Yet Another Sign Up (Why Isn't Open ID More Popular By Now?)
blog.amir.rachum.com
blog.amir.rachum.com
BrowserID, however, has now fixed most of these issues, and it's very straightforward to use. To try it out, you can have a look at http://www.yourpane.com/
1) I would go to a website, it would ask me to register or sign in with "OpenID". It would tell me a little bit about OpenID "Yahoo, ___, and ___ are OpenID providers. If you have a Yahoo ID then you have an Open ID".
2) WTF is the point of an OpenID then?! If I could just sign in with a Yahoo account I thought...
3) I try to sign in with my Yahoo ID like it said. It fails every time. WTF.
4) I go back to Yahoo to GET an OpenID. It tells me I already have one. I try to get one from other "providers" and somewhere along the way I always get misdirected or the sign up / registration process just fails and I just get sick of the whole OpenID-Mind-Game and sign in with my facebook account.
After 3 or 4 mind games I became extremely frustrated and soulfully HATED OpenID. It was all over the place, I didn't get it. It couldn't work for me. So I felt like it was a feature I was not allowed to have. Just thinking of the OpenID logo and name evokes feelings of annoyance. So the brand is trashed is what I'm saying.
And the so-called "informational" documentation on the OpenID project site is ... vague to the extreme, and that's being charitable.
While it's fine abstracting away technical information from users who don't want it, if you're going to create a Grand Unifying Identity Service, you're going to get much better buy-in from those who do care to find out about how things work under the hood, if you make it possible to do so (and without reading the source / diving fully into the developer docs).
OpenID is a trust dud.
In what world is that more usable than "Click here to login with Google / Yahoo"?
If you want to see a more "pure" Persona implementation, our standard example site is at http://123done.org/ (and you can preview the "Persona" redesign at http://dev.123done.org/).
As for as being as easy for first-time users as "Click here to log in with Google / Yahoo," well, we've got some tricks up our sleeves. Look for a blog post next month at http://identity.mozilla.com/ :)
Also, I love how I can integrate Persona with Django in (quite literally) three minutes, with zero changes to any existing auth mechanism.
You're losing users right there if it doesn't redirect back to your site after account verification.
I'm really hoping Persona takes off, especially with widespread browser support. Will it still need a third party service then, or will everything happen in-browser?
If I understand correctly, using OpenID means that Site A can confirm that User X is the same as User X on Site B, using OpenID?
I can see where that's a win for sites A & B. I can also see many instances where that is not a win for me.
Everything gets forwarded to the same inbox.
tuffmail.com is awesome and cheap; I'm a happy subscriber.
Of course, in reality, both sites will request your email address, so they can figure it out anyway.
Between this and your comments on G+, you seem really interested in villianizing your service providers when there are obvious ways to avoid their naive account associations [1], as you even take advantage of.
[1] I say naive because I would be willing to be a large amount of money that I could track you between accounts unless you're taking some insane precautions against it, even without an email address or OpenID url.
For casual purposes, which encompasses much of my present threat model, the measures I'm taking should be reasonably sufficient.
The point I and others are making is that:
0. There's a growing default assumption that individuals have no privacy, that privacy is dead, and that we should all just roll over and forget about it.
1. Even if you trust your service provider today, you may not trust them tomorrow.
2. Even if you trust your service provider, you may not trust those who have access to your data through your service provider. Intentionally or otherwise.
I'm well aware that roughly 32 bits of leaked information should be sufficient to identify me, if not precisely, then with reasonable accuracy. This doesn't mean I'm going to hand over my SSN and DOB to anyone who asks.
It may also be the case that I'm deliberately trying to create various associated identities.
That said: if you're interested in trying to link this identity to others, you can GMail me any of your prospective linkings.
* because the user experience really requires you to have the "nascar effect" of several well-known icons. OpenID could scale horizontally technically but in fact it doesn't work that way. Except for a few providers (like Google) it is not "peer to peer" (many to many) but more like "business to customers" (one to many) relation
* because the "like"-generation beloved blue button talks something else (and is "way more important" than some technical nice thing)
* because it requires putting too many eggs in one basket (one ID to rule them all. And even "the few big ones" are these days hacked without problems)
* because your database of users is your asset (at least in the US). In EU it is more often a liability. * As this is an asset, nobody wants to pay anything for a secure identity as a TTP service.
* because it forbids "sensible" use on mobile devices (I have a phone and a PC, I would like to link my phone(s) to my services through numbers rather than on-phone cumbersome username or openid hack)
* pairing with a QR code works well for me. It even allows to establish a more meaningful key for further communication (I check the "green bar" of the browser than the underlying, semi-anonymous, DNS-depending OpenID)
* because OpenID does not really work for anything than medium-security identification transport. I hope my bank will never use an OpenID to authenticate anything.
* just try a new service with a throwaway account. or a throwaway password. Maybe one day people build services, which do not require pairing to "something" at all. Or Just use "click-the-link-in-e-mail-or-copy-token" approach.
Seriously. I love SO, but this is one of the scariest log in pages I've ever seen: https://img.skitch.com/20120627-d49s8rqaeu5p5d3dkmn2p26tim.p...
I'm surprised it's not seen bigger adoption in the start-up crowd, but I guess it was slightly more work and isn't quite in-line with the MVP culture.
It also places a reliance on a third party - but in this case I expect good reliability from Google, and have a fallback option in place (both for availability, and to support older browsers).
"The short answer is that OpenID is the worst possible 'solution' I have ever seen in my entire life to a problem that most people don't really have. That's what's 'wrong' with it."
http://www.quora.com/OpenID/What-s-wrong-with-OpenID/answer/...
The real question is why these guys didn't let you signup with Facebook.
I don't have any answers.