openideurope.eu

Google, IBM, Microsoft, Yahoo join the OpenID Foundation

On 7 February 2008 Google, IBM, Microsoft, VeriSign and Yahoo became corporate board members of the OpenID Foundation. What it meant and how to read the data.

HistoryPublished

On 7 February 2008 the OpenID Foundation announced that Google, IBM, Microsoft, VeriSign and Yahoo had joined as its first corporate board members. The old European OpenID site reposted the press release on 10 February. This page is a historical retrospective. openideurope.eu is today an independent guide with no connection to these companies, to the OpenID Foundation or to the former OpenID Europe Foundation.

What was announced

The press release, distributed from the Foundation’s base in Oregon, said that the five companies had become corporate board members. The Foundation described itself as an open forum to promote, protect and enable OpenID technology. It had been formed in June 2007 to support the technology that the community had developed. Members, it said, included individuals, students, non-profits, start-ups and industry giants.

Each company’s statement stressed a different theme:

  • Google spoke about a web built on open standards available to everyone.
  • IBM pointed to privacy concerns and identity theft and to its work on user-centric identity in open source.
  • Microsoft said it had helped shape the Foundation’s open policy framework, and the release credited it with donating legal resources.
  • VeriSign stressed that networked identity and authentication would be core services for its future business.
  • Yahoo said it had worked with the Foundation for a year on the intellectual property framework and the final 2.0 specification, and was adopting OpenID for all of its roughly 248 million active registered users. See Yahoo becomes an OpenID provider in 2008.

Behind the corporate quotes sat something less glamorous but more important: a contribution framework. Under the Foundation’s policy, anyone who contributed to a specification agreed to a patent non-assertion arrangement, so that implementers could use the result without fear of lawsuits. This is what companies needed before building on a protocol, and it helped explain why OpenID Authentication 2.0 was finished in December 2007 with so many corporate legal teams involved. The old European site also republished the full Intellectual Property Rights Policy.

Reading the numbers

The release cited more than 10,000 websites with OpenID logins and an estimated 350 million OpenID-enabled URLs. Those two figures describe different things. The number of sites is a count of places where a user could in principle log in. The number of URLs came largely from large providers that had made every account usable as an OpenID. It tells you how many accounts could do it, not how many people ever did. A few months later a blog post on the same site claimed that a further provider announcement had brought the total “well over 500 million”, again counting potential users. Treat these figures as signs of momentum, not measures of use.

Two foundations, not one

The reposting is a good moment to separate two organisations that shared a name. The OpenID Foundation is a US non-profit formed in June 2007; it owns the process for the specifications and, today, publishes OpenID Connect and the protocols for the EU wallet. The OpenID Europe Foundation was a separate Belgian association that wanted to represent OpenID in Europe; its history is in What was the OpenID Europe Foundation?. The European site’s own “Join” page, in fact, also invited visitors to donate to the US Foundation. The two were linked by a shared goal, not by a legal merger as far as the public record shows.

What happened afterwards

The corporate backing did not secure a mass user base. Google, Microsoft and others added OpenID provider features later in 2008 (see Google and Windows Live ID open up to OpenID), yet social login and later OAuth-based sign-in won with the public. The Foundation itself went on to a long life: it moved to OpenID Connect in 2014 and now lists working groups on digital credentials, authorisation and identity assurance, with a changed roster of corporate board members. A reader may find the first board a useful early example of how a standards body secures industry support. The reasons for the later decline are in Why OpenID 2.0 faded. For how federated login works generally, see Identity federation explained, and for every date see the OpenID timeline. The Foundation’s present-day flagship, OpenID Connect, is the direct descendant of this early industry alliance. Current information is at the OpenID Foundation.

More in History