Yeah, 2 is all I really care about. First-party discovery systems are almost always bad imo.
And every time I think about it for more than a second, I get mad that OpenID got eaten by OAuth.
And every time I think about it for more than a second, I get mad that OpenID got eaten by OAuth.
I’m sure it was imperfect, but in theory it was easy to host and easy to implement. :(
Revocation was hard, but it's not like existing systems are solving that in practice either, and you can get a long way by just keeping short leases (which is fine because nothing needs to communicate with any third party).
If passkeys weren't so blatantly DRM-friendly I might like those, but they seem intentionally human-hostile for no good reason at all.