(Seriously, that's a question: Why don't more people use OpenID? Is there something wrong with it?)
(Seriously, that's a question: Why don't more people use OpenID? Is there something wrong with it?)
Because the user is more likely to have email than OpenID, so delegating to an option of one or the other is more complex, and delegating to only the latter is limiting your market.
But yeah, I guess saying "now go to this 3rd party website and create an OpenID account" is pretty ugly. I wonder if it's possible to have your own "sign up" page that's a proxy for creating an OpenID with a 3rd party provider?
People are likely to remember their email if they have one, but URLs are disappearing from user interfaces (see Chrome, Safari, Mobile Safari, etc.).
A user probably already has email, thus it usually isn't required. Unlike openID
They do seem to moving towards OpenID Connect though, which is just a identity layer on top of OAuth 2.0
Issue 2: tech-phobic people don't trust OpenID, OAuth, etc. I'm working with a client who wanted "single sign on" with a tolerated competitor in the same space (nonprofit, don't ask); that competitor's tech guy advocated for OpenID, and OpenID became a hard requirement. The problem: the client's membership fought tooth and nail throughout alpha & beta rollouts (change is scary. are we giving google/yahoo our information? we don't understand it. we're not a bank, why do we need tighter authentication? etc) and it was eventually scrapped in favor of a traditional login.