Facebook's Internet identity monopoly
somebits.com
somebits.com
Some quotes:
OpenID is the worst possible "solution" I have ever seen in my entire life to a problem that most people don't really have.
A nerd will wrinkle up his nose at these [non-OpenID] solutions and grumble about the "security vulnerabilities" (and they'll be right, technically) but the truth is that these solutions get people into the site and doing what they want and no one really cares about security anyways.
Let's think about that one for a second. I find this rather typical of Facebook's attitude in general—a monomaniacal focus on increasing engagement or whatever metrics, a complete disregard for externalities and an arrogant rejection of any sort of social responsibility. This is what makes them so successful as well as so dangerous to the rest of the ecosystem.
He talks about a problem that most people don't have, and then goes on to state nerds turn a nose up at "security vulnerabilities".
At the core, it's a problem that most people do in fact have, it just is not presented to them in a fashion that is easy to digest, or even tasty enough to consider ordering from a menu. The typical computer user doesn't think about what happens to their password in transit, they enter it, hit enter and say a short prayer that they didn't typo so they can get where they want to go, and get on with life.
If the openID marketing initiative focused MORE on the "stop remembering passwords" a little harder than they had, maybe it'd still be relevant outside of tech circles.
And furthermore, building on the "solution [...] to a problem that most people don't really have"
Didn't Facebook essentially go about solving that "problem" themselves, albeit packaged up in a nice wrapper with your friends and social profile as the adhesive tape?
For one, it was too limited in scope: it assumed it would operate only within a traditional browser, that cookies are the only place you ever need to store information and that the user is always there to authorize every single action. You can't use OpenID to delegate or automate anything and OpenID just doesn't work well e.g. in desktop apps or on mobile devices. It's locked to one particular interaction flow, and it's not even a good one.
For another, the whole thing was designed by and for people who run websites. 99.99% of the world does not have their own personal domain and the idea of using a URL as their identity was just confusing and weird. Features like delegating your identity using HTML Meta tags on your site are misguided toys for tech nerds with no real world relevance.
Finally, the parts of OpenID that would actually be interesting, i.e. the selective, automatic sharing of information between sites to avoid long signups, never went anywhere, ensuring there would be no actual benefit for the end user for using OpenID.
Facebook didn't just bring a solution that solved all of this, with Facebook Connect and OpenGraph, but they also delivered the user-base to go with it. Think of all the bad privacy PR that Facebook has gotten... has it dented their image? Nope. Because FB connect is too valuable in keeping the barrier of entry low. When given the option, people prefer FB connect.
The point about security isn't that it doesn't matter, but that OpenID is a completely secure solution that nobody really wants to use. Anyone who knows crypto can design a secure handshake, but it takes a lot more to design something that people actually want to use.
EXCELLENT rebuttal, I hadn't thought to look at FB Connect like this with my original comment.
But there are services where I think people care, where having their activites on that service tied to their Facebook personality is something they don't want. The obiovus example is dating sites, but also simple things like blog comments are affected.
Techcrunch had an article on how their comments "got better" after switching to Facebook Connect, but they also noted that there were much more positive comments, and far fewer negative ones, much less constructive criticism, because people don't want to appear negative in front of their Facebook friends.
I think a lot of people care enough about anonymity or at least pseudonymity, so the more services that require you to have a Facebook account, the more fake accounts will be created. The more they tighten their grip, the more users will slip through their fingers...
1) Facebook Connect provide access to real identity (as opposed to an anonymous token) and they actively try and weed out bad actors 2) Facebook social plugins are easier to use than OpenID 3) Facebook Connect provides distribution of content to people that trust the user (on average 150) 4) The users Facebook profile provides usable insights to the publisher for targeting and follow on marketing
In order for something like OpenID, Google Login, Yahoo Login, Twitter @anywhere, to beat Facebook they need to provide a competitive set of functionality to the publisher and equal ease of use to the end user.
Facebook Connect is no better than the open alternatives to identity management but as usual the open alternatives have a PR problem because the user experience is just as seamless but somehow publishers are convinced that flooding the user's facebook stream is going to bring them traffic.
People have a reason to use their accounts on Gmail, Yahoo Mail, Hotmail/Live, Facebook, Twitter, and etc. The reason why Facebook Connect has been successful is that it is an extension of an identity that many people already use on a daily basis. As long as OpenID remains just an identity provider, it will continue to lose ground. This will especially be the case in the realm of mobile, where cell phones can provide person-specific solutions in a manner that desktops so far cannot.
1) Apple was choosing between Facebook Connect and Twitter Connect for their account integration. 2) Android will naturally use Google accounts as a first choice. 3) Windows Phone will primarily use Live accounts. 4) HP/Palm and RIM need to figure out what they are going to do in this space. 5) Facebook has the ability to leverage Android for a Facebook Phone if they so choose. Currently they are instead trying to become ubiquitous across all platforms. 6) OpenID is nowhere to be found.
We will continue to see integration of this nature across all platforms. OpenID simply does not have the leverage to be successful in the long run. They're still fighting the battle in the browser, while the war is already moving higher up to the device itself.
I'm not sure I understand what you're saying here. TTBOMK, Google, Yahoo!, and Windows Live ID are all also OpenID providers. E.g., the Isotropic online Dominion server allows users to “log in with a Google or Yahoo! account” with an OpenID backend.
So if your thesis is that people reject OpenID because they can't extend their identities from those existing accounts, I don't see how that's the case, unless the OPs have restrictions I'm unaware of. (People might not know they can identify themselves with those accounts, which I think is a real problem, but a separate one.)
I'll illustrate the point as such: My username is Sayter. 1) Go find my Facebook. 2) Then go find my Twitter. 3) Now go find my OpenID. You immediately know where to go for the first two, and in fact can type in the url's for my Facebook and Twitter accounts directly. But how about my OpenID? Is it my Gmail? Yahoo account? Windows Live account? All of the above? Whichever I use the most? Or is it the OpenID that I have on one my domains? My identity for OpenID is fragmented (I'm not even sure how many I have, honestly) and does not exist in a single space, while Facebook and Twitter do exist in single spaces (assuming I only have one Facebook/Twitter of course, but that possibility was simplified for the sake of argument).
That is a non-trivial problem that Facebook and Twitter have (mostly) solved, while OpenID is still struggling with it.
As it stands, email registrations can be automated to the point that its only use on popular site is to confirm the being able to receive emails.
https://en.wordpress.com/signup/
My WordPress.com site can always be transferred to a host of my choosing (especially if I register a similar domain name) (and not at giant GoDaddy).
I simply will not post on sites that require Facebook, or Blogger, or Yahoo! accounts to log in. Period.
Except for banking (which I try to avoid online) and really special logins, I simply use one very-hard-to-crack password for everything, like "bluefrogsridelogsatsunset". People argue about how hard it is to crack passwords, and what kinds of passwords are secure, but I'm pretty sure that no one (except perhaps the government) can really crack a password such as the one above. This solution is good enough for me!
I suggest using the master password to manage other passwords (Browser might have a password manager, Keypass or other tons password managers). Sony, Newegg, Facebook and some other companies can see passwords in plain text which could be used in conjunction with your email or similar contact methods to infiltrate your account.
I actually do use KeePass for several things, and I think it really is more secure than my "simple solution." Plus it keeps my data in a nifty portable "*.kdb" file. But it's just a bit clumsier to utilize. I don't use the Firefox password manager, which updates often; who knows what might happen when it does? KeePass is available at:
OpenID has proven to be too damn complicated. Mortals can't understand it.
Mozilla's Account Manager seems like an awesome solution: http://hacks.mozilla.org/2010/04/account-manager-coming-to-f...
It seems to me that Google, with it's popular browser and web services, is ideally positioned to popularize an account manager protocol. And with the heated competition with Facebook, they've got just the right motivations.
I think it's more that mortals see no reason to bother understanding it. It's conceivable that lulzsec etc might help change that.
As spullara explains below, Facebook's monopoly has come because Facebook Connect is an all-round better product. Publishers get access to easy syndication ("oh, you just joined XYZ? Here are some badges; want to share them on Facebook and let your friends know about us?") as well as higher-quality users overall (Facebook accounts tend to be real). Users get a single login from a service they (mostly) trust and easy integration with their social network ("oh, John's using turntable.fm too? Sweet!").
The brilliance of Facebook Connect is the tie-in of syndication with identity. Logging in with Facebook is a better experience than just registering, for all parties involved. This is why Facebook Connect works and why MSN Passport failed a decade ago.
The monopoly side of things is going to become a problem in the coming years; I for one expect federal intervention in the form of mandating a common federated social networking platform (a la, but not necessarily, via the protocols developed by diaspora). Federation and decentralization is what happened with phones and with email; if Facebook/social networking-style communication is the next generation, it seems like a reasonable next step.
Most users will never tell the difference, at first - Facebook will remain their default client both for login and for reading friends' profiles and news feed. With time, however, competitors will begin to emerge and offer alternate interfaces for either news feed filtration or for identity, opening up space for innovation in a place once dominated by one or more entrenched players (Firefox vs IE, Gmail vs Hotmail/Yahoo/AOL). Early adopters will be using social networking tools but will be able to seamlessly interoperate with people still on Facebook.
Perhaps I'm naively optimistic, but I'd be excited for a future like that. For now, though, I'll stick to Facebook Connect - the bigger it gets, the more likely regulation will occur.
Seriously? This will never, ever happen.
Ever, ever, ever.
That's just not how life works. Or businesses. Or how the US government works. It's the total antithesis to the American ideals. It wouldn't even have a chance of happening in social democracies in Europe, let alone America.
Ever.
Stranger (and more asinine) things have happened.
I fail to see how things like that never ever happen. It doesn't happen in quite the same way, but the fact is, anti-trust isn't antithesis to the American ideals. Allowing one company a position where it can toss abuses both upstream and downstream of its supply chains doesn't mesh at all with a market interested system.
Of course, my sister uses her telephone connection for entertainment as well..
Ma-Bell was in fact, not the only way to communicate. That's like saying Phones were the only way people got in touch. Its simply and patently wrong. as far as industries that did Ma-Bell's job, you've the post, television, and radio.
Cars didn't run on something Standard Oil did not sell.
They all have in common that individuals no longer have control over their own identity. Instead they must cede power over their lives to others who pull the strings.
There is no need for identity providers. The entire concept is totalitarian, offensive and horrific.
So if I go to a shop and buy a tshirt then I have done that pretty much anonymously but if I buy on a website that requires a Facebook connect login then I have given way more information about myself.
There is no real Facebook monopoly imposed on website publishers -- there is just a monopoly imposed on the users of those websites where Facebook connect is the only option or the only visible option. I agree that it's a concern, though.