Live data from Hacker News

We're turning off Clickpass March 15. How to keep your HN account.

news.ycombinator.com

31–40 of 68 posts

Re: We're turning off Clickpass March 15. How to keep your HN account.

#31
post #28

The fact that Clickpass even exists made me realize openID was DOA. I spent a day implementing openID for the users of my website, because I realized, hey, what a cool idea, a URL can represent a single user on the internet, and that user can authenticate against it universally. The sad truth was that I could not expect a single one of my users to even understand what the hell was going on, because for most test open…

Good feedback on OpenId. What do you think of BrowserId?

Re: We're turning off Clickpass March 15. How to keep your HN account.

#32
post #13

(no one can see it except you and us) Offtopic, but I used to think that too until a coworker I'd never met emailed me using that address, warning me that apparently the proxy had cached my view of my profile page and he was able to view it. Has this been fixed yet?

You mean nobody can see it except you, YC, and the man in the middle?

Your system is setup to ask your corporate proxy to fetch unencrypted pages for you. That proxy may be configured to make a physical printout on your boss's printer of every page you request and there's nothing YC can do about that beyond offering https://news.ycombinator.com/ for you to use. That, too, may not be sufficient if your company has its own trusted SSL cert installed which is used to proxy and intercept everything so that all your internet activity can be decrypted.

Re: We're turning off Clickpass March 15. How to keep your HN account.

#33
post #28

The fact that Clickpass even exists made me realize openID was DOA. I spent a day implementing openID for the users of my website, because I realized, hey, what a cool idea, a URL can represent a single user on the internet, and that user can authenticate against it universally. The sad truth was that I could not expect a single one of my users to even understand what the hell was going on, because for most test open…

I always thought that the problem with openID is they didn't use email addresses instead of URLs. e.g. use john@example.com and require a certain url template for the endpoint e.g. example.com/openid/john

That way I don't have to remember another identifier and we already trust at least part of our identity to our email provider. Not perhaps as open, but much more approachable as a user.

Re: We're turning off Clickpass March 15. How to keep your HN account.

#35
post #28

The fact that Clickpass even exists made me realize openID was DOA. I spent a day implementing openID for the users of my website, because I realized, hey, what a cool idea, a URL can represent a single user on the internet, and that user can authenticate against it universally. The sad truth was that I could not expect a single one of my users to even understand what the hell was going on, because for most test open…

I always thought that the problem with openID is they didn't use email addresses instead of URLs. e.g. use john@example.com and require a certain url template for the endpoint e.g. example.com/openid/john That way I don't have to remember another identifier and we already trust at least part of our identity to our email provider. Not perhaps as open, but much more approachable as a user.

Hate that idea. I don't want to have to share my email address, in fact that's a primary reason why I always use my open ID (which is unrelated) when possible. Providing email as a credential creates an implicit, if not explicit, invitation "Here, spam me." This is why I'm generally against using email as an identifier.

Other examples that all suck for this reason: Apple IDs. Windows Live ID. Jabber.

Re: We're turning off Clickpass March 15. How to keep your HN account.

#36
post #35

Earlier quoted context omitted.

I always thought that the problem with openID is they didn't use email addresses instead of URLs. e.g. use john@example.com and require a certain url template for the endpoint e.g. example.com/openid/john That way I don't have to remember another identifier and we already trust at least part of our identity to our email provider. Not perhaps as open, but much more approachable as a user.

Hate that idea. I don't want to have to share my email address, in fact that's a primary reason why I always use my open ID (which is unrelated) when possible. Providing email as a credential creates an implicit, if not explicit, invitation "Here, spam me." This is why I'm generally against using email as an identifier. Other examples that all suck for this reason: Apple IDs. Windows Live ID. Jabber.

This problem is tough to imagine with jabber where you control access through your roster.

That is. They would then have to ask you permission to spam you.

Re: We're turning off Clickpass March 15. How to keep your HN account.

#37
post #11

I just followed the steps, but I'm getting a "Bad login." message when I try to sign in using Chrome's incognito mode. How long before the new username/password combo works?

Make sure you use correct capitalization of your username. The login screen is case sensitive. (Which seems crazy to me)

It's working now, so I guess it was the capitalization, thanks.

Re: We're turning off Clickpass March 15. How to keep your HN account.

#39
post #35

Earlier quoted context omitted.

I always thought that the problem with openID is they didn't use email addresses instead of URLs. e.g. use john@example.com and require a certain url template for the endpoint e.g. example.com/openid/john That way I don't have to remember another identifier and we already trust at least part of our identity to our email provider. Not perhaps as open, but much more approachable as a user.

Hate that idea. I don't want to have to share my email address, in fact that's a primary reason why I always use my open ID (which is unrelated) when possible. Providing email as a credential creates an implicit, if not explicit, invitation "Here, spam me." This is why I'm generally against using email as an identifier. Other examples that all suck for this reason: Apple IDs. Windows Live ID. Jabber.

How do people operate in the 21st Century internet treating their email address as private? I've never been reserved about giving out my email address and I've never had a spam or harassment problem. Ever.

Re: We're turning off Clickpass March 15. How to keep your HN account.

#40
post #32
post #13

(no one can see it except you and us) Offtopic, but I used to think that too until a coworker I'd never met emailed me using that address, warning me that apparently the proxy had cached my view of my profile page and he was able to view it. Has this been fixed yet?

You mean nobody can see it except you, YC, and the man in the middle? Your system is setup to ask your corporate proxy to fetch unencrypted pages for you. That proxy may be configured to make a physical printout on your boss's printer of every page you request and there's nothing YC can do about that beyond offering https://news.ycombinator.com/ for you to use. That, too, may not be sufficient if your company has its…

https://news.ycombinator.com/ is available! https HN links come up in Google results (at least from memory).
Post reply on HN