Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It provides a canonical identifier for your account without compromising your identity to BrowserID-enabled services. The OpenID spec divulges who you are.


The OpenID spec divulges who you are.

How so? As far as I know, the only mandatory information is the OpenID identifier (the URL you need to input to authenticate). While more information can be exchanged, that's completely optional and up to the user. For example, MyOpenID always asks what "persona" - if any - you want to send when you authenticate.

BrowserID is no better: you need to input your email address.


The OpenID identifier can act as a relational key across services.


So can the email address in BrowserID, or the username in the typical user/pass combination. If you don't want to be connected, use different IDs for different services. Nothing in OpenID prevents a person from having multiple identifiers; in fact, Gmail generates different identifiers for each domain you authenticate on: http://blog.stackoverflow.com/2009/04/googles-openids-are-un...


How does it compare to Microsoft Passport?

How does it compare to client-side certificates?


It's decentralized and the UX is usable, respectively.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: