• eric.rini (7/29/2012)


    Everyone knows usename and password is not enough. Stop blaming users for your flawed security implementations.

    How about we stop reinventing the wheel and come up with a SAFE, SECURE, REUSABLE online identity. Something tied to more than just a password. Oh wait, it's already done: http://openid.net/. Seriously, I am tired of hearing about every site needing a unique 12+ character mixed case letters, numbers, symbols password, that's ridiculous and works against rational user friendliness and usability design constraints.

    I disagree. Having a single ID (this includes things like Facebook, Google+ etc) is essentially the same thing as having a single password. If that ID is compromised, everything is compromised, there is no 'firewall' between identities. Actually it's WORSE because there is a single dashboard with record of EVERY place you use it. The potential thief/snoop doesn't even have to go looking for where you were using your account... it's right there.

    If you use that ID for posting on a lot of sites where your screen name is visible, it enables a lot of information to be extracted about you though a websearch (this is especially true if it's your real name) by potential employers, nosy or pissed off neighbors, stalkers etc.

    The sad thing is, many websites are getting lazy and moving to this model, giving you a 'choice' of Facebook, Google, OpenID etc without even the option of establishing an unrelated account.

    One more thing: if you look at the OpenID website, one of their 'advantages' is this little gem: Many OpenID providers collect and share a wide range of demographic information, including name, date of birth, location, gender and an email address. This data allows you to optimize your marketing efforts and tailor your website to better target the needs of your core audience.

    ...

    -- FORTRAN manual for Xerox Computers --