw away subdomains to use as OpenIDs with free providers. (There are several DNS providers with hundreds of free second-level domains that you can make as many subdomains as you like for free in 45 seconds.

Between this and your comments on G+, you seem really interested in villianizing your service providers when there are obvious ways to avoid their naive account associations [1], as you even take advantage of.

[1] I say naive because I would be willing to be a large amount of money that I could track you between accounts unless you're taking some insane precautions against it, even without an email address or OpenID url.

Re: Yet Another Sign Up (Why Isn't Open ID More Popular By Now?)

#33
post #13

The reason you dont see it mainstream is because for someone like my mom its too difficult to understand. She does however understand "Login with Facebook/Google/Twitter" because it is simple, one click, approve permissions and done. Anything more is just a hassle for them to remember and they will fallback to email/password instead.

And when you have more than one option, your users will start to make more than one account for your site.

Nothing is stopping them from doing that with Username/Password or OpenID. In fact I would argue that it probably happens more with the username method because users forget they have an account. With Google/Facebook/Twitter signin they click and that service remembers everything for them and sends it to the app for authentication.

Re: Yet Another Sign Up (Why Isn't Open ID More Popular By Now?)

#34

Earlier quoted context omitted.

Who says I use the same user names or email addresses (particularly when making a concerted effort to divide my identities).

... Then you would have OpenIDs for those email accounts. Or you could just as trivially make throw away subdomains to use as OpenIDs with free providers. (There are several DNS providers with hundreds of free second-level domains that you can make as many subdomains as you like for free in 45 seconds. Between this and your comments on G+, you seem really interested in villianizing your service providers when there a…

I suspect you could, or an entity with sufficient motivation could.

For casual purposes, which encompasses much of my present threat model, the measures I'm taking should be reasonably sufficient.

The point I and others are making is that:

0. There's a growing default assumption that individuals have no privacy, that privacy is dead, and that we should all just roll over and forget about it.

1. Even if you trust your service provider today, you may not trust them tomorrow.

2. Even if you trust your service provider, you may not trust those who have access to your data through your service provider. Intentionally or otherwise.

I'm well aware that roughly 32 bits of leaked information should be sufficient to identify me, if not precisely, then with reasonable accuracy. This doesn't mean I'm going to hand over my SSN and DOB to anyone who asks.

It may also be the case that I'm deliberately trying to create various associated identities.

That said: if you're interested in trying to link this identity to others, you can GMail me any of your prospective linkings.

Re: Yet Another Sign Up (Why Isn't Open ID More Popular By Now?)

#35
There's no way to make everyone happy, but pretty much all the options suck. Setting up yet another account sucks. OpenID sucks because nobody intuitively understands it. My login is a URL?? WTF? Facebook/Google/whatever login sucks because some people don't have it and some people who have it don't trust it.

I don't have any answers.

Re: Yet Another Sign Up (Why Isn't Open ID More Popular By Now?)

#36
"It boggles my mind that this is apparently a big question for techies and, to me, is a perfect example of the Silicon Valley mindset that doesn't understand how to build products that real people want to use.

"The short answer is that OpenID is the worst possible 'solution' I have ever seen in my entire life to a problem that most people don't really have. That's what's 'wrong' with it."

http://www.quora.com/OpenID/What-s-wrong-with-OpenID/answer/...

The real question is why these guys didn't let you signup with Facebook.

Re: Yet Another Sign Up (Why Isn't Open ID More Popular By Now?)

#37
post #16

It's common knowledge now that OpenID has severe usability problems. As much as I wanted it to work, none of my apps' visitors (hell, back in 2006) could understand what it was or how to use it. BrowserID, however, has now fixed most of these issues, and it's very straightforward to use. To try it out, you can have a look at http://www.yourpane.com/

"To log in, just enter your email address below and click the link that we send you. To log in again, you can save the link and use it directly (you don't have to request a new one)." In what world is that more usable than "Click here to login with Google / Yahoo"?

BrowserID is horribly complicated. Even to log into Mozilla's own Web Apps store. I had to remember my browser id, wait, enter it again and then enter a password. Why are there more steps to something so simple. It's for these reasons that no one wants to adopt these things.

Re: Yet Another Sign Up (Why Isn't Open ID More Popular By Now?)

#38

Earlier quoted context omitted.

I don't think they can do that, unfortunately. Verification is done when you create a BrowserID account, so it'll never happen again, no matter which site you go to next. You'll just get logged in.

Yeah, that totally sucks. We're working on it. Support for post-verification redirects should land in production in ~2 weeks, IIRC. There will be an announcement on the Mozilla Identity blog when that goes live. (Sorry to threadsit here!)

Also, in the step when you enter a password (to create a BrowserID), the second field is called "Reset password". What's up with that? Should it not be something like "Password (confirm)"?

Re: Yet Another Sign Up (Why Isn't Open ID More Popular By Now?)

#39

Earlier quoted context omitted.

Yeah, that totally sucks. We're working on it. Support for post-verification redirects should land in production in ~2 weeks, IIRC. There will be an announcement on the Mozilla Identity blog when that goes live. (Sorry to threadsit here!)

Also, in the step when you enter a password (to create a BrowserID), the second field is called "Reset password". What's up with that? Should it not be something like "Password (confirm)"?

Our translation files were messed up. The fix should enter production on Monday: https://github.com/mozilla/browserid/issues/1905 Thanks!
Post reply on HN