Stack Overflow: Support for OpenID Ends on July 1, 2018
meta.stackexchange.com
meta.stackexchange.com
Slashdot removed support, as did shirt woot and deletionpedia. Freecode and gitorious are gone. After this, the only things I'll have left on openid will be pipy (which doesn't seem to work) and openstreetmaps.
I understand why and the technical debt involved, but this still makes me very sad. We're moving in the wrong direction. We're going away from open, federated, distributed standards and back to closed, wall-gardened, proprietary, massive identity providers.
I'm not. I just create an email and password for each site I use. A password manager means that's not a big deal.
EDIT: I meant to say I create an account based on email and password. I don't actually create a separate email address per site.
Incredibly helpful to track who leaked your email and to whom, better control spammers, etc. Just checked on Have I been Pwned, and I have 30 emails from my domain there [1]. Anecdotally, there's at least another 50-100 email addresses that I get spam regularly, so HIBP is a small subset of all the leaks.
Easy to implement. I use G Suite with Gmail[2], but it works with most other providers.
[1] https://haveibeenpwned.com/
[2] disclaimer: I work for Google, but not on G Suite team, and I pay for the service on my own.
You could also use the hash of the domain name with a secret salt value. Then if you somehow lost your login info, you could still figure out what your recovery address was if you still knew the salt.
Only spam I get is on leaked addresses.
The thing is, too often do people lament the loss of federated/open systems and quickly jump on a blame train spanning the users who "are making the wrong choices by not using the 'obviously better, open systems' and the corporations who 'push their evil walled gardens onto users'".
But few people actually think about what is actually causing these shifts. Users don't usually care about open vs. closed, and seldom care about ideology. They want their shit to work without hassle, to look good, to achieve what they want.
I see so many people blaming users and companies for moving away from IRC, onto systems like Discord and Slack. Why you gotta blame the consumers when they are merely switching to obviously better alternatives? IRC is not a suitable replacement for Discord today, and systems like XMPP and OpenID are massive fucking messes. They don't get used because they're too hard to use. Usability is a feature.
Honestly, I think proprietary solutions win so often because they value pragmatism by nature, whereas open solutions tend to value ideology. Sometimes, you have visionaries at the helm who do value pragmatism and you end up with the best of both worlds. Torvalds is an excellent example: He produces pragmatic, open software and his way, although not "ideologically pure", has done more to promote free software than Stallman ever has.
Not to point fingers; I definitely know there are Stallman-wannabees floating around the site who are in it purely to feel superior to others, and be able to wag their finger and make fun of those using "crass, proprietary software". They don't try to understand why consumers use the proprietary solutions (they can't try, because they refuse to use them). And at the end of the day, the needle hasn't moved.
Anyway, all that to say, we're moving in the wrong direction because too many people cling onto the systems that have obviously lost (openid and IRC) without considering why consumers use oauth2 and slack. It's armchair lamenting.
Open, federated systems are possibly, arguably, better, both in terms of ideology (or alternative, more specific terms like "privacy") and (maybe) technology. But, as you say, users don't care about open/closed, they don't care about ideology, they don't even care about technology. They care about ease of use and appearance.
Open, federated systems will never be as simple as proprietary systems. Further, they'll never attract the money necessary to get even as close as possible in terms of ease of use and appearance. Non-proprietary systems will usually lose out of the gate, not because they're dragging a 100lb anvil of ideology but because the alternatives have a magic tailwind of simpler requirements and more resources. (And that's as pragmatic as you can get, right?)
Note: I'm not a Stallman-wannabe, I'm not wagging fingers (at the moment, on this issue), and I use proprietary solutions all the time. But I also know what I'm trading off.
Why can't other services work like email and Matrix and have success? A lot of it just seems like success of marketing to me.
I think part of it is just the ease of setting up services. You can install new programs on your desktop win/macos and they'll update themselves and all that, but servers are not so easy. There are things that are coming out that make servers more pluggable/lego brick build-able like Sandstorm, and maybe one of those will really take off and make hosted apps something more individuals would be willing to pay for.
E-mail also has its huge share of problems. Setting up your own e-mail server is also super unreliable because of over-aggressive spam filters, as I wrote about here:
http://penguindreams.org/blog/how-google-and-microsoft-made-...
2. You could argue that many of those others are taking over part of the email use-case, including file transfers.
3. I dunno.
This is also Why complex Piracy/CD Ripping lost steam with services like Spotify/Netflix in countries with big piracy rings. Good user experience trumps ideology.
I do agree that we are going in the wrong direction, and that we should be building open, federated, distributed protocols/standards. However, OpenID is not a good example of such given its dependencies.
What is meant by "dependencies" here?
I created an account on SO using an OpenID provider in 2009. In 2014, the provider disappeared and with it, the ability to log into the account. I was never warned about this and have never been able to access that account again.
Since then I only access SO via web searches (didn't create another account). I wonder how many people are in the same situation.
The original OpenID, where my identity was a URL that wasn't a website, and wasn't my email address, was never easy to explain.
Which is a lot of work to do nothing at all . . . I just really like the idea of OpenID.
Consider doing this if you only depend on a single Google / FB / other account.
it's fairly painless
> The reality is OpenID support has created a ton of complexity in our codebase
I don't doubt this is true but I do find it surprising. I would be interested to see a breakdown of this from a technical perspective. I'm sure it adds complexity, but in the context of the overall complexity of SO I would have expected it to be relatively overshadowed.
> Users have spoken with their actions. You prefer Google, Facebook and Stack Exchange (aka email/PW) based account auth.
No, they haven't. OpenId use in SO has declined for two reasons: (1) providers shutting down and (2) Stack Overflow UI changes to hide the option from users in the login form (making my logins require extra clicks).
> around one-tenth of a percent are actively using OpenID (defined as having visited a site in the past 12 months). If you include all the inactive accounts it is still less than 2.9% of all accounts.
0.01 up to 2.9 is a massive jump and seems to indicate a high active user turnover. I wonder what the user activity retention rates are on SO. What percentage of currently active users are very recent joiners.
There was simply no benefit for the larger sites to access OpenID as an authentication mechanism. Perhaps the EUs General Data Protection Regulation can change that to some extend for smaller sites that wish to store almost nothing about the users, while still authenticating them.
OAuth 2.0 is an authorization framework, not an authentication protocol. OAuth 2.0 can be used for a lot of cool tasks, one of which is person authentication.
OpenID Connect is a “profile” of OAuth 2.0 specifically designed for attribute release and authentication.
For more info, see our blog: OAuth vs SAML vs OpenID Connect. [1]
[1] https://www.gluu.org/resources/documents/articles/oauth-vs-s...
> OpenID has been replaced by OpenID Connect
Replaced != compatible.
Also, "traditional OpenID" is very ambiguous phrasing... are you referring to OpenID 1? OpenID 2? or OpenID Connect?
In fact, the few websites which supported OpenID allowed to use custom providers while OAuth mostly limited to handful of social media providers. So OpenID was a way to decentralize the web and prevent password reuse while OAuth is a strategy by large Social Media corporations to increase your dependence on their brand.
In the end they both might be able to authenticate and to prevent password reusage to some extend, but their motivations and implications are very different.
AMA, I guess.
But yeah, this got me into trouble a couple times. I actually have a /openid URL on my site that redirects to Google, but forgot. This, mixed with accidentally having two accounts (back when Careers was it's own thing) meant some poor SO rep had to do a whole bunch of untangling one day.
I'm glad they're consolidating systems into an easier-to-understand thing. If it had just be email/password from day 1, I don't think I'd have had half the troubles I did by trying to be "future-compliant".
To forgo the bother of managing being provider or even relayer, I just use a Dreamwidth (the LiveJournal fork) profile [2]. Always interesting using a url as a login. For those who say that's confusing for the masses, there was a method of mapping e-mail address to OpenID profiles. [3]
I was a bit confused as to why OpenID Connect turned out the way it did, moving focus from federated to the closed "Login with Facebook/Twitter/GitHub/Dropbox/Google" thing (if they is Oauth/OIDC based?).
I guess the above could be related - I get no spam because federated OpenID didn't take off, and federated OpenID didn't take off because companies wished to sidestep a future spam problem.
[1] https://wiki.thingsandstuff.org
OpenID 1 & 2 have been dead and deprecated for some time...Google deprecated support in 2016.
All domains should move to supporting the latest iteration, OpenID Connect, which, by all indications, looks like it will be stable and relevant for many years to come.
https://developers.google.com/identity/protocols/OpenIDConne...
Stack Exchange has less than 10 million registered users? That’s surprisingly low even for Stack Overflow alone. I wonder how many MAUs they get...
The openid.net website is blocked by some popular web filters as "virus/malware".
Anyone know why?
Also, as remarked on the followup stackexchange discussions, this will make stackexchange login (against Google, Fb) JavaScript-only, won't it?
Could somebody with more know-how clue me in about the state of affairs of OpenID and web auth?
Because the Internet needs standards to work. If all domains implement authentication differently, we do not have an interoperable network.
As is customary, standards must evolve to keep up with requirements. OpenID 1 and 2 weren't built with the idea that smart phones would be in every persons pocket, or Internet connected devices in every home.
The latest iteration of OpenID--OpenID Connect--is essentially Google's playbook for authentication. It's of huge value to the rest of the world.
To put it simply: having your own OpenID Provider at your domain (e.g. idp.example.com) allows you to operate a similar authentication infrastructure as Google.
What does that mean?
- Single sign-on (SSO) across web and mobile applications
- Ability to support a variety of strong authentication mechanisms (a.k.a 2FA), like U2F security keys and OTP mobile apps, in one place for many apps
If all apps and services were to align with OpenID Connect, we would have a truly scalable and interoperable identity layer for the Internet.
All OpenID Providers publish their details at a publicly discoverable (and standard) domain: https://{hostname}/.well-known/openid-configuration.
For instance, you can see our OP meta data here [3].
This provides the foundation for using email as an identifier, i.e. in order to access protected resource at autonomous site, input email at a domain with an OP, and the RP can perform discovery to find where to send the user for authentication, and dynamic registration to register their client (app) with the OP to obtain user information ("claims").
[1] https://openid.net/specs/openid-connect-discovery-1_0.html
[2] https://openid.net/specs/openid-connect-registration-1_0.htm...
Do you e-mails end with @idp.gluu.org? Or how would the RP discover that the domain is not "gluu.org" but "idp.gluu.org"?
https://accounts.google.com/.well-known/openid-configuration
No, no they don’t. Not by far. Google, for example, doesn’t - and even if they did, it wouldn’t be useful, as they don’t support dynamic client registration either, as they want lock-in. Being able to type in my email address into a generic widget and get the Google auth dialog is specifically what they don’t want.
Facebook has the same issue, as does Yahoo. I don’t think I know of a single implementer of OpenID Discovery and Dynamic Client Registration - the only purpose of OpenID Connect as deployed in the wild is to share development resources, not to create a system where people can type in their email address into a generic widget which works for every OpenID Connect supporting domain off the shelf with no RP-side configuration and get a login form.
See here:
https://accounts.google.com/.well-known/openid-configuration
And as far as I know, Facebook doesn't support OpenID Connect. They still roll their own custom OAuth2 implementation.
When you login to google, it prompts you for an email address first. If your email is associated with an organization that has configured Google Apps to use their OP for authentication, Google will redirect the user to their home domain based on the email.