Live data from Hacker News

37Signals to retire OpenID for logins on May 1

productblog.37signals.com

11–20 of 118 posts

Re: 37Signals to retire OpenID for logins on May 1

#11

"Login with Facebook, Login with Twitter" <- these are your new single sign on providers. I wonder if in the future they'll try to standardize these login providers and the information they share, we can call the new standard Open...something...ID...no...OpenLogin, there we go.

I think providing Facebook/Twitter logins for other social media sites make a lot of sense. Want to login to post on Yelp? Done. Want to checkin at 4sq? Gotcha.

But using those services to check into the applications running your business? Fuck no. I'm certainly not going to let anyone depend on their ability to get paying work done by whether Twitter is up or not. And I know of plenty of people who aren't interested in mixing their private-life Facebook with their work-life accounts.

Then of course there's Google. I'd be weary to let a large number of customers be owned by that Gorilla.

OpenID was promising because it was an open standard, not controlled by any one party. But unfortunately it had the usability of your average open source project (acceptable for hackers, terrible for anyone else).

Re: 37Signals to retire OpenID for logins on May 1

#12
I think I'm starting to understand 37signals advertising strategy through DHH tweets, that admittedly only works because they have listeners.

  1) Tweet negative/positive questions about x.
  2) Tweet negative/positive observations about x.
  3) Tweet negative/positive observation backed by data about x.
  4) Tweet article about how positive/negative x is on blog.
  5) Take action about positive/negative x.
Usually over the span of a couple days. It feels like you are watching DHH come to the realization that something is good/bad which helps you come to the same realization.

There is nothing wrong with it, and I don't know if its intentional but its super effective.

Re: 37Signals to retire OpenID for logins on May 1

#13
post #10

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

"one of the worst executed visions of all times" What could have been done better? I spent a couple of years advocating for OpenID adoption, because I believed that the alternative (one or two companies controlling login for the entire Web, ala Microsoft Passport or Facebook Connect) would be a massive blow to the decentralised nature of the internet. I believed that OpenID's usability issues could be resolved if eno…

Wasn't web finger supposed to fix some of the usability issues with openID? I don't think I ever saw that added, but I could be wrong.

Re: 37Signals to retire OpenID for logins on May 1

#14

I think I'm starting to understand 37signals advertising strategy through DHH tweets, that admittedly only works because they have listeners. 1) Tweet negative/positive questions about x. 2) Tweet negative/positive observations about x. 3) Tweet negative/positive observation backed by data about x. 4) Tweet article about how positive/negative x is on blog. 5) Take action about positive/negative x. Usually over the sp…

I wish I could brand that as a fancy marketing scheme, but I think the answer is much simpler. It's simply transparent discovery and thinking. If it happens to work as advertising, that's a positive side-effect, but the main dish is coming to good conclusions.

I certainly grew more confident in the decision to dump OpenID after talking with lots and lots of people on Twitter about it. You get to test your ideas, see what the feedback is, tweak, and retry. All while making the decision process public.

Re: 37Signals to retire OpenID for logins on May 1

#15
post #5

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

That particular holy grail is a poisoned chalice and it's claimed plenty of victims, anyone remember Sxip? It's not a technical problem, it's power, control and ownership. Anyone in a position to allow a platform to get serious traction isn't going to give that control up and anyone that isn't can't make a system with enough traction. Then there's issues of trust, delegation and longevity. I'd love someone to do it w…

The department of commerce wants to create such an identity system. I'm not sure I like the idea, but it would be "single sign on". I think it is a safe bet that their intention is to eventually make it mandatory, and they have the "ownership", presumed trust, and longevity, not to mention the ability to pass laws "encouraging" adoption.

There are probably better news reports out there, but this is what I found with a quick google: http://www.commerce.gov/news/press-releases/2011/01/07/us-co...

Re: 37Signals to retire OpenID for logins on May 1

#16

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

I was always worried it'd be trivially easy to phish OpenID... I never even signed up for one.

Re: 37Signals to retire OpenID for logins on May 1

#17
post #10

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

"one of the worst executed visions of all times" What could have been done better? I spent a couple of years advocating for OpenID adoption, because I believed that the alternative (one or two companies controlling login for the entire Web, ala Microsoft Passport or Facebook Connect) would be a massive blow to the decentralised nature of the internet. I believed that OpenID's usability issues could be resolved if eno…

Simon, I know the work you and others have done and continue to do in the OpenID world, and it's commendable work.

The problem with OpenID and other Open Web work IMO is the sheer number of half-baked specs brought forward. Much more than any other standards group. I don't know why. “The nicest thing about standards is that there are so many of them to choose from,” like Tannenbaum said. Perhaps there is a general lack of attention span, a ohh-shiny problem, a not-invented-here problem that is particularly rampant in this community.

Re: 37Signals to retire OpenID for logins on May 1

#18
post #10

Totally understandable, one of the worst executed visions of all times. I think there's a really huge opportunity in this space, and the first who'll be able to figure out the perfect (and, most importantly, simplest) way to offer a single-sign-on, integrating privacy and security features, will be hugely thanked.

"one of the worst executed visions of all times" What could have been done better? I spent a couple of years advocating for OpenID adoption, because I believed that the alternative (one or two companies controlling login for the entire Web, ala Microsoft Passport or Facebook Connect) would be a massive blow to the decentralised nature of the internet. I believed that OpenID's usability issues could be resolved if eno…

For most users I talk to, an email address (rather than a URL) is how they think of identifying themself in a cross-system way. Orienting the spec around that would have made a huge difference.

Were there HCI experts a big part of the community that put together the vision and architecture? How diverse (tech background, language, age) was the original community? Both of those are areas that could have made a big difference.

It remains a great vision, so hopefully people will continue to work on it.

Post reply on HN