5 ms·
Dear World, email addresses are not identity
- fizx 18y agoNeither are SSNs, but hey...
- aneesh 18y agoWell, they're not completely ineffective. How many people do you know that have two or more SSNs? How about multiple email addresses?
- tomsaffell 18y agoI've heard of it going the other way, i.e. one SSN maps to multiple people (or at least multiple names).
- jshen 18y agowell there are two different issues that overlap a good deal. 1. wanting a way to uniquely identify a user that is easy for the user to remember (email works great) 2. wanting a way to prevent users from creating duplicate accounts Using emails works great for 1 and is a decent low bar for 2. There are no good answers for 2 so using an email address is the best I have seen.
- awt 18y agoWould be cool if he had discussed some alternaties...
- btw0 18y agoWhat should be a good online identity? It's an open problem nobody has yet solved.
- aneesh 18y agoFacebook is trying to solve it. It's easy to create a new email account. It's much harder (though not impossibly so) to create a fake identity with 150 friends.
- Devilboy 18y agoThat's true, although I kinda like being pseudo-anonymous on most public forums. Also meet my friend: http://www.facebook.com/profile.php?id=622877592 http://www.facebook.com/profile.php?id=622877592
- Shamiq 18y agoEveryone needs his own key. And needs to sign her own documents.
- potatolicious 18y agoThe better question is what you need from the user's identity. If an identity is simply a means to authenticate the user on your service only then an email is more than good enough. If you don't need anything else that is associated with the person's identity (e.g. his social network, real-life address, etc etc) then I don't see a problem with using email.
- olefoo 18y agoIt's becoming enough of a problem that it is being suggested that the government support some form of credential that could be used online. see: http://www.nytimes.com/2008/12/09/technology/09security.html http://www.nytimes.com/2008/12/09/technology/09security.html And yeah; I'd rather the government than facebook, thank you very much.
- mnemonik 18y agoI wouldn't. I would much rather a private company with experience in determining online identity provide a service like this. A. It would be an optional service, so you would only use it if you wanted to. (Unless gov't got involved somehow, but my whole point is that they shouldn't be involved.) If it were a gov't run operation it would probably be impossible to opt out of. A recent example is the Australian filter. That's not working out very well, neither would this. B. A private company has more to lose if it were to screw up implementation and design than the gov't would. I would trust my privacy to a company before the gov't because I could weigh customer reviews and go to a competitor's service if it was better. C. A gov't can say screw you guys, work with my standards for verification. A private company would be forced to work with others or fail.
- charlesmount 18y agoHi article does not really address the point he makes in the title. Email is the best source of primary identity for web applications. If you are building a business application that people want, over 95% of the time people will give you valid email addresses. User are so much more valuable if you can market to them over time. It is very difficult to do this without at least an email address. Of course people can get disposable email accounts, this is just stating the obvious but still does not help at all in suggesting a better alternative for primary identity.
- notauser 18y agoI fall into the 5%. If it's something I really want to try... I'll look harder for a temp e-mail domain that you haven't blocked yet. New ones spring up every day. Why make it harder for me, as you are just pissing me off? If I like it I'll give you my real details, but the Internet is full of spammers and crooks and by default it seems prudent to assume that all websites are run by those types until proven otherwise.
- sanj 18y agoI wonder if there is a market for providing real, verified identities. Not requiring them, mind you, but streamlining things if you provide it: like the Clear security program in airports that lets you skip the lines.
- vyrotek 18y agoEven if a service existed that would manage your online identity, how would you prove at you are yourself everytime you sign in? I think thats the biggest problem right now. Another problem is the second someone gains access to your 'online identity' they now have access to everything else that was also linked using this identity. So maybe its not a good idea to have a central identity manager. Maybe we just need to be researching how do we prove that you are indeed YOU when you visit a site again and not worry about figuring out if you are you AND the same person on x,y,z sites.
- KevinMS 18y agoAlmost every email address carries an implicit username/password as well as a degree of identity provided by dns services (where the email goes) So thats not bad proof that the person that recieves an email to that address will receive the next one, and thats where all the login info is passed around. Mailinator however breaks all this, you can use any email address you want, including one that somebody else is using. Maybe this blog is a little biased?