<HTML>
<HEAD>
<TITLE>Re: [OpenID] Feedback from OpenID demo</TITLE>
</HEAD>
<BODY>
<FONT FACE="Calibri, Verdana, Helvetica, Arial"><SPAN STYLE='font-size:11pt'>That’s really good feedback, thanks for sending Bill.<BR>
<BR>
I just published a blog post exploring these issues. Bill already summarized the ideas, but for a flushed out description, check it out:<BR>
<BR>
<a href="http://www.sociallipstick.com/2009/05/logout-the-other-half-of-the-identity-equation/">http://www.sociallipstick.com/2009/05/logout-the-other-half-of-the-identity-equation/</a><BR>
<BR>
On 5/22/09 9:47 AM, "Bill Shupp" <<a href="hostmaster@shupp.org">hostmaster@shupp.org</a>> wrote:<BR>
<BR>
</SPAN></FONT><BLOCKQUOTE><FONT FACE="Calibri, Verdana, Helvetica, Arial"><SPAN STYLE='font-size:11pt'>I did a quick internal OpenID demo here at Digg yesterday, and thought <BR>
I'd share the feedback here.<BR>
<BR>
There were about 20 people there, of which maybe 3 had used OpenID. <BR>
Some people were not technical, though most were. Featured in the <BR>
demo were Plaxo and Facebook for RPs, and Google and MyOpenID as OPs. <BR>
The feedback was not terribly positive, and the criticisms focused on <BR>
two areas:<BR>
<BR>
1) Lack of Single Sign Out in the protocol<BR>
2) "Automatic Login", as implemented currently at Facebook<BR>
<BR>
Obviously, #2 really highlighted #1. People thought that login should <BR>
be an explicit action, not automatic. When discussing #1, I mentioned <BR>
an idea that Luke Shepard shared this week at IIW, of adding <BR>
"logout_setup" and "logout_immediate" to the protocol. The idea being <BR>
that if you click logout on the RP, it could send a "logout_setup" to <BR>
the OP, which would trigger a popup asking if you also want to logout <BR>
of the OP as well. This idea got a pretty favorable response, and <BR>
seemed to satisfy some of those concerned with the Single Sign Out <BR>
issue. "logout_immediate" could behave similar to <BR>
"checkid_immediate", where the logout is performed without user <BR>
interaction, and might be favored by higher value RPs like mint.com or <BR>
the like. Obviously, there's room for RP abuse here, though.<BR>
<BR>
Cheers,<BR>
<BR>
Bill Shupp<BR>
_______________________________________________<BR>
general mailing list<BR>
<a href="general@openid.net">general@openid.net</a><BR>
<a href="http://openid.net/mailman/listinfo/general">http://openid.net/mailman/listinfo/general</a><BR>
<BR>
</SPAN></FONT></BLOCKQUOTE>
</BODY>
</HTML>