I am always happy when I can use OpenID on a site. It's a really low barrier and guarantees that I won't leave at the sign up form. The only reason I don't use it every day is because the sites I visit every day don't support it.
In fact, a ton of the code that runs the site itself is fully open source: http://developers.facebook.com/fbopen/ That's mind-blowingly impressive. I still don't believe more people don't know about this or seem to care.
"FB connect" is a session management and authentication product from facebook. I find it obnoxious. It is pretty much literally the antithesis of openid. FB open source: good, FB connect: horrible.
To those of you who haven't used it, try it out before condemning it.
It's really nice to login with the click of a button (no typing usernames and passwords) and signing up is usually a one click action as well.
Or you can host your own.
See here for a good list: http://openid.net/get-an-openid/
I initially wasn't too impressed by OpenID, but I was sold by the third site I got to use my login. It's value is really tied to the adoption by sites.
It's especially nice on small blogs: you don't have post anonymously if you are averse to signups.
http://intertwingly.net/blog/2007/01/03/OpenID-for-non-Super...
This allows you to change the underlying implementation at any time.
Gravatar support is, for example, a feature I'd like to get from my OpenID provider. After all, my image belongs to my identity.
Next, with a single identity comes also privacy concerns. Automatically generated disposable E-Mail addresses for each new sign-up would be nice to have, in my opinion.
Privacy concerns, however, are also related to the most common business models of these providers: It seems, nearly all of them want to display or sent me advertising. Or they want to be able to improve their advertising displays.
Can't they just ask for, say, US$29 or US$39 a year?
Then, I'd also need some sort of easy Identity transfer. If I switch providers, for example, the new one should be able to ask the old one for all the data and notify the consumers about the switch. Otherwise, the transaction costs of a switch would be rather high, exposing me to monopoly problems.
Browser support would also be nice to have, so there's a check that I'm being redirected to my true ID provider, not just something that looks like it.
Maybe, this stuff is too sophisticated for a sufficiently large number of people. But maybe, it works with the right sales pitch.
Your later concerns are solved by openid delegation. Any uri you own can be made an alias of any openid you want. Thus if you switch openid providers all you need to do is edit a page you own and make it point to a new provider. https://www.myopenid.com/help#own_domain
The great thing about login/identity/authentication standards is that there are so many to choose from. Didn't we learn the first time around with web browser capabilities to avoid this kind of fragmentation again?
As most websites that do support it — that I use — require a traditional email/username and password based account and I've yet to encounter a website that required me to have OpenID to make full use of functionality, to me, an OpenID account is the extra account I have to keep track of.
Interestingly, Wildbit removed support for OpenID in Beanstalk earlier this year. (http://wildbit.com/blog/2009/05/26/what-happened-to-openid-s...)
Additionally, users can publish their activities on a website back to social networks including Yahoo, Facebook, Twitter, and MySpace which increases referral traffic to your sites and facilitates subsequent logins.
Clients include Sears, Kmart, Universal Music Group, EMI, Fox News, KickApps, UserVoice, Viewpoints, Get Satisfaction, Savings.com, FamilyLink, DC Shoes, Famous Footwear, and many others
When you 'sign up' you would just provide you public key to the website (upload or url). Then when you were presented with a login, the browser would be sent a data set to sign with your private key and send back to the server you are trying to access (which would then verify with you public key).
My main frustration right now is that, aside from Bouncy Castle, all the libraries I've looked at to do cryptography seem to just be partially implemented wrappers around GnuPG.
If all I had to do was grab their public key, I could then do everything behind the scenes (even creating groups so that some people can see some photos and others can't).
Anyway, this is very simple to do. You first create a server that can authenticate you just for itself over the web. You send it your id, it sends a random string. You sign it and send it a random string of your own. Server signs your random string and sends it back. You both know you are authentic, server leaves a signed cookie at your end. Now this server can act as an openid server too. You give random web-app your openid residing on this server... random web app asks this server. It confirms or denies and life is good.
Ofcourse, I _know_ this, but in general, users don't know and don't care. So, OpenID actually makes the web a safer place for inexperienced users, which is I think is rather important.
I don't understand how anyone can promote OpenID in good conscience with this glaring hole in the design. You simply can't rely on user education.
Can someone who doesn't believe the phishing potential is real please tell me why? What am I missing?
I'm a believer.
I used MyOpenID instead of google/yahoo etc since after reading the article about the power of google passwd that was posted here, since I expect MyOpenID to be primarily for trivial logins.
And there are few sites I log in with my OpenID.