Hacker News new | ask | show | jobs
by dwaite 1268 days ago
No. Generally this is because it is not a technical capability problem, but a business problem.

Often, sites which use OpenID for authentication either have no automated account recovery, or do recovery based on a verified email claim. This means those relying parties do indeed rely on the reliability and service support promises of the OP, as well as the validity of attribute data shared.

If ISPs or Google had been interested in providing webfinger-based discovery, we might have been able to create a decent UX around an assumption that your identifier was an email address, and that a local authentication process (including potentially an emailed code or link) was an acceptable fall-back. But there was never really critical mass for this to happen.