6 ms·
Yes: Don't force me to log in with facebook. No: Don't force me to make another fucking password. I have a whole shitload of passwords. I use an independent (
by binaryfinery 16y ago
Yes: Don't force me to log in with facebook.
No: Don't force me to make another fucking password.
I have a whole shitload of passwords. I use an independent (not in the browser) password tool. I'd really like to be able to generate a password and login automatically: i.e. for my tool and the website to automatically hook up.
Oh, yeah that's called OpenID: http://openid.net/get-an-openid/ http://openid.net/get-an-openid/
And no jokes about my tool please.
- StavrosK 16y agoThe only thing I wish for nowadays is for the public to gain a better understanding of OpenID so we can start using it on every site. It's the best thing to ever come out.
- xiongchiamiov 16y agoIt became significantly easier when Google (and Yahoo!, and MySpace) became OpenID providers. If you do something like StackOverflow does (click the Google icon to login with Google), then it's pretty low-effort to use.
- StavrosK 16y agoAh, that's true. It's a bit odd to use a dedicated icon to log in to something that is exactly the same as the more general option you offer, but the average user won't know that, so it makes sense. Do you know the endpoint for Google? I didn't know they supported it natively.
- xiongchiamiov 16y agohttps://www.google.com/accounts/o8/id https://www.google.com/accounts/o8/id
- StavrosK 16y agoThank you.
- joeyh 16y agoAnd there is a free version of the login widget StackOverflow uses. (Not quite the same code base, but more or less identical.) At http://code.google.com/p/openid-selector/ http://code.google.com/p/openid-selector/ When I deployed a version of that on my sites, I got lots more causual users posting comments, etc. Most of them just click on google.
- jasonkester 16y agoI won't implement OpenID for any site where I have a say. It needs to die so that something good can step into its place. If you have a site that requires OpenID, I won't use it for the same reason I won't use your site that requires Facebook. If you're going to implement it, make sure you also implement a standard user/pass registration or you'll lose a lot potential users (as in most of them).
- jdavid 16y agoWhat Problem do you have with OpenIDv2a + OAuth?
- generalk 16y agoSo I start a SaaS business and put "Please login with your OpenIDv2a+OAuth compatible login below." prominently on my front page. And then I have no users because nobody knows what that means.
- jarek 16y agoYou should probably put "Please login with your Facebook or Gmail account below" on your front page instead. Modify the services named based on expected clients. Choose one or more from the following: AOL, BBC, Facebook, Google, IBM, MySpace, Orange, PayPal, VeriSign, LiveJournal, Yandex, Ustream and Yahoo!. * On the sign-up page, put in smaller text "You can sign up/log in with any compatible OpenID service" for the technically savvy users, if you expect any at all. Don't straw man. * list copied from Wikipedia.
- bugsy 16y agoA problem with asking someone for their gmail password to sign into malwarenet.org is that it seems very suspicious. Why does malwarenet.org want my password? I bet I can guess - they want to steal my email, find my bank account numbers and identity fraud me. Oh, it doesn't work that way, right right, but how can any one without exceptional technical skills know that for sure? Lots of site spoofing out there. Hell, opendns is giving me a spoofed ip address for google right now. What is that about, I thought they were secure. What else on my DNS service has been hacked? Bank sites? Probably.