[OpenID] Is OpenID truly user-centric and OP-independent? (WAS: Bug in OpenID RP implementations)

Peter Williams pwilliams at rapattoni.com
Wed Jan 14 13:51:57 UTC 2009


Add a plural s to the word identity.

IN policy language, the goal is surely not attaining "independence" from the communications infrastructure; but achieving "autonomy".

This is nicely seen in the plaxo model for building RPs, where you can bind n openids to the plaxo account. As a user, you can invoke any one of these identification paths. If flicker suspends your account (which they are want to do), there is no downside to you at Plaxo. Survivability is built in, with automatic, dynamic re-routing around the congestion point.


From: general-bounces at openid.net [mailto:general-bounces at openid.net] On Behalf Of Andrew Arnott
Sent: Wednesday, January 14, 2009 5:35 AM
To: Martin Atkins

In fact, I've become convinced that there is no way to allow a user to maintain his own OpenID identity independent of any OP or ISP given the profile of a common Internet user today.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-general/attachments/20090114/237dccc3/attachment-0002.htm>


More information about the general mailing list