OpenID In 2010

1y ago
9 Views
2 Downloads
1.87 MB
32 Pages
Last View : 8d ago
Last Download : 3m ago
Upload by : Aarya Seiber
Transcription

OpenID in 2010Relying Party UX Overview and Lessons LearnedOpenID UX Summit 2010Brian Ellin / brian@janrain.com1

What is OpenID?Authentication & profile import for easilymoving around the webOpenID UX Summit 2010Brian Ellin / brian@janrain.com2

The OpenID OpportunityRethink registration and sign-in as it exists today.OpenID UX Summit 2010Brian Ellin / brian@janrain.com3

Quick Engagement!1. No new password at every site2. No re-entering profile everywhere3. No verify-email dance4. Lower mental investment!OpenID UX Summit 2010Brian Ellin / brian@janrain.com4

Take a step backDon’t just bolt OpenID onto your existing registrationsystem as a password replacement. Treat it equally.OpenID UX Summit 2010Brian Ellin / brian@janrain.com5

Simplify1. Simplify Login/Register flow2. Avoid lengthy registration forms3. Engage quickly, ask for data as neededOpenID UX Summit 2010Brian Ellin / brian@janrain.com6

Users are getting it.but the interface is key.OpenID UX Summit 2010Brian Ellin / brian@janrain.com7

OpenID UX Summit 2010Brian Ellin / brian@janrain.com8

Button Driven Sign-inOpenID UX Summit 2010Brian Ellin / brian@janrain.com9

OpenID UX Summit 2010Brian Ellin / brian@janrain.com10

blink182.comOpenID UX Summit 2010Brian Ellin / brian@janrain.com11

3rd Party vs Email Password60% choose 3rd party on blink182.comOpenID UX Summit 2010Brian Ellin / brian@janrain.com12

tigweb.org exampleOpenID UX Summit 2010Brian Ellin / brian@janrain.com13

Interface is below the fold.!"# %"&OpenID UX Summit 2010Brian Ellin / brian@janrain.com14

tigweb.org - improvedregistration page!"# %OpenID UX Summit 2010Brian Ellin / brian@janrain.com15

NASCAR StyleFavicons can meanother thingsShare This, Follow, Become a Fan etc.OpenID UX Summit 2010Brian Ellin / brian@janrain.com16

Best accompanied with aclear message of benefitOpenID UX Summit 2010Brian Ellin / brian@janrain.com17

89% chose a 3rd partyinstead of clicking login/signupOpenID UX Summit 2010Brian Ellin / brian@janrain.com18

Combine Login & RegisterFor a single, simple experience.OpenID UX Summit 2010Brian Ellin / brian@janrain.com19

Single entry point into systemOpenID UX Summit 2010Brian Ellin / brian@janrain.com20

Return experience is keywhen offering many choicesOpenID UX Summit 2010Brian Ellin / brian@janrain.com21

Use immediate modewhen you can.Sign-in without redirecting or opening a popup.OpenID UX Summit 2010Brian Ellin / brian@janrain.com22

Avoid the full browserredirect by using asmall popup windowOpenID UX Summit 2010Brian Ellin / brian@janrain.com23

openid.ui.mode popupOpenID UX Summit 2010Brian Ellin / brian@janrain.com24

Mobile ConsiderationsDon’t use a popup for iPhone and Android browsers.OpenID UX Summit 2010Brian Ellin / brian@janrain.com25

Mobile OpenID is great!1. Typing on a phone is hard2. No new password at every site3. No re-entering profile data each site4. Less mental investment!OpenID UX Summit 2010Brian Ellin / brian@janrain.com26

Profile DataData transport on top of OpenID via AX/Sregemail, first name, last name, country,language, profile pic url, nickname,gender, date of birth, postcodeOpenID UX Summit 2010Brian Ellin / brian@janrain.com27

Verified EmailMany providers issue an email address that they havealready verified. You don’t have to verify it again.OpenID UX Summit 2010Brian Ellin / brian@janrain.com28

OAuth HybridPiggybacking OAuth on top of OpenID for access toContacts, Social, and other rich APIs.OpenID UX Summit 2010Brian Ellin / brian@janrain.com29

NASCAR n.comOpenID UX Summit 2010Brian Ellin / brian@janrain.com30

Who is your audience?Build an interface and integrate with appropriateproviders.OpenID UX Summit 2010Brian Ellin / brian@janrain.com31

A few years out1. Only managing passwords at provider sites2. Using a password at a non provider site willbe a foreign conceptOpenID UX Summit 2010Brian Ellin / brian@janrain.com32

Brian Ellin / brian@janrain.com 3rd Party vs Email Password 60% choose 3rd party on blink182.com 12. OpenID UX Summit 2010 Brian Ellin / brian@janrain.com tigweb.org example 13. OpenID UX Summit 2010 Brian Ellin / brian@janrain.com

Related Documents:

OpenID 1.0 finalized in 2005 by grassroots community – OpenID 2.0 finalized in December 2007 OpenID Foundaon is the custodian of OpenID intellectual property OpenID is an Open Standard

OpenID Connect is an internet standard for Single Sign-On (SSO) Identity Provision (IdP) OpenID Connect supports web clients mobile / native clients. 1. Need to authenticate a user? 2. Send user to their OpenID provider (via browser / HTTP 302 redirect) 3. Retrieve identity token The OpenID ConnectFile Size: 565KB

1 OpenID Connect Conformance Profiles v3.0 OpenID Connect Working Group, OpenID Foundation June 28, 2018 1. Introduction This document defines the set of profiles of the OpenID Connect specifications used for

Together with the OpenID 2.0 specification [9], the OpenID Attribute Exchange extension (OpenID AX) [10] was defined. This extension enables the exchange of users’ attributes within the OpenID protocol flow. Specifically, it defines a mechanism for fetching user attributes that

OpenID 2.0 to Connect Migration spec approved, April 2015 OpenID Provider Certification launched, April 2015 Relying Party Certification launched, December 2016 Logout Implementer’s Drafts approved, March 2017 OpenID Certificati

OPENID 2–1 2. OPENID OpenID Connect is a simple identity layer on top of the OAuth 2.0 protocol. It enables Clients to verify the identity of the End-User based on the authentication performed by an Authorization Server, as well as to obtain basic profile information abo

OpenID Connect concepts 101 Relationship to OAuth 2.0 101 Prerequisites 103 OpenID Connect flow 104 Build an OpenID Connect IdP server 105 Build an OpenID Connect client 105 Use the API Gateway OAuth client demo 106 Deploy the client demo 108 Client po

Using OpenID with SAP NetWeaver Note: With the latest release 2.0 of the OpenID specification, the Relying Party can also discover the authentication service location of the user’s OpenID Provider by requesting an eXtensible Resource Descriptor Sequence (XRDS) document. XRDS (9) is a standardiz