The Killer App for OpenID

Openid-2
One of the biggest challenges facing OpenID is it’s a solution (universal identity management) looking for a problem to solve.

Sure, it’s a pain having to remember different usernames and passwords (unless you lazily use the same ones for everything) but most people don’t see it as a huge issue, which means OpenID has failed to gain much traction. And to be frank, that won’t change much even with major players such as Google, Yahoo and AOL starting to climb on the OpenID bandwagon recently.

All, however, is not lost because there is a “killer app” that could propel OpenID from a curiosity into a mainstream tool.

The genesis for this optimistic outlook is PageOnce, which I discovered yesterday on TechCrunch. PageOnce is a personal application portal where you can access all your online accounts (e.g. GMail, Facebook, LinkedIn, Visa, MySpace, Citibank, Netflix, etc.). This is a concept that, in theory, sounds great because it would eliminate the need to visit multiple sites at a time when we’re using an increasing number of online services.

The biggest hurdle is you have to provide PageOnce (or any other personal app portal) with all your username and password information. This makes me uncomfortable because it means you have to have complete faith in PageOnce’s security – something I think that many people would be loathe to do, especially with financial information.

This is where OpenID comes into play. Rather than giving PageOnce all your username/password information, you could use OpenID as a way to submit your information efficiently and securely. Of course, this is based on the assumption OpenID can evolve to address security issues such as attacks from phishers, as well as concerns about privacy.

Sure, there are a lot of “ifs” surrounding the emergence of personal portals and OpenID but if both ideas are going to gain any kind of traction with consumers, it would be a good idea if the players in both camps started working together to present a united solution.

More: Here’s a good video about digital identification from Sxip’s Dick Hardt, while MediaShift’s Mark Glaser has a lengthy post on how to protect your online privacy.

Technorati Tags: ,

This entry was posted in Web 2.0. Bookmark the permalink. Post a comment or leave a trackback: Trackback URL.

11 Comments

  1. Posted February 15, 2008 at 7:56 am | Permalink

    Mark, I agree. I have a beta account with PageOnce – and leaving aside it’s North American slant – and I have not really tried it out fully due to not having faith in security of the site. This isn’t a fault of theirs, but one of my not wanting to risk anything just for the sake of trying out the site fully.

  2. Posted February 15, 2008 at 8:01 am | Permalink

    would you use pageonce ??

    I mean you got your gmail account frozen (reset). The Ebay account setting changes recently correct ??

    So is openid, in your personal opinion mature enough to level all your personal info into one service provider ?

  3. Posted February 15, 2008 at 8:10 am | Permalink

    Pete,

    I wouldn’t use PageOnce if it meant handing over my username and password information. In theory, OpenID could (and I stress could) be a good tool to address this issue but admittedly it has a long way to go before I’ll really jump on the bandwagon.

  4. Posted February 15, 2008 at 8:17 am | Permalink

    It seems to me that OpenID suffers from even greater security risks than PageOnce does. Once somebody cracks your OpenID password, they have access to every website that supports it, even ones that you might have never visited.

  5. Posted February 15, 2008 at 10:20 am | Permalink

    You make an assumption in the first paragraph–”most people don’t see it as a huge issue”–that needs more attention. First, have you got any proof?

    More importantly, even if people don’t perceive it as a ‘huge issue’, that doesn’t meant that it’s not a problem worth solving.

  6. Posted February 15, 2008 at 10:30 am | Permalink

    Darren:

    Guilty as charged! Good points on both fronts.

    Mark

  7. Posted February 15, 2008 at 12:18 pm | Permalink

    Integrating the OpenID to PageOnce is a great idea.
    And adding a way to view your information for websites which support OpenID authentication instead of username and password is on our roadmap

  8. Posted February 15, 2008 at 12:24 pm | Permalink

    Guy:

    Glad you like the idea. :)

    To be honest, OpenID continues to struggle partly because it’s not even offered as an option many places, although that may be changing as companies such as Yahoo get on board. If people get exposed to it, try it and use it, then there will be a bigger community that can, hopefully, improve OpenID.

  9. Posted February 15, 2008 at 6:43 pm | Permalink

    For the application you are thinking of, what we should consider is OAuth (oauth.net) and not OpenID. Even though OpenID allows one to have a single “username” and “password” across multiple sites, you end up sharing the credential information potentially compromising security. On the other hand OAuth allows a user to get a more restrictive permission token from the contributing site and pass it on to the consuming site. The restriction could be on the scope of access and/or duration of validity etc. Additionally, use of OAuth does not require use of OpenID and so can be used immediately. You can read an explanation of OAuth from users’ perspective at http://www.hueniverse.com/hueniverse/2007/10/oauth-end-user-.html

  10. Posted February 16, 2008 at 6:51 am | Permalink

    Aswath,

    I’ll check out OAuth. Thanks, Mark

  11. Posted February 17, 2008 at 6:37 pm | Permalink

    Ken makes a good point that if a central OpenID username/password is compromised to an attacker, the attacker gain access to all of that user’s accounts.

    The team I work with has been working to solve this problem. Our implementation of OpenID binds a users openID to a security device, like a smart card or USB token, TrustBearer OpenID. So this removes the need for username/password altogether and improves account security.

2 Trackbacks

  1. [...] The Killer App for Open Id Added on 02/16/2008 at 12:48PM The Killer App for Open Id [...]

  2. [...] social networking by stevepepple on February 17th, 2008 There’s an interesting discussion on Mark Evan’s blog about the potential of a killer application for OpenID: One of the biggest challenges facing [...]

Post a Comment

Your email is never published nor shared. Required fields are marked *

*
*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

  • TwitterCounter for @markevans

  • How it works  |  Vision & Calls  |  Cost

    What's on

    Have you seen what you can get with BT's digital tv?

    © All Rights Reserved
    BT Vision and Calls

    Did you know that BT offers great deals in cheap mobile calls and cheap international phone calls? If you have a phone line with BT, come and see how we can reduce your bill of your home phone.


    Get one of our broadband telephone packages to get even more entertainment at a great value.

    How it works

    With BT Vision now you can enjoy Freeview digital tv channels, radio channels and a great range of on demand entertainment.

    Cost

    Get a deal at a great value with our digital tv packages. Visit our website to find out more.

    What you need

    BT Phone line

    BT Total Broadband

    A TV and aerial

    Freeview coverage

    Speed test  |  Availability  |  Support

    BT Total Broadband

    Want fast, broadband wireless internet? Get BT Total Broadband.

    Speed test

    If you are unsure of how fast your line is, have a broadband speed test. You just have to enter your telephone number or postcode below. You will need a minimum of 2MB speed to be able to get BT Vision.

    Enter phone number
    or postcode
    Availability

    Want to see check broadband availability in your local area? Enter your postcode in our broadband postcode checker below and find out what is available to you.

    Enter postcode
    Support

    BT offers great support with broadband services. Do you need broadband help? Contact us and we will be more than happy to help you.

  • Wikio - Top Blogs - Technology