[OpenID] OpenID and SSO

Hans Granqvist hans at granqvist.com
Tue Jul 1 09:09:18 UTC 2008


>>"Click to proceed", yes,
>
> There shouldn't even be that, though. Just go to the site and see the
> page. No matter how much you abstract the process of authenticating,
> if they have to take steps to have the service recognize them then
> it's a login.

The entire idea of logging in is a bit of an anachronism. :)

The user should offer to automatically identify and authenticate, and
the RP acts on the credentials if it wants to.

There seems to be a way to do this with OpenID. You need to tweak it
just a bit. I wrote up my thoughts about this a while back:

http://commented.org/blog/2008/1/3/continuous-openid.html

Hans



More information about the general mailing list