3 ms·
I've heard vague mentions of OpenIDs fundamental problems, but is there a breakdown somewhere? I've had a hard time finding a detailed technical description of
by artlogic 11y ago
I've heard vague mentions of OpenIDs fundamental problems, but is there a breakdown somewhere? I've had a hard time finding a detailed technical description of why OpenID failed.
I do understand that it confused the hell out of users that they had to login in with a URL, but that seems like branding and education more than a technical flaw.
- Navarr 11y agoI have always thought that OpenID would be wildly more successful if: 1. User puts in their email address 2. Website does a lookup on DNS for the email to find an OpenID endpoint (via SRV or TXT or whatever else) 3. If OpenID connector is found, user gets redirected to authenticate 4. If not, generic create account method.
- artlogic 11y agoExactly - that's why I say that the "enter a URL" issue seems like a minor update, not a glaring technical issue.
- icebraining 11y agoI think that's essentially Persona, except they do some extra work to avoid informing the Authentication endpoint about the sites you're logging in to.
- nickbauman 11y agoThat confusing part is not just a technical problem. OpenID basically teaches users to be phished, for one. But this has been discussed elsewhere, by yt, on HN.
- xj9 11y agoCould you link to that discussion? I'm very interested in the concept of federated identity and I would like to see where previous efforts have failed (and what they did well).
- nickbauman 11y agoHere you go: https://news.ycombinator.com/item?id=8831419 https://news.ycombinator.com/item?id=8831419
- alwillis 11y agoGood breakdown of different distributed naming/id systems, including OpenID: http://webcache.googleusercontent.com/search?q=cache:XpidG9O7rRQJ:manu.sporny.org/+&cd=1&hl=en&ct=clnk&gl=us http://webcache.googleusercontent.com/search?q=cache:XpidG9O...