The decision two weeks ago by Yahoo! to support the burgeoning openid initiative, where users choose their preferred user account provider for logging into other Web sites, was a defining moment for the increasingly popular effort to bring order and sanity to the often confusing world of user identity on the Web. This major move by Yahoo! underscores how new models for user identity and security are becoming strategically important in the online world, and it also has long-term implications for the enterprise, as we’ll see.
Enterprises will be able to manage the growing problem of the proliferation of accounts created in external, off premises Web apps.There’s no doubt that Yahoo!’s addition of over 250 million accessible user accounts to openid, which can now be used to log into the thousands of openid-compliant Web sites, is a significant win for an initiative that is starting to reach critical mass. My own tests show that Yahoo!’s support for only the newer, more secure specification of openid greatly limits the number of external Web sites you can actually access with your Yahoo! account, however this issue will surely be resolved as more 3rd party sites adopt the new spec.
More interestingly, Yahoo! at this time does yet not allow 3rd party issued openids to be used to access its own Web properties. Why is this vital? Because it will fundamentally limit the usefulness of open Web identity, and openid; what’s the point of having an identity from your preferred provider — or as we’ll see below, from your workplace — if you can’t use it where you want to? This one way adoption of open Web identity is common among the major adopters in the space so far.
Provider-only support of open Web identity is going to be a major challenge for the movement until someone articulates the value proposition for allowing 3rd party authentication of accounts from other Web sites. Read Dare Obasanjo’s reasoning around this in the second half of this post.
Other major Web firms and software companies have been pursuing the grail of open — or mostly-open — Web identity for several years now, including most notably Microsoft and Google. Josh Catone over at Read/Write Web wrote yesterday about Microsoft’s stated intent to join the openid bandwagon, which will likely push the number of openid accounts well past half a billion, regardless of what happens with Microsoft’s acquisition play for Yahoo! This kind of scale of support will put open identity, and specifically openid, on the map and hopefully simplify and empower Web users around the world.
Open identity does push users into considering their Terms of Service of their provider much more carefully, since the’re making a long-term strategic decision with whom they’ll will invest with their Web identity, and whether they offer a good home for what may be their last new Web account ever. A quick examination of Microsoft’s Live ID (the open Web identity formerly known as Passport) shows how Microsoft has had to remake their service to be more open and friendly to users and businesses that support it. Expect that many of today’s identity providers will begin making their offerings more appealing for those shopping for their new Web super-identity. This will likely include, as we see, some enterprises.
What’s so important about open Web identity and how does it affect enterprise identity?
Well for one, when using openid sites that allow 3rd party identities, users need only Read the rest of this entry »






















