OpenID 2.0 for Google Accounts is going away
support.google.com
support.google.com
[1] http://homakov.blogspot.com/2013/03/oauth1-oauth2-oauth.html
Persona is still there. It's still maintained, despite getting no funding, but that doesn't mean developers can't pick it up. If you are interested in authentication, learn about it. Implement it. Support it. Convert people.
https://www.mozilla.org/en-US/persona/ https://developer.mozilla.org/en-US/Persona
Edit: Found this - https://developer.mozilla.org/en-US/Persona/Libraries_and_pl...
Google now uses an OAuth 2.0 extension called OpenID Connect. This introduces an entity that's analogous to a referral letter [1], the ID token. It's basically a little string of encoded (possibly encrypted, possibly signed) JSON containing 'claims' about the authentication state of the end user. The client application can then validate that token to confirm to its satisfaction that the authentication happened for some particular user — and that the ID token was created for it and not some other application.
[1] http://nat.sakimura.org/2011/05/15/dummys-guide-for-the-diff...
For example:
- a site might offer to login via Facebook, but I'm afraid to in case my friends' Facebook news feeds get spammed.
- I want to offer an easy login for my users, but which OAuth provider do I pick? Which OAuth, OpenId thing am I supposed to use? They all look the same! But different!
Can't wait to migrate everything over to Connect instead.