Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Instead tell them to choose their favorite social IdP on the discovery interface. This will immediately win over a sizable proportion of your audience who will blithely log into your app with almost zero effort (since most social IdPs will happily maintain a user session indefinitely).

As However, as Jim Fox demonstrated on the social identity mailing list the other day, not all users feel comfortable performing a social login operation. Some users have a healthy distrust for social IdPs, and moreover, that lack of trust is on the rise. So be it.

...

If you're still reading this, you'll want to know what the viable alternatives are. Honestly, I havendon't a clueknow. All I can say is that I'm intrigued by the user centric approaches of the IRMA project and the FIDO Alliance. If similar technologies were to proliferate, it would be a death knell for the centralized IdP model. In its place would rise the Attribute Authority, and I don't mean the SSO-based AAs of today. I mean standalone AAs that dish out attribute assertions that end users control. This is the only approach I can see working in a World of Zero Trust.