I'm surprised no one has brought this up, but remember that having people log into RPs using their email address is giving away a very personal bit of information that I'd like to hide more than give away. On another thread concern was expressed over allowing OpenID to accidentally reveal the preferred language of a user. Well to me I think email address is far more concerning. <div>
<br></div><div>Of course an RP may want an email address and AX or SREG is a great way to get it, but that's always the user's decision while at the OP or later at the RP, and isn't a mandatory step to even initiate the login process.<br>
<br><div class="gmail_quote">On Thu, Oct 30, 2008 at 3:00 AM, Ben Laurie <span dir="ltr"><<a href="mailto:benl@google.com">benl@google.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;">
<div class="Ih2E3d">On Thu, Oct 30, 2008 at 7:07 AM, Chris Messina <<a href="mailto:chris.messina@gmail.com">chris.messina@gmail.com</a>> wrote:<br>
> On Thu, Oct 30, 2008 at 4:14 PM, David Recordon <<a href="mailto:drecordon@sixapart.com">drecordon@sixapart.com</a>> wrote:<br>
>> Can you use POBox.com with <a href="mailto:david@yahoo.com">david@yahoo.com</a>? For the added complexity I just<br>
>> don't think it's worth it considering you already can't delegate your email.<br>
>> If you control the domain then you can choose your Provider, otherwise<br>
>> you're at the mercy of who controls the domain. Don't like it, then don't<br>
>> use your Yahoo account as your OpenID. IMHO.<br>
>> --David<br>
><br>
> I'm coming around to this perspective.<br>
><br>
> While maximal flexibility would be ideal for "delegating email<br>
> addresses", I'm willing to compromise to find the simplest, easiest,<br>
> quickest and least costliest path to adoption.<br>
><br>
> While the mapping concept is a worthwhile one technologically, I think<br>
> that trying to push all the freedoms that you get with URL-based<br>
> OpenIDs into email addresses could be a losing proposition.<br>
><br>
> If we can support email addresses with maximal flexibility with<br>
> minimal costs, great, but from what I've seen of how changes actually<br>
> get made, changing the OpenID spec as little as possible is the best<br>
> way forward.<br>
><br>
> It sounds like the OpenID.identity approach might be the best way to<br>
> make this happen, pronto, without mucking with DNS and so on.<br>
<br>
</div>What is "the OpenID.identity approach"?<br>
<div class="Ih2E3d"><br>
> Remember, email addresses today aren't really explicitly supported by<br>
> the spec; the goal should be to make that a possibility with as little<br>
> effort as possible.<br>
<br>
</div>It seems to me that there's a couple of things to consider:<br>
<br>
1. Often the RP actually wants an email address, because it wants to<br>
be able to communicate with the user. This can be solved with AX, of<br>
course _but_ I suspect users will be confused by having to give an<br>
"email address" that isn't actually their email address.<br>
<br>
2. It seems that its possible to do a pretty good job with just the<br>
domain - the email address is just a way to get the user to tell you<br>
what the domain is so discovery can start.<br>
<br>
Obviously discovery is a prerequisite, though.<br>
<div><div></div><div class="Wj3C7c"><br>
><br>
> Chris<br>
><br>
> --<br>
> Chris Messina<br>
> Citizen-Participant &<br>
> Open Technology Advocate-at-Large<br>
> <a href="http://factoryjoe.com" target="_blank">factoryjoe.com</a> # <a href="http://diso-project.org" target="_blank">diso-project.org</a><br>
> <a href="http://citizenagency.com" target="_blank">citizenagency.com</a> # <a href="http://vidoop.com" target="_blank">vidoop.com</a><br>
> This email is: [ ] bloggable [X] ask first [ ] private<br>
> _______________________________________________<br>
> general mailing list<br>
> <a href="mailto:general@openid.net">general@openid.net</a><br>
> <a href="http://openid.net/mailman/listinfo/general" target="_blank">http://openid.net/mailman/listinfo/general</a><br>
><br>
_______________________________________________<br>
general mailing list<br>
<a href="mailto:general@openid.net">general@openid.net</a><br>
<a href="http://openid.net/mailman/listinfo/general" target="_blank">http://openid.net/mailman/listinfo/general</a><br>
</div></div></blockquote></div><br></div>