Yahoo! announced yesterday that they are opening up their authentication mechanisms so that you can get access to users’ data stored in Yahoo (with their permission of course) as well as leverage account information for single sign-on. They offered up some PHP example code and have even opened it up further than Google has with their efforts.
I’m going to say it: this is fantastic. I know, I know. I’m reading a bunch of notes on the identity gang mailing list about how bad this is going to be or how this isn’t really open (just deepening the silo). I think some of that is true but in the grand scheme of things this is a fantastic step in the right direction.
With the emergence of technologies like OpenID and InfoCard its clear that there are some excellent technological solutions to the concept of user-centric identity. My biggest concern is that Yahoo!, Google and Microsoft join forces and do a federation between their sites (and only their sites). If I still have to keep all of my data in any one of those places, its no worse than me only being able to get cable, phone and Internet from a very few providers (read: monopolies). Could that happen? Dunno. I don’t think its likely with the way things are shaping up between Google and Microsoft; those two companies are way to competitive to collaborate on something like this.
It really would be great if instead of deepening their silo, Yahoo! had instead chosen to use OpenID. I do think people are still a little weary of this new technology. I get it time and again when I see the rolling of the eyes and the ole’ “been there, done that” look on people’s faces when I tell them about it. That said, every day the momentum is continuing to pick up. I see more and more sites adopting it, the use of our identity provider platform is just exploding and there is a palpable shift as we’re approaching a tipping point. Is it ready for a Yahoo!? Probably not quite yet. 6 months and we’ll be there. And guess what? Both Yahoo! and Google are getting closer to what we really want which is a truly open, decentralized, user-centric system for identity management.
You’ve got to crawl before you can walk.
3 comments
Comments feed for this article
Trackback link
http://kveton.com/blog/2006/09/30/yahoo-browser-based-authentication/trackback/
October 1, 2006 at 10:24 am
pd
There’s a substantial grammatical error in the first sentence of this post. What exactly is the point you were trying to communicate?
October 1, 2006 at 4:47 pm
kveton
Point well taken. Fixed! This is what I get for blogging on little or no sleep! :-)
October 13, 2006 at 12:44 am
kronkltd.net
When I first learned about OpenID, my first thought was that it\’d be great for Yahoo. Yahoo already has a very large user base and gives a profile page to every user. (Although it changes if you sign up for 360.)
Hopefully, once 2.0 is finished and proven, and some of the other specs that go on top of it (OpenID-AX) are ready to go, we\’ll start to see more big names taking a look into it.