[OpenID] Feedback requested: New OpenID RP login UX prototype

SitG Admin sysadmin at shadowsinthegarden.com
Fri Nov 20 00:02:27 UTC 2009


I haven't tried it yet, but since you seem to have the latest 
operable demo, I'll send to you this thought I had:

On prompting users to enter their OP (without said users necessarily 
understanding what an OP *is*), and also reinforcing/teaching the 
OpenID concept of "enter your password at an OP, never at any other 
site", what about offering a "multiple choice" / "fill in the blank" 
prompt?

"Enter your password only at this site:
(select any one)"

(Or, with MultiAuth - or, heck - just plain allowing for users not 
getting the "select any one" part - accepting multiple selections and 
then asking the user which of those possibilities to use. Separate 
test, if that works out: what effect is it to give them an option, 
after first selection, of going back to add even *more* OP's?)

Remind users to never enter their passwords at the OP; also, use that 
to help them remember which site they have an account at (and, while 
they might not understand what it *means* to "have an account", they 
will surely remember the password bit). This would fail for OP's that 
didn't warn their users about entering passwords elsewhere, but it's 
good security (even outside of OpenID), and I don't think the 
non-major OP's would be listed under "multiple choice" anyway.

-Shade


More information about the general mailing list