GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Rich Felker (dalias@hachyderm.io)'s status on Wednesday, 19-Nov-2025 23:40:59 JST Rich Felker Rich Felker

    Folks don't apprentice what an amazing thing OpenID was, and what a monstrous act of vandalism Google's destruction of it was.

    You could literally put up a minimal site on your own domain with whatever authentication method you prefer, and use that URL as your identity to login to any site supporting OpenID correctly.

    No need to use your identity on some big social media site they trusted and offered as a login option. No need to risk compromise of access to those accounts like with OAuth.

    Just your own identity you really own, and no password hell.

    In conversation about 11 months ago from hachyderm.io permalink

    Attachments


    • Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Thursday, 20-Nov-2025 00:45:09 JST Rich Felker Rich Felker
      in reply to
      • soc

      @soc This was a long time ago. They just stopped supporting it and declared it deprecated in favor of the awful OAuth thing they replaced it with, that had none of the good properties of OpenID and lots of new bad properties.

      In conversation about 11 months ago permalink
    • Embed this notice
      soc (soc@chaos.social)'s status on Thursday, 20-Nov-2025 00:45:12 JST soc soc
      in reply to

      @dalias What did they do?

      Was it telling Mozilla to shut down Persona, or did I mix things up?

      In conversation about 11 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Thursday, 20-Nov-2025 00:46:41 JST Rich Felker Rich Felker
      in reply to
      • Arazil

      @arazil "OpenID Connect" isn't OpenID but part of the awful stuff Google & friends used to destroy OpenID.

      In conversation about 11 months ago permalink
    • Embed this notice
      Arazil (arazil@elvenstar.cafe)'s status on Thursday, 20-Nov-2025 00:46:51 JST Arazil Arazil
      in reply to

      @dalias The OAuth and the OpenID Connect standards always seemed like overengineered solutions that were designed to ensure a steady stream of business to "authentication experts." 🤦

      In conversation about 11 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Thursday, 20-Nov-2025 00:52:20 JST Rich Felker Rich Felker
      in reply to
      • Dan Lyke

      @danlyke The magic of OpenID wasn't that it was better than other identity systems, but that it was web-based and worked with a URL as the identity, so that any web-based service could use any identity provider *chosen by the user*.

      In conversation about 11 months ago permalink
    • Embed this notice
      Dan Lyke (danlyke@researchbuzz.masto.host)'s status on Thursday, 20-Nov-2025 00:52:22 JST Dan Lyke Dan Lyke
      in reply to

      @dalias yeah, except... I did the second implementation of LID, and a reference implementation of YADIS. When OpenID was happening, I said "just give me one feature: pass me a display name".

      By the time all of the rest of the cruft got added, that had disappeared, and in the 99% use case (blog and forum comments) OpenID was less convenient.

      Banks were never gonna use it, for the same reasons Passkeys are locked to vendors.

      In conversation about 11 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Thursday, 20-Nov-2025 01:10:22 JST Rich Felker Rich Felker
      in reply to
      • Dan Lyke

      @danlyke We should have seen that they didn't *want* to accept it, but we should have forced them to accept it. They should not get a say.

      In conversation about 11 months ago permalink
    • Embed this notice
      Dan Lyke (danlyke@researchbuzz.masto.host)'s status on Thursday, 20-Nov-2025 01:10:23 JST Dan Lyke Dan Lyke
      in reply to

      @dalias I don't think Google destroyed OpenID, I think it was destroyed by its own standards process that elevated all sorts of wackiness over "what is the actual problem that this is supposed to solve?".

      But we also all should have seen that identifiers that the end user controls the access to was never going to be acceptable to relying parties that needed complex standards for the security of that identifier.

      In conversation about 11 months ago permalink
    • Embed this notice
      Dan Lyke (danlyke@researchbuzz.masto.host)'s status on Thursday, 20-Nov-2025 01:10:25 JST Dan Lyke Dan Lyke
      in reply to

      @dalias yeah, but without passing through a screen name, it was less convenient to use than passwords.

      LID (which preceded OpenID) had all of that and more, but that data got dropped in a byzantine standards process that destroyed the necessary functionality to make it convenient.

      Which is why I implemented LID on my blog, and a YADIS (part of OpenID) reference (for Verisign), but when OpenID came around I said "meh, not gonna bother".

      In conversation about 11 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Thursday, 20-Nov-2025 01:11:41 JST Rich Felker Rich Felker
      in reply to
      • Dan Lyke

      @danlyke Strongly disagree about "less convenient than passwords". You didn't need any secret except the browser's management of session cookies. All you needed to log in anywhere was the non-secret URL.

      In conversation about 11 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Thursday, 20-Nov-2025 01:12:12 JST Rich Felker Rich Felker
      in reply to
      • tanavit

      @tanavit I don't have a link handy and wasn't close enough to the technical details to recall, but basically it was just https interactions whereby site A could send you to a URL (representing an identity) on site B, and have site B send you back to site A with validation that the browser session is considered by site B to be validated as that identity.

      In conversation about 11 months ago permalink
    • Embed this notice
      tanavit (tanavit@toot.aquilenet.fr)'s status on Thursday, 20-Nov-2025 01:12:14 JST tanavit tanavit
      in reply to

      @dalias

      Interesting.

      I have a micro-web site (100 Mo) associated to my personnal domain name, provided by the registrar.

      Would it be usable for that ?

      If yes, could you please provide me a link to the procedure ?

      A simple one if possible because I learnt computer science with punched card.

      In conversation about 11 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Thursday, 20-Nov-2025 01:45:41 JST Rich Felker Rich Felker
      in reply to
      • jer

      @jerrej Thanks. 😂 Looks like I mistapped the adjacent completion-suggestion on my phone keyboard.

      In conversation about 11 months ago permalink
    • Embed this notice
      jer (jerrej@mastodon.social)'s status on Thursday, 20-Nov-2025 01:45:42 JST jer jer
      in reply to

      @dalias

      I can barely
      a p p r e n t i c e
      it now!

      In conversation about 11 months ago permalink
    • Embed this notice
      groxx (groxx@hachyderm.io)'s status on Thursday, 20-Nov-2025 01:45:43 JST groxx groxx
      in reply to
      • Dan Lyke

      @dalias @danlyke +1, a new signup could very easily be just "click or enter your provider" -> approve -> fill in the rest of the account like normal.

      or maybe don't require all that up front because it isn't necessary. let people in, and let them change their name if they stay.

      In conversation about 11 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Thursday, 20-Nov-2025 01:48:55 JST Rich Felker Rich Felker
      in reply to
      • Dan Lyke

      @danlyke I dunno, I never had filling in a screen name as a requirement for identity. I'm fine with having a different visible identity I pick on each site when getting started on it or that I can change later as needed. I just don't want to need per-site credentials that they're going to leak in a breach and force me to update, or for the site to be able to force me to re-authenticate every day or whatever bs.

      In conversation about 11 months ago permalink
    • Embed this notice
      Dan Lyke (danlyke@researchbuzz.masto.host)'s status on Thursday, 20-Nov-2025 01:48:56 JST Dan Lyke Dan Lyke
      in reply to

      @dalias I mean... I love the sentiment, but how?

      I suspect that bitrot has removed the ability of my blog to be a LID relying party, or to use my own URL as a LID identifier, but if there's a movement out there of people who are using their URLs as identifiers that passes a screen name, I'd consider resurrecting those capabilities. But my blog is also down from ~1,500 daily readers to ~15 these days.

      And forums are kinda over and bloggers are just installing Wordpress and carrying on...

      In conversation about 11 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Thursday, 20-Nov-2025 01:52:09 JST Rich Felker Rich Felker
      in reply to
      • Dan Lyke

      @danlyke If you own the domain name, you don't have to host it yourself. You have the freedom to move between providers whenever you like.

      In conversation about 11 months ago permalink
    • Embed this notice
      Dan Lyke (danlyke@researchbuzz.masto.host)'s status on Thursday, 20-Nov-2025 01:52:10 JST Dan Lyke Dan Lyke
      in reply to

      @dalias I mean, I hear ya, but until we have some sort of platform that normal people can run at home, or that they have a strong reason to pay a few bucks a month to a provider for (and there's a reason for diversity of providers), I believe that we'd see the same consolidation of providers that we've already seen. Whether that was Verisign (which was half-heartedly trying to be) or Google is a toss-up.

      And re-auth is a matter of letting autofill happen and clicking go...

      In conversation about 11 months ago permalink
    • Embed this notice
      Martin Hamilton (m@martinh.net)'s status on Thursday, 20-Nov-2025 05:33:55 JST Martin Hamilton Martin Hamilton
      in reply to

      @dalias See also, OAuth 2.0 and the Road To Hell - https://web.archive.org/web/20130325140509/http://hueniverse.com/2012/07/oauth-2-0-and-the-road-to-hell/

      In conversation about 11 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: web.archive.org
        OAuth 2.0 and the Road to Hell
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Thursday, 20-Nov-2025 07:29:06 JST Rich Felker Rich Felker
      in reply to
      • Chris A Moody

      @chrisamoody It's a social problem: there's no adoption because it's deemed deprecated. No sites offer login via it. No providers provide it.

      In conversation about 11 months ago permalink
    • Embed this notice
      Chris A Moody (chrisamoody@podvibes.co)'s status on Thursday, 20-Nov-2025 07:29:07 JST Chris A Moody Chris A Moody
      in reply to

      @dalias is that no longer possible?

      In conversation about 11 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Friday, 21-Nov-2025 07:11:49 JST Rich Felker Rich Felker
      in reply to
      • Olivier Navas

      @oliviernavas Yes, but you have the ability to choose one you trust rather than being forced to use one of the big 3 extremely untrustworthy ones a site offers you. Or to even run your own.

      Any kind of third party authentication like this is a bad idea for the most important root-of-trust type accounts you really care about, but it's perfect for the problem of "every random shopping site, forum, product support site, etc. requires me to make an account".

      In conversation about 11 months ago permalink
    • Embed this notice
      Olivier Navas (oliviernavas@mastodon.libretic.fr)'s status on Friday, 21-Nov-2025 07:11:52 JST Olivier Navas Olivier Navas
      in reply to

      @dalias
      Though confortable, Openid and other centralized authentication ssrvices suffer the same caveat : you have to trust those who run the authentication service, since they have the power to impersonate your identity in any web site you can log in via their authentication service.
      If you accept to "sign in with with Google" to create an account in any website, then google may log in this web site with your identity and you can't know if they do.

      In conversation about 11 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.