4 ms·
Are you this Alain? http://answers.onstartups.com/users/502/alain-raynaud http://answers.onstartups.com/users/502/alain-raynaud if so then your account looks up
by codinghorror 16y ago
Are you this Alain? http://answers.onstartups.com/users/502/alain-raynaud http://answers.onstartups.com/users/502/alain-raynaud if so then your account looks up to date to me, and you were able to log in through Facebook. Realize that this was a legacy SE 1.0 site we imported over, so your account may have had some very old stuff in it, and it may not be representative of SE 2.0 logins.
- patio11 16y agoRespectfully, "We did something on the backend and now some logins no longer function" is a fairly common implementation flaw with OpenID. This is a pretty serious Oops for an identity system. The traditional username/password pair is virtually immune to this, if we assume the developers are competent. (Competence will not solve OpenID delegation, as one example. It is virtually immune to comprehension by mortal minds.) Something for other HNers to keep in mind if they are considering openID for their next project (flee, flee!)
- Locke1689 16y agoWith all due respect, I think you're completely wrong about this. I do not assume that most developers are competent. In fact, when it comes to security, I assume most developers are about two steps away from handing out root on request.
- patio11 16y agoSpeaking generally, I agree, competence is a risky assumption. It isn't risky about the SO devs: I've met some, they're sharp. They're certainly well-past sharp enough to get username/password working right. But OpenID is easy to screw up. Practically everyone has enormous problems with their implementations. (This goes seven times over for yours truly.) Which is (yet another) knock against choosing OpenID for anything important, versus systems which evidence exists can be implemented correctly. It is possible to bork username/password, but it is possible to implement it mostly correctly, too. I do not think it is possible to implement OpenID correctly. (For what it's worth, StackOverflow's is the best implementation I've seen from the user's perspective.)
- Locke1689 16y agoThe implementation issues comprise a very good point. Do you think this is solvable by better libraries? I've been working on my own solid implementation of OpenID for Django to plug-n-play with the built-in authentication system. Can it be saved and, if not, what's the alternative? Teach developers about bcrypt?