4 ms·
I'm using Google ID, but the technology that enables this is OpenID. It's just under the hood, which IMHO is where it should be. Most users have no idea what Op
by nir 17y ago
I'm using Google ID, but the technology that enables this is OpenID. It's just under the hood, which IMHO is where it should be. Most users have no idea what OpenID is, and are confused when they are asked for a URL in order to sign up.
Even for an OpenID-savvy user, why would it be frustrating or less secure to login via Google? If someone got my Gmail password, sites like mine would be the least of my worries..
- zargon 17y agoBecause I don't have a google account. But I do run my own openid provider.
- nir 17y agoI'd say that's an edge case, but still - sites that don't support OpenID would require you to create login. This method basically asks you to create that login with Google instead, is more secure than most of these sites.
- djcapelis 17y agoBecause my preferred openid provider uses client-side SSL certs to authenticate me, google doesn't. Part of the point of openid is it allows me to implement security procedures you haven't thought of without making me beg every site I use to do things the way I want.