Plusnet
Sunday 8th November 2009 Login | Register

Does Clickpass make OpenID more usable?

March 13th, 2008 at 20:25 by Tamlyn Rhodes

Clickpass has just launched a new OpenID offering which aims to make single sign-in easy enough for the masses. It takes a rather different approach to OpenID than other sites I have tried. The first obvious difference is that sites must, in addition to supporting OpenID, add a special Clickpass button to their sign-in screen. Behind the scenes it also generates a new, unique OpenID URL for each site you use. This is an interesting extra layer of privacy as it makes you completely unidetifiable to the relying party (i.e. the website you are signing in to). I gave it a whirl with Plaxo but was shocked to find that upon clicking the Clickpass button I was taken to a page on clickpass.com which asked me for my Plaxo username and password!

Carsten Pötter has a more in depth post on this bizarre behaviour of Clickpass. He ends with this thought:

There have to be better solutions for making the OpenID experience more comfortable for mainstream users. OpenID is here to overcome the password dilemma of many people, even trying to be more secure. Giving away passwords to third party sites is contradictory and is giving the wrong signal to users.

A comment on that post from Clickpass boss Peter Nixey goes some way to explaining why they chose to do it that way:

We spent a lot of time talking about the ‘asking users for passwords’ problem. In actuality we don’t even pass the credentials through our server – they are submitted directly to the relying party but nonetheless is would be better not to ask for them at all.

It’s true that the form goes direct to the server of the relying party (it is used to send them the randomly generated OpenID URL) but how is anyone to know that? Half the point of OpenID is avoiding sharing passwords between sites. Most users probably wouldn’t think twice about entering their private login details into a third-party site (especially when presented as part of a login process) but that is exactly the kind if blind trust that we, as conciencious web developers, should be educating against.

Ultimately though I think Clickpass’s biggest problem will be getting sites to implement their special button. There are few enough sites that accept standard OpenIDs.

2 Comments »

Stronger passwords now available

May 31st, 2007 at 13:40 by Ian Wild

Customers now have the option to make their passwords stronger, and will be forced to choose a password at least 8 characters in length when signing up or changing their current password. More details can be found in this article on strong passwords.

More…

4 Comments »

Coming Soon : Stronger Passwords

May 21st, 2007 at 19:04 by Liam

Hi all,

Quick heads up that on Wednesday we will be rolling out changes to the platform that will allow customers the ability to choose much more secure passwords.

For those that don’t know, customers are currently restricted to using a 5-8 character password containing numbers and lowercase letters that must start with a letter! The option to allow stronger passwords has been the most voted for suggestion on the Usergroup Issue Tracker for a while now and we recognise that it’s something a lot of you have been asking for.

As of Wednesday customers will be forced into choosing a password that’s between 8 and 16 characters when they signup. This password can also contain any of the folowing characters:

!#$%&()*+,-./:;?@[]^{|}~
0123456789
ABCDEFGHIJKLMNOPQRSTUVWXYZ_abcdefghijklmnopqrstuvwxyz

You will not be forced into changing your existing details so anyone with a password not meeting this criteria can continue using their current credentials.

Password changes on the portal will propagate around all the systems (FTP, Mail, Portal access etc.). The only system that will not support the new password format will be FrontPage. FrontPage will only take into account the first 8 characters.

If anyone has any questions or feedback then please feel free to contribute to this thread and I’ll do my best to provide answers.

1 Comment »

Photos

photo photo photo photo photo photo

View More

Forums

Users online: 86

  • Total Topics: 79596
  • Total Posts: 653481
  • Total Members: 11672

Visit the Forums

Plusnet

Force9

Metronet

Free-Online

Madasafish

PAYH

Just The Name

Related Sites

Community Apps

Here at Plusnet we're always trying to use clever open source things to make our lives easier. Sometimes we write our own and make other people's lives easier too!

View the Plusnet Open Source applications page

About Plusnet

We sell broadband, phone, VoIP and more to homes and businesses in the UK. Winner of 9 out of 11 Categories in the 2008 USwitch survey. Winner of "Best Consumer ISP" at 2008 ISPA awards. Voted number 1 in the Broadband Choices 2008 survey.

© Plusnet plc All Rights Reserved. E&OE

Community Site News is powered by WordPress

Add to Technorati Favourites