Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Google's Next Move in Telecomm | Main | Controlling Spyware: Tips and Techniques »

Dated Assumptions about "Owning" Users Stymy OpenID

With over 11,000 sites now accepting OpenID, how come Google, Microsoft, Yahoo and AOL have limited or no support for using OpenIDs at their own sites. Why is that? Michael Arrington partially answers the question in a recent TechCrunch post. There is more to the story and it has to do with an out dated assumption about "owning" a user on the Internet.

Arrington says:


Putting my conspiracy theory hat on, it looks to me like these companies want all the positive press that comes from adopting this open standard, but none of the downside. By becoming Issuing parties, AOL and Yahoo hope to see their users logging in all over the Internet with those credentials. But they don't accept IDs from anywhere else, so anyone that uses their services has to create new credentials with them. It's all gain, no pain.


Jason Kolb
adds:

Accepting them means that you're conceding that the users of your application have a home somewhere else and you're just letting them visit.

The problem for the Big 4 is that is that "having a home" or "owning" a user is as outdated an idea as possible with the Internet. Verisign is no more my "home" than any other site even though they provide my OpenID credentials. A home page is a home in name only. Home for Internet users is their bookmarks, del.icio.us tags, search toolbar and all the other tools we pull together in our browsers. I can use Google for searching and email, Yahoo for maps and movies and Microsoft for travel and am no more at home at one place or the other.

In time the Big 4 will realize that chasing the fiction of the "user home" does not out weigh the opportunity loss of adopting OpenID and helping to continue to improve it. (For more on OpenID see OpenID: Pros and Cons in the Messaging and Web Security Digital Library).

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/681

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net