First, full disclosure: I don’t know a lot about OpenID. But I do know that there are some serious issues related to online identity. Here are two of the questions I find most pressing:
- How do I create a persistent identity, across all the different web services I use? This is a question of convenience. Registering for a website that I’m going to use once is kind of ridiculous. Even if I wanted to use it again, chances are I will have forgotten my password, or even that I ever registered there in the first place. I could always register again, but that isn’t useful for me, or the service provider.
- How do I take ownership of my personal information? This is a privacy and security question. I’m online a lot. There’s a lot of digital information about me that could be gathered up to paint an interesting picture of who I am. Ideally, I should be the person who owns that picture and controls who has access to it.
Now, I’m not saying that OpenID has solved these problems – far from it – but it has created the opportunity for people to test things out and discuss what works and what doesn’t. As far as I can tell, the first issue is being addressed more directly than the second. Still, I don’t think we’re going to have a meaningful approach to the privacy question until we get some more experience with persistent identities.

