[OpenID] Combining Google & Yahoo user experience research

John Panzer jpanzer at acm.org
Tue Oct 14 18:16:16 UTC 2008


Eric Sachs wrote:
> ...
>   And those UI guidelines are complete overkill for a website who is 
> willing to just use a single IDP and completely eliminate its own 
> legacy login system.
I think you're saying that an RP has the option of using the OpenID 
protocol, bound to a specific IDP, simply to avoid building its own 
login system.  I guess so, but in this case OpenID itself is overkill 
(and is an implementation detail -- SAML or OAuth or an IDP-specific 
protocol could solve the problem nearly as well).  I don't think the 
OpenID community should discourage this use of the protocol under the 
hood, but from a branding perspective I think it would be bad as well as 
confusing to users to have OpenID even mentioned.

John







More information about the general mailing list