Last Thursday over 60 OpenID advocates met at Sears World Headquarters in Chicago for a full day of discussions on progress to date and future plans for OpenID deployment and utilization. There is a summary of the event on the OpenID Foundation wiki. See Twitter coverage of the event with the hash tag #openidux
Who Attended:
Companies represented included Sears, NPR, PBS, AARP, MTV, Fox News, Universal Music Group, Kodak, Tribune Interactive, White Pages, OpenTable, Scout24/Deutsche Telecom, GameStop, Bank of America, Yahoo, Google, AOL, Microsoft, PayPal, Facebook, JanRain, Exact Target, Ping Identity, and others.
Updates from the Identity Providers:
The session kicked off with presentations by Google (Joseph Smarr), Yahoo (Allen Tom), Microsoft (Angus Logan), Facebook (David Recordon), PayPal (Andrew Nash), and AOL (George Fletcher). Copies of many of the presentations are available on the OpenID Foundation wiki. Some key highlights from these sessions:
- Google is working on providing more API access to its OpenID Services, including Buzz, Portable Contacts, Activity Streams, OAuth WRAP, etc. Their OpenID service will also be certified by the newly formed Open Identity Exchange (OIX) for use on federal government websites.
- Yahoo has deployed an OpenID/OAuth hybrid deployment model for access control to Yahoo data and APIs including Contacts (address book), Yahoo Mail, and Yahoo Updates (Activity Streams). Allen went through a case study of how Yahoo OpenID and OAuth services are being used on Huffington Post and the many benefits to users of this experience. Allen described how Yahoo Updates allows posting back to 300M Yahoo homepage, 300M Yahoo Mail, 90M Yahoo Messenger, and 40M MyYahoo accounts.
- Microsoft reported that they have over 500 million active users across Windows LiveID, Bing, Xbox, HotMail, Messenger, MSN, and Office. They continue to making process in providing 'standards' based access to user data and services. Angus described how Windows LiveID is currently being used across Windows Live and Xbox. He also discussed MS' active involvement in OAuth/WRAP, Portable Contacts, OWF, and Activity Stream initiatives.
- PayPal described their work with the federal government in launching an OpenID service for federal websites. Consumer policy and permissioning mechanism based on the UMA model will be integrated into the IDP operation. They are currently working with a limited number of "white listed" commercial websites for deployment of their OpenID services. Organizations wishing to discuss acceptance of PayPal OpenID on their websites are encouraged to contact Andrew Nash.
- Facebook discussed the widespread adoption of Facebook Connect and how they have been accepting OpenID for logins for the past year. They continued to share user experience learnings from building Connect and stressed the importance of developer simplicity around OpenID this year. David demonstrated a killer multimedia demo where a video feed dynamically consumed and displayed data from Facebook profiles via Connect.
- AOL reported that they will be upgrading their OpenID Provider service to V2.0 within the next few weeks. George discussed that they are pursuing a number additional enhancements based on emerging standards like XRD and webfinger. In addition, as an existing OpenID 2.0 Relying Party, AOL continues to expand the number of properties that accept OpenIDs.
- MySpace was unable to attend due to some last minute scheduling conflicts. Monica Keller, formerly an OpenID Advocate at MySpace has recently transitioned to Facebook and is now working with David Recordon on open standards initiatives.
- Simplify the login and registration flow - rethink the process and optimize it for a third party approach, don't just bolt it onto your existing page
- Avoid lengthy registration forms. Engage quickly, progressively ask for data as needed. Import SREG, AX, and/or OAuth data where possible to pre-populate registration forms.
- Remember user preferences and present only the preferred ID provider upon return visits.
- Consider a branded button-driven interface, select the ID providers that are most relevant for your user base.
- Queue the users right at the register/login link with favicons or other visual images and text that makes it clear that they can use existing accounts instead of having to create an entirely new account.
- Placement of elements of the workflow on the webpage can impact adoption and usage
- Consider combining registration and login into one integrated service
- Use the OpenID UX extension for a pop-up interface that keeps the login process in the context of the host website - avoid the full browser redirect. Use check immediate mode when possible so user achieves a "single click login" experience.
- OpenID for mobile applications is great - less typing required, easier to import data for registration forms, no username/password to input. Don't use pop-up for mobile interface.
- Use "verified email" from ID providers when available to eliminate the 2 step email verification registration flow that results in reduced success rates.
- Use the OpenID/OAuth hybrid for access to rich user data including friends, address books, photos, etc.
- Increased market research on the needs of RPs, OPs, and end users
- Enhancement of the open source libraries
- Marketing, education, and promotion
- Improved ability to serve non-browser-based platforms, including mobile
- Enhanced user profiles, including allowing RPs to store extended profile data at the OP
- Begin building out the consumer side of system, allowing users to connect with and use their 3rd party accounts across ecosystem
- PBS has teamed up with the OIDF to investigate what a Public Media Trust Framework, modeled after the US federal government trust framework, might entail
- Talking to Stations, Shows, NPR, and companies like Google and PayPal to envision a time when all of this might come together and to create a path forward.