Simpler sign-ups for Yahoo! users with OpenID
How many times have you created a new account at a website and seen a message that said: “Thank you for creating an account. To activate your new account, please access your email and click the verification URL provided.”
Context & Ripple Effects
Google has been building toward this since 2008, when it began moving toward single sign-on with OpenID after first accepting OpenID logins on Blogger in January of that year — work that followed WordPress.com's early adoption of the standard back in 2007. What changes with this post is the direction of the flow: instead of Google acting only as an identity provider, it is now acting as a relying party that accepts OpenID credentials from Yahoo.
First-order effects
- Yahoo users can register for Google services using their existing Yahoo credentials, skipping the new-account-and-email-verification loop the post opens with.
- Yahoo's role as an OpenID identity provider gets its largest-scale test yet, since Google properties are among the highest-traffic relying parties on the web.
Second-order effects
- Other large consumer web companies face pressure to pick a side of the federation equation — either issuing OpenID identities to their user bases or accepting them — rather than running closed per-site account systems.
- Rival federated-login efforts such as Facebook Connect, which Google Friend Connect was already competing against on install friction as of October 2009, now contend with a Yahoo-backed credential pool flowing into Google properties.
Third-order effects
- If large providers keep both issuing and accepting federated identities, account creation migrates from thousands of independent site databases to a handful of identity providers — concentrating login relationships, and the profile data attached to them, in fewer hands.
The trend: Web authentication is consolidating from per-site usernames and passwords toward federated identity controlled by a small set of large providers, with OpenID as one competing rail.