Showing posts with label OpenID. Show all posts
Showing posts with label OpenID. Show all posts

June 02, 2011

Apple's Missed Identity Play: "Sign In With Apple"

One of the greatest tug of wars amidst leading Web companies today is that for ownership of your identity, through your personal profile, or pushing you to "Sign in with" their credentials. You may sign in with Twitter, Facebook, Google or OpenID, and enable those services to certify it's you. One of the most successful tech companies out there who never comes up in this conversation is Apple, and it's incredible to think how easily they could have converted its army of Mac loyalists (myself included) to "Sign in With Mac", carrying the Apple flag forward as a badge of honor. More than a decade after getting my .Mac e-mail account (and later signing up my wife to do the same), I am splitting my email activity fifty-fifty with GMail and haven't gained much reason on Apple's side to double down on Cupertino.

When Steve Jobs unveiled iTools at MacWorld San Francisco in 2000, one of the primary offerings of the then-free product was an e-mail address ending in Mac.com. Fresh off success with the 1998 launch of iMac, and still a year away from the debut of the iPod, the company still had its most loyal followers "Thinking Different", and sending people messages with my Mac.com account was cool. It told everybody who would get a note from me that I had chosen Apple. Even when I would have to spell out my e-mail address on the phone, I'd always tell people... "M.A.C. As in Macintosh" in case it wasn't obvious.



Steve Jobs Introducing iTools (MWSF 2000)


But for a variety of reasons, the Mac.com address wasn't especially capitalized on. The service, initially free of charge, controversially converted to an annual paid service by 2002, alongside tools such as iDisk and .Mac home pages, and later rebranded as MobileMe in mid-2008, pushing people even further away from the allegiance with Apple but instead to theoretically more personal Me.com address.

When Apple initially made the move away from free Mac.com addresses for all, the message was that the free mail service was being abused, which no doubt cost them money and headaches - on top of costs for iDisk storage. But of course it also decimated the potential audience of users, most of whom already had free email accounts from somewhere else, be it Hotmail, Yahoo, Netscape or their ISP. Using a Mac.com account almost seems like an artifact unless you're a clear Apple loyalist.

In parallel, while Apple put MobileMe/iTools/Mac.com/whatever on the backburner, the company experienced incredible success with the iTunes ecosystem. Every iTunes customer has an Apple ID (or signs in with AOL), and has trusted Apple with their credit card details, as iTunes expanded from its initial offering of music to music videos, TV shows, movies, books, and of course, mobile applications for iPhone, iPod Touch and iPad. So Apple's effectively sitting on one of the most actively spending user databases in the world, but one that isn't leveraged elsewhere on the Web. There's no "Sign in With Apple" on major sites like the New York Times or CNN. There's no "Sign in With Apple" on Amazon.com or eBay.
iTunes Knows My Apple ID, but the Rest of the Web Doesn't

The fight for identity relevance between the major players of the Web, including Facebook, Google, Twitter, LinkedIn and others is critical, especially as signing in with one's identity brings additional privileges. Signing in with Facebook brings you your social graph and their history as you find what articles are popular. Signing in with Google is starting to bear fruit with their +1 initiative, but it's early days. Signing in with Twitter gives you the option to follow people on downstream sites if they have Twitter @Anywhere installed. But Apple's not playing in a place where they absolutely could have an impact.

Much has been made of Apple's perceived struggles when it comes to Web services. Those of us who have been watching Apple seemingly forever recall the false start of iReviews, where people could review Web sites on the Internet, the aborted launch of iCards for greeting cards through iTools, the lukewarm approach to .Mac Home pages, and the constant renaming of the email service. This is by no means discounting their fantastic success in hardware and some software, but they could be my identity. I, and many others like me, at one time and even today, want to tell the world we are Mac people, and we could sign in with Apple. But we aren't.

With iCloud to be presented at WWDC this next week, we're moving even further away from the naming of .Mac and what it meant to be a Mac person, especially if this product suite gets its fourth name in a decade or so. No doubt they'll keep shipping some great stuff, but even we Mac people are going to sign in with somebody else all around the Web.

November 02, 2010

OpenID Foundation Finally Grabs @openid Twitter Account

The OpenID protocol, aimed to authenticate users in a decentralized way, helping individuals own their own identities instead of requiring unique accounts for every service, has had something of an ironic issue for some time - given that the OpenID Foundation didn't actually own their own ID for one of the more popular discussion forums out there - Twitter. Today, this issue can be put to rest as Facebook employee and open source advocate David Recordon announced this afternoon they had gained access to the @openid account - giving folks a central place to keep tabs on updates to the protocol.

While OpenID at times has been pilloried for being obtuse, making logins more complicated rather than less, the project has helped push the concept of decentralized identities away from individual domains, including last week's news that Flickr had adopted the standard. The protocol, developed by now Google employee Brad Fitzpatrick in 2005, while at Six Apart, has seen deployment at a significant and influential number of Web services, and has corporate members including Facebook, Google, IBM, Microsoft, PayPal and Yahoo! on the foundation's board of directors. Ironically, nobody from Twitter is involved on the board.

The release of the account may or may not have been related to yesterday's OpenID OAuth Summit, held at Facebook headquarters, which saw stakeholders from a variety of tech companies, including Kevin Marks of BT, Chris Messina and Joseph Smarr of Google and Tantek Çelik, computer scientist at Microformats.org, participate to potentially discuss the differences between the at times complimentary but competing formats. Also, the Internet Identity Workshop (IIW) kicks off today in Mountain View, where many of these same folks will be participating.

Debate on OpenID versus OAuth continues to rage on the Web, of course. Recent entries include the Halloween post on Codebase: OpenID OR OAuth – That is the Question. Regardless of the eventual resolution, proposed as a new agreement called OpenID Connect, adoption of open standards and reduced complexity is a good thing. You can now follow OpenID's happenings at @openid.

March 04, 2010

Designing Buzz for a Google-Free World

If you haven't seen a lot of applications built in the last few weeks that leverage the Google Buzz API, it's because there aren't any. In fact, Google hasn't yet rolled out any API for Buzz. According to the company, this isn't due to any backroom dealings where they plan to introduce proprietary code and hooks that tie activity to their platform, but instead, because they wanted to be sure they could first build a product that in fullness leveraged open Web standards, and start with that foundation to deliver an interoperable system that could continue to function even if Google were to "disappear off the face of the earth".

In a presentation to the Silicon Valley Google Technology Users Group last night, held at the Google campus, DeWitt Clinton, a software engineer for the company, talked to developers and other tech enthusiasts about the company's API strategy and approach to Buzz, and explained that Buzz is designed not to increase lock-in to Google, but instead, to leverage open technologies that will let data flow to and from sites without central ownership. While a Buzz API will eventually be released, it will leverage the same open standards that power it today.

"The first principle of Buzz is that we can build this on protocols that are open and free, but not centralized," DeWitt said. "Can Google disappear off the face of the earth and Buzz still works? We need to make this data federated and distributed."

On the day Buzz launched, I referenced much of the foundation for Buzz in a quick article about the open tools and APIs that "make Buzz hum". But last night, DeWitt expanded that story to include 9 major open APIs, briefly outlined below.

1. Atom

DeWitt called Atom "the lingua franca of the programmable Web today", explaining that Atom contains entries that are "well structured", and include source entry, GUIDs that enable deduplication, and specification of the content type. He said, "You are able to pass rich data in that Atom feed in a way that is more specific than other feed types."

2. AtomPub

DeWitt said AtomPub "has become the most popular paradigm for restful APIs on the Web." AtomPub expanded the original Atom format to include the ability to both create and update feeds, not just passively read.

3. ActivityStreams

ActivityStreams essentially watch users' activity and can specify rich verbs and actions within those feeds. This enables feeds for all comments posted on Buzz, all likes, or even alerts that one person following you on Buzz also follows you on another network. DeWitt's examples hint at future developments for the platform, as these specific feeds are not yet clearly visible.

4. Pubsubhubbub

Much discussed here on the blog, Pubsubhubbub reduces the need for sites to poll for updates, and powers real-time updates between services. DeWitt reiterated "the hub is decided on by the publisher" and "there is nothing Google-specific about that.", saying that the infrastructure and plumbing for Buzz has been laid for the last few years. Pubsubhubbub has been pioneered by Brad Fitzpatrick and Brett Slatkin, both Google employees.

5. MediaRSS

Developed by Flickr, MediaRSS syndicates rich media through both RSS and atom feeds, creating a structured namespace inside RSS for content and a thumbnail. Buzz leverages MediaRSS, letting you pull rich content, like Flickr photos, into the platform. Of course, PicasaWeb, a Google property, also supports MediaRSS.

6. OAuth

The product of engineers from all corners, including Twitter, OAuth was engineered "to solve a vexing problem in the industry," Dewitt said, explaining OAuth prevents the need to ask users for their name and passwords on third party sites, acting as a delegated authorization protocol that gives permission to the application. Google Buzz, like Twitter, leverages OAuth to provide authenticated access to your data.

7. WebFinger

A new-age version of the old command-line prompted, text responding Finger protocol, WebFinger aims to be a way to get public information tied to an individual, through their identity, assigned to an e-mail address. "We want people to identify themselves, and we want people to discover people," DeWitt said.

WebFinger is similar to the strategy of OpenID, but OpenID hasn't had massive adoption by end-users who have found it unwieldy. WebFinger, aiming to be less arcane, enables the independent nature of Buzz, helping to federate the data and distribute it by domain, owned by the end user. DeWitt said, "The profile lookup and notification mechanism can be in the hands of the user being addressed."

8. Salmon

Still in earliest stages of development, Salmon is an extension or replacement for the old PingBack model that had blogs informing the other about references or links. This "flawed" model only provided minimal data, and could not be verified, letting me send PingBacks anywhere I wish if I chose. Salmon's goal is to leverage what's being called "Magic Signatures", signed with a public key to prove and verify linkage.

The first approach for Salmon will be to migrate comments from aggregators to originating posts, as covered a few times on this blog. But DeWitt said that "Likes" are similar activities that could flow back with Salmon, or be used to notify users of "following" or other activity. DeWitt forecast that sites like Blogger and StatusNet would rapidly adopt and federate Salmon to transmit data updates.

9. Portable Contacts

Simply described, Portable Contacts show your information and that of the friends who you follow, providing users a secure way to get access to address books and friends lists without having to request credentials or scrape the data.

DeWitt also noted XFN, the XHTML Friend Network, and FOAF (Friend Of a Friend) as being key contributors to the Buzz technology stack today, adding that he was "glad smart people were working on this ten years ago because we are all benefiting from it now."

DeWitt, on his Buzz feed, has been talking a lot about open standards and their importance to the Google team at large. See @Jesse Stay A few points of clarification to your most recent post [1], because I believe getting the details right matters. and "The thing I find most attractive about Google Buzz is its stated commitment to open standards.", as well as his first post from February 21st, which thanked the standard developers: Standing on the shoulders of giants—a look at the people behind the protocols behind Google Buzz:

Given Google's size, there is a good amount of distrust on the Web from people who think they own too much of your data, know too much about you, or have goals that run contrary to your own ideals on privacy, communication and sharing. Not even DeWitt's detailed presentations and explanations and promises of openness and data portability will convince everyone that they are on the right path. But I personally believe the frankness and detail that is being shown here is not just promising a strong future for this individual product (Buzz), but also in extending the groundwork done for the entire Web, for products and services we haven't even seen yet.

DeWitt adds: "All of these protocols are open. They are literally also all free. They are intended to be used by everybody, with or without Google being involved. You don't have to ask us if you can use Salmon or Pubsubhububb. We have a liberal and permissive patent license."

Is Google going away? Not today, and not this year. Is Buzz perfect? No. Of course not. Can it do all the things I can do on other sites, like FriendFeed? No. Not yet. But it seems that the Buzz team has opted to make tradeoffs that favor fast shipping and openness over completeness and individual features. And if you don't trust Google, it sounds like you can do something about it.

"We are pretty adamant about not building this on proprietary technology," DeWitt said last night. "If any of you feel that it is not going in the right direction, you have the power to change its direction and Google will not stop you."

You can find me on Buzz here and can follow DeWitt Clinton on Buzz here.

March 03, 2010

Open Identity Exchange Proposes Identity Trust Framework


Today, at the RSA conference, the Open Identity Exchange (OIX), aimed to increase trust in online identities, and backed by the OpenID and Information Card Foundations, announced its inception. In parallel, the U.S. Government is recognizing multiple technology companies as meeting federal standards for identity assurance, including Google, PayPal and Equifax, essentially securing users' ability to register and log in at federal Web sites with credentials from each of those services.

Goals of the Open Identity Exchange include building online users' trust and confidence in the exchange of identity credentials, standardizing these interactions and reducing hassle with online logins, registrations and purchases. As practically any Web user knows, frustrations with remembering scads of online user names and passwords, each corresponding with different sites with varying trust levels, can be a complete pain - no matter how much effort is taken to standardize, and the alternative, keeping one password for multiple services, which many do, has many more problems of its own.

OIX and its members are looking to reduce the problems with today's Web and move toward further highlighting open standards. Founding members of OIX, a non-profit corporation, include Booz Allen Hamilton, CA, Equifax, Google, PayPal, Verisign and Verizon.

The Often Complicated Process of Assessing Trusted Identity Online

Google's participation in the exchange follows the company's hirings of some of the more vocal advocates of OpenID and the open movement in general, including Chris Messina and Joseph Smarr. Earlier this week, a Google spokesperson wrote by e-mail that the inclusion of the company as part of OIX's launch should not come as much of a surprise.

"As you probably know, Google has long supported and contributed to the development of identity standards such as OpenID and OAuth, largely in order to increase online security by reducing the reliance on password use across websites." they wrote.

A white paper on the new OIX Web site, entitled "An Open Market Solution for Online Identity Assurance", explains how open identity technologies, including OpenID and Information Cards, serve to take closed user name and password systems deployed by most Web sites and expand them to accept identities issued by other parties, such as Google, PayPal and Equifax. Much of the paper, and OIX's mission, centers around the issues surrounding identity, including social, business, legal and emotional, such as trust.

This model of trust is explained in a second piece which defines a new "Open Identity Trust Framework (OITF)". The OITF paper shows holes in today's trust frameworks, and questions how people passing along personally identifiable information can be sure their data is protected with acceptable technical, operational and legal safeguards, while proposing a structured role for policymakers, providers, assessors, auditors, and dispute resolvers, to be sure that all participants are acting in a trusted manner. It may seem overly bureaucratic, but considering the Federal government needs to accept its findings, process is a good thing.

Lest you think this just yet another association or bureaucracy with talking heads looking to grease the skids of online growth, see the conclusion of the OITF model paper, where the authors explain a data utopia: "
Imagine 
that 
the 
OITF 
model
 takes
 off
 and
 identity 
aspects
 of 
all 
digital 
communications 
become
 reliant 
on 
this 
new
 layer 
of 
the
 Internet. 
Society 
could 
become
 dependent 
on 
this 
type 
of 
infrastructure 
for
collective 
action. 
The 
authors
 want
 to
 make
 it 
clear
 that 
trust 
frameworks
 for 
identity 
information 
portend 
to 
be
 so
 important 
for 
the
 future 
information 
society 
that
 they
 warrant 
extensive 
scrutiny, 
participation, 
and
feedback
 from
 a
 wide
 representation 
of 
stakeholders.
"

You can find out more on this new exchange at http://openidentityexchange.org. In addition, Google posted on the announcement on the company's online security blog: Federal Support for Federated Login

November 28, 2009

Keep A Close Eye on Chris Messina for the Web's Future

There are a few people in the Web whose work I can't help but watch with significant interest, as I know they are among the more visible people, working in teams with lesser-known colleagues, focusing their effort on moving the Web forward. From DeWitt Clinton, Brett Slatkin, Brad Fitzpatrick, Chris Saad, Dave Winer and David Recordon, to people like Jason Shellen, Chris Wetherell, Kevin Marks, Leah Culver, Paul Buchheit, Bret Taylor and Chris Messina, to name two handfuls, I can believe that these folks are working on those projects that are shaping the way we communicate and take in information. Messina, in particular, has penned a few blog posts over the last month that have had us thinking quite a bit - and it is safe to say he is on a roll.

Chris, in November alone, has proposed a new microsyntax for Twitter, forecast the death of the URL, and talked about how "designing for the gut" takes advantage of how the new social Web pushes people to overcome phobias and connect with people.

A well known advocate for open source, and one of the voices behind OAuth, which we discussed on Thursday, Messina has a history of thinking beyond where we are today and proposing concrete ideas that can be acted upon immediately. Those hashtags you see everywhere on Twitter these days, in practically every tech event and many trending topics? Chris proposed the idea in August of 2007. So it makes sense that he might have given a ton of thought to more uses for microsyntax, as he describes in his proposals for Twitter, as he suggests new items, including "/by", "/via" and "/cc". These suggestions are very clear and concise, the work of someone who has done his homework.

Chris' thoughts on the reduced focus on the URL too are salient, as we become more used to navigating in our browsers with pre-determined buttons and workflows. For me, URLs are often simply one-time visits before they are thrown into my RSS reader for safe-keeping, or they become bookmarks for later clicking. But the act of typing in a URL character by character seems antiquated. As he says, that's a gut feeling, and not one backed by much science on my part.

As I see it, the social Web changes the entire process of content discovery. Instead of portals, we are relying on mortals. Our trusted friends and experts bring us the best content from around the Web to us directly, via Facebook, Twitter, FriendFeed, and even that old tool... e-mail. We are trusting human filters to select the best from our RSS repositories and hand it off downstream. We pick a handful of trusted favorites, and make them the equivalent of our Yahoo!, or even Google.

Chris' post on the death of URLs paints a not so pretty picture of how, if left uncontrolled, a few powerful companies could help funnel the majority of users to predetermined sites, hand selected by them - much like the fears we once had about dominant portals. This could be done as we graduate from the traditional browser and link model to something else, where Web-connected applications pass us the requested data. He says, "We all know that the internet has won as the transport medium for all data — but the universal interface for interacting with the web? — well, that battle is just now getting underway."

One thing about the Web is that it is ever evolving. The places we choose to communicate are changing. The information we think provides value is changing. Our requirements for how quickly we need the data are changing. Chris and the many folks I mentioned in the first paragraph are among the first line of defense we have, trying to set standards and promote change for a world that feels right from both the gut and from the mind. You can find Chris' writing over at http://factoryjoe.com/blog/ or on Twitter at @chrismessina. While I assume many of you read him religiously, it's time the rest of you did as well.

November 18, 2009

Open Web Foundation Speeds Protocols' Legal Contracts



On Tuesday, the Open Web Foundation released an agreement aimed to speed new specifications' ability to be adopted by downstream users, with the intent of spreading open tools throughout the Web. Though occupying the always-complicated intersection of both the legal world and the tech world, the agreement is very interesting. The non-profit organization, featuring leading geeks from many of Silicon Valley's best known and most-respected companies, is hoping to promote data portability and open Web standards, no matter their source. Tuesday's agreement makes it easier for others to implement specifications without requiring lengthy bureaucratic legalities, and already features 10 major protocols and services as having signed up.

Among the services that have committed to using the new agreement include Yahoo!'s Media RSS standard, OAuth, Microsoft's WebSlice, and my often mentioned personal favorites, the PubSubHubbub and Salmon Protocols, being promoted by employees from Google.

As explained on the Yahoo! blog, on Facebook's Developers' blog and at Standards Law, services such as OpenID and OpenSocial were both forced to spend a great deal of effort working on legalities, taking their sharp engineering resources away from doing what they do best - code. The hope is that by setting a standard for approvals and access, much of these headaches can be eliminated.

The agreement itself is lightweight, compared to many legal tomes, and essentially mirrors standards set by Apache and Creative Commons, both of which have much history in the Web community. It covers how to handle attribution, that users can be trusted to leverage the work without fear of patent lawsuits, and that downstream users will not lay claims to others' efforts.

It could be yet another important step in making sure the Web is open, and that users can expect similar behavior and access capabilities from site to site and service to service. See also:
The Blurry Picture of Open APIs, Standards, Data Ownership
from October 29th.

November 11, 2009

Attacking the Web's Beverly Hills and Schenectady Problem

Not too long ago, every new site you joined on the Web forced you to provide a daunting array of details about you in order to join. Full pages of pull-down menus asking about your date of birth, your marital status, your home address and other information was standard. But over the last few years, with advents such as OpenID, OpenSocial, Facebook Connect, and more recently, Twitter OAuth, personal identities are becoming portable - letting you sign in with a dedicated login to a new site, and reducing your need to store yet another password.

Kevin Marks, vice president of Web services at BT, formerly of Google and Technorati, relayed at the Defrag Conference this afternoon that under the old way, companies, after accumulating a high number of users, would often find they had an extremely high number of users responding they lived in either Beverly Hills or Schenectady, New York. Why? Because they were saying their zip codes were either 90210 or 12345. They were lying - sick of answering page after page of personal data for yet another Web site.

In the years since, thanks to efforts like OpenSocial, we have seen the rise of Web standards that interoperate, letting you pass along your personal information and credentials to new sites without having to create yet another user name and password.

"Over the last two years, we worked out the sanitization of protocols, so it could fetch things from one site to another," Marks said. "In that time, OpenSocial is up to 1 billion users. There are sites all over the world who are using this."

Marks broke down the solution to the real identity problem into four pieces:
  • Me
  • My Friends
  • What We Do
  • The Flow
Tools like OpenID and WebFinger solve for "Me", Portable contacts, through the unification of the Vcard specification, solve for "My Friends", activity streams solve for "What We Do", and new protocols like AtomPub, PubSubHubbub and Salmon are solving the "Flow". As you know, I have been a big proponent of tools like PubSubHubbub, Salmon and tools like Facebook Connect and Twitter OAuth, as they not only pass along data between sites, but also make data pass between sites more quickly. And while they are causing what could be considered a revolution, it is happening through the simple evolution of activity that is already happening.

"All these standards are empirical standards," Marks said. "We first did this with microformats. We asked what people are doing already, and agreed we would do the same thing."

Now, if you do tell companies you live in Beverly HIlls or Schenectady, New York, there's a greater chance that you really do, and maybe we'll believe you.

December 10, 2008

Five Ways OpenID Can Be Embraced

By Mona Nomura of Pixel Bits (FriendFeed/Twitter)

Attempting to learn OpenID for the upteenth time, I ended right where I started: Confused. So I reached out to the community for help and received tremendous feedback that helped me better understand what OpenID is about. People left thoughtful, thorough comments on how to actually use OpenID and someone even left step by step directions. That made me realize: OpenID is still irrelevant for the average user.

However, the discussions held on FriendFeed and my personal blog opened an avenue to great (rational) exchanges of ideas, which got me thinking about how OpenID can be relevant to us.

  • Verifying needs to be simpler
    Technicalities aside, verifying, signing up, claiming, or whatever the "correct" term is, one thing is clear: The steps need to be simpler. Right now, the process is a nightmare requiring many steps. Users should be able to go to OpenID provider sites, and with one step - two at the most, be able to verify.
  • Email providers need to get involved
    With password storage managers the norm, URL log-ons should not be a burden - in theory. And that is the problem: in theory. Realistically, non-technical users are intimidated by using something other than their usernames, e-mails, or handles (nicknames) to log on. Since usernames and handles, without the URL, would be difficult to use as an OpenID log-on, Gmail, Hotmail, Yahoo et al joining the movement makes perfect sense.
  • Partner with consumer sites
    One word: incentive. Imagine if OpenID were to be accepted by Amazon, eBay, PayPal and financial institutions. Why wouldn't everyone use OpenID?
  • Update the site and Wiki with clearer instructions. I did not know that being logged into a provider site omits the verification process and log-on using OpenID without verification is possible - did you? That information is not readily available on the OpenID site, why? Or why isn't that on their Wiki? Almost every person with Internet access can go in an edit a Wiki. Will someone go in an update OpenID's Wiki page, please?
  • Create a Need
    Either I am missing something or it is still unclear why OpenID is so important - and most of it is due to all the technical jargon that is on the site. OpenID / OAuth, privacy, owning information, decentralizing, centralizing, user-centric, SSL, profiling, identity, and other stuff (for a lack of a better term) - it would be helpful if it were re-written in English anyone can understand.
If OpenID were to implement at least three of the above five, even my mother would be able to understand and use OpenID. Are you a part of the movement? If not, what would make you use OpenID? Or do you even care about OpenID?

Read more by Mona Nomura at Pixel Bits