<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>dekstop weblog : OpenID: Making Throw-Away Accounts Reusable Since 2005</title>
    <link>http://dekstop.de/weblog/2007/02/making_throwaway_accounts_reusable/</link>
    <description>Since there are so many announcements about OpenID these days I decided it&apos;s time to actually have a look at the OpenID 1.1 spec. Turns out it&apos;s a light and fairly quick read, and its authors paid delightful attention to some crucial details. I especially liked this: The main advantage ...</description>
    <dc:language>en-us</dc:language>
    <dc:rights>Copyright 2007 Martin Dittus</dc:rights>
    <lastBuildDate>Tue, 20 Feb 2007 23:59:09 GMT</lastBuildDate>
    <generator>MicroLinks 5.6 (dekstop.de)</generator>
    <managingEditor>public&#64;dekstop&#46;de</managingEditor>
    <webMaster>public&#64;dekstop&#46;de</webMaster>



    <item>
      <title>OpenID: Making Throw-Away Accounts Reusable Since 2005</title>
      <link>http://dekstop.de/weblog/2007/02/making_throwaway_accounts_reusable/</link> 
      <description><![CDATA[<p>Since there are so many announcements about <a href="http://openid.net/">OpenID</a> these days I decided it's time to actually have a look at the <a href="http://openid.net/specs/openid-authentication-1_1.html">OpenID 1.1 spec</a>. Turns out it's a light and fairly quick read, and its authors paid delightful attention to some crucial details.</p>

<p>I especially liked <a href="http://openid.net/specs/openid-authentication-1_1.html#delegating_authentication">this</a>:</p>

<blockquote>
<p>The main advantage of [OpenID's delegation mechanism] is that an End User can keep their Identifier over many years, even as services come and go; they'll just keep changing who they delegate to.</p>
</blockquote>

<p>And was impressed to see stuff like <a href="http://openid.net/specs/openid-authentication-1_1.html#anchor7">this</a> in the spec:</p>
<blockquote>
<p>It is RECOMMENDED that the form field [for the User's OpenID URL] be named "openid_url" so User-Agent's will auto-complete the End User's Identifier URL in the same way the eCommerce world tends to use conventions like "address1" and "address2".</p>
</blockquote>

<h3>Recycling Finally Makes Sense</h3>

<p>I guess I won't start using the same OpenID account for all my identification needs, even if it might sound convenient. The thought of having a single login for <em>everything</em> isn't very appealing -- because it easily allows tracking you across services (cf the ubiquitous session cookie).</p>

<p>Here's what's so cool about this: OpenID allows you to reach a middle ground where you can have a limited number of accounts for most of your Internet interactions, regardless of the number of services you actually make use of; and each account can become an island, for use within a certain context. Your blogging account. Your throwaway test account. Your Digg and Slashdot trolling account. Your porn account.</p>

<p>That's the one feature that makes OpenID interesting to me: As soon as a significant number of websites start acting as OpenID consumers (i.e., they let you login via an OpenID account you registered elsewhere) you gain control over the number of passwords you have to remember. No more bugmenot, or relying on your browser or KeyChain to remember passwords for you. You'll be able to memorize them all.</p> 

<p>Essentially, OpenID caters to our convenience while keeping us in control of our own privacy.</p> 

<p>And all with a very simple mechanism -- with a little discipline it should be possible to write, test and deploy a primitive OpenID provider in a couple of hours. So if you don't want to trust anyone with your passwords and browsing habits it's dead easy to roll your own identification service from scratch, or deploy an <a href="http://openid.net/wiki/index.php/Libraries">open source implementation</a>. And by the looks of things you're soon going to live in a world where your custom ID provider will work with all sites you care about.</p>

<p>Is there anything Brad Fitzpatrick can't <a href="http://brad.livejournal.com/tag/status">do</a>?</p>]]></description>
      <dc:creator>Martin Dittus</dc:creator>
      <category>a new world</category>
      <category>privacy</category>
      <category>web services</category>
      
      <guid isPermaLink="true">http://dekstop.de/weblog/2007/02/making_throwaway_accounts_reusable/</guid>
      <pubDate>Tue, 20 Feb 2007 23:59:09 GMT</pubDate>
    </item>
  </channel>
</rss>
