« Rock On OSCON! | Main | Flexibility is Overrated (OSCON 2005) »
No Password Fields
At last night’s Identity BOF, Meng Weng Wong, the founder of pobox.com, said something that frams the whole Identity 2.0 discusion perfectly: “I don’t want my next Web application to have a password field in the database.”
Posted by windley on August 4, 2005 9:25 AM




Comment from Ross at August 5, 2005 6:12 AM
Any practical ideas on how this would work??
Comment from Phil Windley at August 5, 2005 9:18 AM
You would have to use SXIP, LID, OpenID, or Passel (or a similar system) as your *sole* authentication solution. You'd be forcing your users to sign up for one of those however, instead of merely supplying the login/password yourself. This will be more feasible when one or more of these has achieved some standing and most people who come to your site already have an ID.