Hacker News new | ask | show | jobs
by foobar456 4775 days ago
OAuth is for authorization, not authentication. Please stop using it like this. If you want SSO-style authentication using OpenID or SAML2.
1 comments

Unfortunately I think that ship has sailed. Personally I'm hoping Persona will catch on. At least that's designed as an authentication scheme.
What problem does it solve that OpenID doesn't? OpenID already has a lot of adoption, and IMO works quite well.
OpenID is great, but I somehow just don't expect it to get that much adoption on sites where "Sign In With Facebook" is the default. Whereas I have at least some hope that Persona might become that common if Mozilla play their cards right.