Coding Horror: Your Internet Driver's License
codinghorror.com
codinghorror.com
That is what your mother thinks of when she hears Driver's License. Why on earth would that be the branding you pick for OpenID or federated authentication? You are practically trolling your own idea at that point!
Observe the kinds of things people are going to say about any federated identity scheme which you call a License:
"Jeff Atwood thinks the government should be able to take away your Facebook account! He's fascist!" "I didn't say that!"
"Jeff Atwood thinks your mom shouldn't be allowed on the Internet until she stops calling it 'the Googles'! He's an elitist bastard!" "I didn't say that!"
"Jeff Atwood thinks that if you get kicked off a WoW server you should lose your Gmail account. He's in bed with corporate interests!" "I didn't say that!"
Much to my delight, we canceled the silly project to issue government ID cards.
No perhaps about it. It seems to the average American, the word "drivers license" evokes "proof of identity" first and "proof of ability to drive a car" second, because they're using theirs as a general ID more often than for its original purpose.
It gets even funnier when American companies operate abroad and require "two photo IDs" in countries where everyone has a government-provided ID card.
This is because the idea of a National ID Card is for some strange reason (strange to this American, I mean) seen as an evil thing by the general public here.
But we all know our number by memory.
I don't. And I use my passport as an ID when two forms of ID is required.
http://www.wanderlust.co.uk/magazine/articles/destinations/a...
Apparently rail travel made the whole process of issuing and checking passports a bit of a pain so most countries just gave up - they didn't become common again until 1914.
It's not strangely low; Americans can travel to far more than the equivalent of the EU without one. (We can go to all 50 plus Canada and Mexico.)
:(
Edit: Since June 2009.
The US Gov does now issue passport cards which are a form of national ID card that allows citizens back in at international LAND borders. You should ask for one when you apply for your passport; they're nice to carry in your pocket when you're abroad and the full passport is safely locked away.
Yes, it looks like we speak the same language, but the diversity in "American" is at least as broad as the difference between the middle of "American" and "received English". (Yes, I'm aware that there's a lot of diversity in UK English.)
Yes, Americans mostly watch the same TV, but our exports and castoffs are not unknown in Europe.
I've lived in the UK and Oz and in both countries my drivers license stays in my wallet ready for when an over eager bouncer to ask me to prove my age or for when I sign up to a new video store on a whim. My passport pretty much stays at home unless I'm going to the airport.
Obviously, just kidding.
When most people think of driver's licenses, do they really think government certification, or do they think universal ID? I would be honestly interested in the answer.
Don't you have to take a test to obtain a licence? Here in the UK the test is relatively difficult and expensive, so not everybody has a licence. Passports are much cheaper, easier to obtain and don't come with age limits, so they are a more universal form of ID (though they are also bulky and hardly something you would carry around on you).
When most people think of driver's licenses, do they really think government certification, or do they think universal ID? I would be honestly interested in the answer.
When I think of driver's licences, I think of driving a car. Universal ID doesn't occur.
Why?
-- You have to take a test to get it, but you do that when you are 16 or 17, and never again. In most states, the test is ridiculously easy.
-- In an average year, you probably use it hundreds of times for its ID value (to buy beer at the grocery store or drinks at a bar, to cash a check, to check in for an airline flight), and (hopefully) zero times for the public safety function (showing it to a police officer after being pulled over).
-- Outside of NYC, the fraction of people over the legal driving age who don't have a license has to be less than 10%
> This is the status quo of identity on the internet. It is deeply and fundamentally broken.
What I do is, I have a couple of hard passwords that I use for email and Dropbox and important services like that, and then I have a couple of stupid usernames and passwords that I use and re-use and re-use for services whose security I don't care about. (I've arrived at this strategy after years of using the internet.)
A couple of times, I have actually tried to register an account with my usual username, found that the name was taken, wondered "Hmm, did I already create that account?", tried logging in with the usual password, and found that the login worked. "Oh, yeah, now I remember making that account..." I took this as a good sign, that I wasn't wasting brainspace on that login.
I think my strategy works fine for dealing with "a dozen websites who all want a username and password", given that only one or two of them are critical. And therefore I'd question the need to change, as opposed to people figuring out a strategy like mine and passing on the idea. Also, currently, anonymous throwaway accounts are easy to create; would it be that way if sites required something like OpenID? (I guess if the idea is just to reduce password complexity for customers, then sites could just add OpenID as a secondary means of logging in--rather than having it be the sole means--and you could still make throwaway accounts. Note that I don't know anything about OpenID; maybe there is a way to do anonymous throwaways within OpenID.)
Generally that's a red flag and I just don't use the site, but I don't always have that luxury. The service my company uses for performance evaluations has this limitation. Hmmm, a website I go to at most 3 times a year, requires a significantly complex password due to the site's nature, and yet won't let me use special characters making all my memorized "hard" passwords impossible? Yup, I have to request a new password everytime I visit it. Very annoying.
It's the login-password pairs which are inconvenient (and, a lot of time, insecure) part out there. So, logically, the straight answer seem to be to get rid of this part in favor of something more usable, users can possess to prove their identities. For example, improving browser support for public-key crypto and key storage (think HTML5 <keygen> element). However, world has gone in a completely different direction, created "identity providers", who now actually possess users' identities (so you don't own your identity anymore), and, as a result, introduced more failure points to the auth process.
OpenID is neat and convenient when done right, but it was just a protocol invented to sign comments at other persons' blogs. It was never meant for personal identity management and architecturally lacks a lot of important points for that. XRIs may be considered some sort of solution for that (I-numbers are guaranteed to be persistent), but still feel somehow wrong.
That's because the question answered wasn't: "How do we solve the problem of user identity on the web?" The actual question answered was: "How do we solve the problem of user identity on the web using web services?" Once you define the problem that way, OpenID becomes the logical best solution. However, it's hardly the best way to do it in any general sense.
I'm willing to show my ID at bars and airports, to cops, and when opening bank accounts, because it's the law. And at least most of these venues have excuses -- banks want to link large amounts of your money to your ID, so they need to make sure they've got it right; cars are deadly weapons; alcohol is a potentially deadly drug. (The airlines? They really love nontransferable tickets with big change fees. And security theater. And, uh, did we mention that it's the law?)
But in general nobody asks for your ID unless they have a good reason. And I just don't see a good reason why my as-yet-nonexistent Stack Overflow karma needs to be linked to any other aspect of my identity.
At least I have a straightforward answer to my question: No, the Stack Overflowers will not give me the simple username and password that I want. It's against their religion. Good to know. I'll ask again five years from now.
We have some users that juggle cookie based accounts for as long as a year. And as of about 6 months ago we can reinstate your cookie on the "forgot my login" form, provided you gave us a valid email address to start with (we don't validate emails).
OpenID is more like a Von's Club card. An inconvenient scrap of plastic that would just take up space in my wallet so it gets left at home. Every time I go into a Vons, I have to ask the cashier for a new one and it pisses me off that little bit, just like every time I go to StackOverflow I need to dig though my email to figure out what OpenID provider I used to sign up for my account there.
Just like the Grocery Store Discount card, where I find myself more driving out of my way to go to a store that doesn't make me use one, I generally don't bother with sites that want me to dig out my OpenID just to use them.
Now that Gmail is a provider, the barrier is lower, but back then you had your pick of a half-dozen fly by night early adopter providers. So anybody who used it back then has at least one worthless OpenID.
Just give me the "Save username and password" option in Firefox and I'm happy.
You take a test to get an email address, have to wait until 16 for the privilege and it can be almost arbitrarily revoked?
13.3 Google may at any time, terminate its legal agreement with you if:
So I think the metaphor fits quite nicely, don't you?
No, I can setup my own MTA, or get a cheap account at a random host which will provide me an MTA, and there are a billion services out there to get email addresses.
I don't support centralized internet ID systems for the same reasons I don't support a national identity card: it's a central point of control that will inevitably be used by the government against its citizens and corporations for profiling and targeting all of us.
As much as it may appeal to the tech mind to have things in nice little boxes this is a terrible and dangerous idea.
I'm not sure where people are getting this idea that he's talking about creating a new concept called an Internet Driver's License. He's just trying to encourage service providers to adopt OpenID/OAuth instead of traditional logins.
Ironic.
I'm flabbergasted that so many people heard "Internet Driver's License" and simply started frothing at the mouth. It's quite crass, in my opinion.
I know that systems such as OpenID and others perform authentication directly between the user and thetrusted provider (google, facebook, twitter, etc), and that the site ends up with a one-time token that confirms the user's identity. The site requesting authentication never gets the actual password to the openID account, which makes this approach viable in a technical security sense.
But here's the thing: general users are getting used to entering their centralized credentials to perform actions on untrusted sites. Technical users understand the design. We can confirm that, yes, TwitScoop does indeed direct us to twitter.com/oauth/... (no HTTPS, but that's another story).
Regular users posting a comment on a blog, though, don't see any difference between giving their credentials to a trusted Google login site and entering their credentials into some form on a blog.
If, for example, logging in with Facebook credentials becomes common, it would be trivial to create a rogue blog which collects login information. Fill it with a few incendiary posts, possibly create an official-looking Facebook login page that doesn't display its URL, and it would be possible to capture quite a few sets of credentials.
Alternatively, MyOpenID and some other OpenID providers allow you to choose what pieces of data to present to the requesting site when asking you for permission to authenticate with them.
Facebook is another story, as they want every profile to correspond to a real-life human and only present an allow/deny choice for permissions to the requesting site instead of finer-grained access control.
I see no problem with tying my offline identity to my online one.
Besides, if you wanted to disconnect the identities you just create multiple OpenIds for each identity you want to act out.
edit: ok, the sarcasm in this comment may justify it being downvoted, but can someone kindly explain what is being said in this article apart from: "having many logins/passwords for each site is not nice, we should all support OpenID/OAuth"? Because I really don't see any other piece of information.
Reminds me of someone (can't really find who now) who said a few months ago that HN is like going out for a movie and a dinner. The value of it isn't really the movie and the dinner, but the opportunity of discussions it creates.
So... yeah :)
The crucial difference between a drivers license and some kind of centralised internet ID is that anyone can verify a drivers licence with a reasonable degree of accuracy - they don't need to contact the government each time to see if it's genuine.
With an internet ID the provider gets to collect a lot of information about me and what I'm doing (not saying they would, just saying they could), which makes me nervous.
It takes private companies w/ consumer interests in mind to achieve that sort of global scale and user adoption. In this case, namely Facebook.
I think 'an internet drivers license' would basically become an ID card.
Unlike an ID card you can have as many OpenID accounts as you wish – they can be freely created just as easily as email addresses. The solution is the same as for email: Give a different account to each site.
Every hyped technological product has a a short window in which to dominate, and if it does not, it will remain confined to a nice. That's the case with OpenID. It's over, the battle is lost. Same goes for RSS, DRMed music, Django, etc.
The coding horror guys made a poor technological decision. Instead of just giving up, they are doubling down on it. That's not very clever.
Oh... You mean the guitarist... Right... It was tragic... Only about 40-something...
Source?
I hardly expect such comments from guys like Jeff.
I think it has something to do with what commenter Kevdog said:
> Here's where the driver license analogy breaks down: I have physical control over my license, it stays with me. No one can lose my license for me.
Or even easier: use delegation. Add some meta tags to the header of your blog (or any HTML page under your control), and sign up for sites using your blog URL as your OpenId.
See an example at my domain (the content is currently blank, but the meta tags are in the source code): http://jmh.id.au
I can sign up anywhere by typing in 'jmh.id.au', and it uses myopenid.com for login. If for some reason I didn't trust myopenid.com I can change providers by editing that page. So I'm not tied to any one provider.
The first is practical: you are not qualified to run OpenID on your server. Really, you're not. I'm not and I have actually implemented both OpenID providers and Relying Parties for clients before, at the old day job. If you run OpenID, you are exposed to every threat your OpenID provider is currently vulnerable to in perpetuity, unless you make it your mission in life to stay up to date on OpenID security. The people who actually do that missed a timing attack which compromised the security of nearly every OpenID-using system on the Internet. You will not do better than they did.
The second reason this is bad advice is because OpenID has a feature which should make it unnecessary: delegation, which lets you nominate any OpenID provider on the Internet as "your" provider. You are theoretically able to change that after having done it, so if you want to move your identity from Google to Yahoo you can. Delegation is a misfeature. It makes the OpenID spec roughly ten times more difficult to understand than it already was. Very few people implement delegation correctly -- of particular notice, very few relying parties implement it correctly, which means that when you come back in a few years with the same OpenID but a different underlying provider they have no recollection of you at all. That is a pretty bad failure mode for a federated authentication system, and many relying parties coded by smart people walk straight into it.
Then we come to the real meat of the matter: for an authentication system to be useful, you have to be able to use it without being able to implement it. OpenID is a user experience nightmare for non-technical users. Just the experience of actually logging in is bad enough. It also teaches your users to fall for phishing attacks against their holiest of holy credential, because every sane person uses OpenID through their email provider and OpenID teaches you that you can go to any random site, the screen is going to flash, and then you should type in your email address and password. This is phishing heaven, and losing one's email account means you lose practically your entire online identity (banks accounts, domain names, Google AdWords accounts, etc etc) even before OpenID explicitly makes your email king of all credentials.
Anyway, is delegation going to get better, or should I not bother setting it up and just stick to using the same password for all my non-interesting sites? In particular, is it the site I delegate to, or the site I am authenticating myself to, or both, that can screw it up?
Phishing attacks could definitely be a big potential problem. I'd be interested in seeing how much of the phishing and usability problems could be solved via good browser support for OpenId.