5 ms·
If you use a Yahoo/Google OpenID, the user doesn't need to know the identifier (or anything else for that matter) - you use a fixed URL (https://www.google.com/
by nir 17y ago
If you use a Yahoo/Google OpenID, the user doesn't need to know the identifier (or anything else for that matter) - you use a fixed URL (https://www.google.com/accounts/o8/id https://www.google.com/accounts/o8/id for Google), Google/Yahoo handles the sign in and sends them back.
I'm currently building an app that relies solely on OpenID for user auth. I chose to enable only these sites, so that (a) users are not required to supply/complete a URL, and (b) there isn't the "which OpenID did I use this site?" when a user returns to it after a while.
- malvim 17y agoActually, google has just begun to use your profile URL, using that 'Vanity URL' business. If you turn vanity urls on, your OpenID identifier will be like so: http://google.com/profiles/<your-google-login> http://google.com/profiles/<your-google-login>; I have used it and logged on to stackoverflow.com. It does work.
- nir 17y agoYou're right - but for my apps I don't think I'd support these, for the same reasons.
- djcapelis 17y agoYou're not using OpenID if you do this, you're using Google's id. It's fine if that's what you expose by default, but you really do need to give the user a checkbox or something so they can input their own if they have one. I have an OpenID I use everywhere, if I come to one of your sites and end up using my google ID instead it will cause me nothing but frustration and end up being less secure. In fact I'd probably not login to your site because of this if I didn't have a compelling reason to do so.
- yangman 17y agoThis is still OpenID. Google uses a singular URL for all identities that OpenID consumers use to discover the true user identity, which is unique per user per consumer domain.
- zargon 17y agoIf it only accepts google logins, then it doesn't matter if google is using openid as the mechanism -- you can't say you use openid logins. It's like if I said that my application supports CSV, but you have to provide it as an Excel file.
- nir 17y agoI'm using Google ID, but the technology that enables this is OpenID. It's just under the hood, which IMHO is where it should be. Most users have no idea what OpenID is, and are confused when they are asked for a URL in order to sign up. Even for an OpenID-savvy user, why would it be frustrating or less secure to login via Google? If someone got my Gmail password, sites like mine would be the least of my worries..
- zargon 17y agoBecause I don't have a google account. But I do run my own openid provider.
- nir 17y agoI'd say that's an edge case, but still - sites that don't support OpenID would require you to create login. This method basically asks you to create that login with Google instead, is more secure than most of these sites.
- djcapelis 17y agoBecause my preferred openid provider uses client-side SSL certs to authenticate me, google doesn't. Part of the point of openid is it allows me to implement security procedures you haven't thought of without making me beg every site I use to do things the way I want.
- shib71 17y agoWe've done that by using RPX (https://rpxnow.com/ https://rpxnow.com/). It's awesome - users with Google/Facebook/Twitter/Yahoo accounts don't have to remember their URL and more savy users can use whatever OpenID they want.
- nir 17y agoFirst time I hear about RPX - looks interesting.