OpenID
You can now use your WordPress.com blog as an OpenID. — Are you fed up with having to remember dozens of usernames and password? Does the idea of creating yet another account on yet another site leave you cold? — OpenID is a new standard that hopes to alleviate some of the pain …
Context & Ripple Effects
WordPress.com has turned every one of its blogs into an OpenID identity, meaning the blog URL itself becomes the login credential users present at any site accepting the standard. Read/WriteWeb's pickup grouped the announcement with 37Signals adopting OpenID the same day, framing both as early mainstream-platform validation for what had until then been a niche identity protocol.
That pairing matters because OpenID's pitch — one identity instead of dozens of per-site username/password pairs — only works if large consumer platforms both issue identities (as WordPress.com now does) and accept them, a chicken-and-egg problem these adoptions chip away at.
First-order effects
- WordPress.com users can now sign in to any OpenID-enabled site using their blog address, making the platform an identity provider overnight without new credentials being issued.
- Sites accepting OpenID gain a wave of potential users who arrive pre-authenticated, while 37Signals' same-day adoption signals its apps will accept such external identities.
Second-order effects
- Other large blogging and web-app platforms face pressure to either issue or accept OpenIDs, since a rival's URL-as-login makes their own mandatory account creation look like friction.
- Relying-party sites cede control of the authentication experience to identity providers like WordPress.com, shifting where session management and password-reset support burdens land.
Third-order effects
- If issuing and accepting OpenIDs becomes table stakes for consumer platforms, single sign-on decouples identity from individual services, weakening the lock-in value of proprietary account systems and raising questions about trust and accountability when a third party vouches for a login.
The trend: Web identity is shifting from per-site username/password silos toward user-owned URLs functioning as portable credentials, with major platforms racing to become identity providers.