Monday, June 08, 2009

About Email Addresses and OpenID

Out of the hundreds of millions of OpenID's in the wild today, 99% of them are provided for by Yahoo, Google, MySpace and AOL.

Three of them are email providers and your OpenID is tied to your email address. ie Opening and account at one of them gives you an email address and an OpenID. You can also create a Google account with a non Google email address. Again the OpenID is tied to an email address. So when you are logging in with any of these OpenID's you are in effect logging in with an email account.

This is also true in the case of MySpace even though it is not an email provider. When you login with your MySpace ID you are really logging in with your email address! The MySpace OpenID is also tied to your login email address.

In other words 99% of the OpenID's in the wild are really email addresses masquerading as OpenID's!

Why the need for this masquerading? Because OpenID does not support Email addresses as OpenID's.

And why doesn't OpenID support Email addresses as OpenID's? Given the facts above I cant think of a reason. Can you?

6 comments:

jk3us said...

How would that work? If I entered my email address on a website, how would it know where to send me to log in? Consider the user who uses a yahoo email address and has that address tied to their google and myspace accounts.

Also, on your 99% statistic, I bet if you looked at openid users (who actually log into other sites with their openid), you would not see that large a majority from those providers, you'd see more myopenid, claimid, etc.

jk3us said...

Also, I'd much rather give you, a site that I don't have any reason to trust, my website url rather than give you my email address for you to spam.

Santosh Rajan said...

The answers to your questions are here.
http://www.abstractioneer.org/2009/04/personal-web-discovery.html

Santosh Rajan said...

Your Comment "I bet if you looked at openid users (who actually log into other sites with their openid)".

As your comment suggests less than one per cent of the people who have OpenID's actually use their OpenID's.

An there in lies one the problems of OpenID. Users simple dont like OpenID. All the more reason to include email addresses as OpenID's.

As for your argument about spammers "the horse has bolted from the barn" as the article I have pointed to suggests.

qwp0 said...

OpenID manipulates URLs, that's the reason why e-mail addresses cannot be used instead. However, a few technologies are being developed to allow mapping of e-mail addresses to URLs. For instance, there is emailtoid.net which allows you to log in with your e-mail address to any EAUT-enabled website. Right now.

I recommend you contribute to one of the email-to-url projects instead of suggesting rewriting the OpenID spec from scratch.

> Users simple dont like OpenID.
And that's the reason why Google, Yahoo! and other big companies have implemented it, right? I have nothing to add, sorry.

Santosh Rajan said...

Indeed I am working on supporting email addresses as OpenID's by trying to contribute to the community effort.

As for all the big companies supporting OpenID, they are all supporting what is called directed identity where the user does not have to type his OpenID. To login he actually types his username or email address!

Post a Comment