OpenID in government: Romania and Eastern Europe, 2008
In 2008 a Romanian government programme proposed OpenID for public online services. What the archive shows, how Eastern Europe fits in and what it taught.
HistoryPublished
In March 2008 the OpenID Europe blog carried a short item with a big claim: a new Romanian government programme intended to use OpenID for all online services between the public and the state. It is the closest thing in the archive to a government embracing the standard, and it is worth reading carefully, because the other Eastern European stories from 2008 are smaller than they look.
Romania: a programme, a server and a caveat
Three items from the archive form the Romanian story.
- 6 March 2008. The blog reported the programme and linked to the official announcement and the government proposal, both in Romanian. The Romanian contact promised updates and said that work was under way to launch the first Romanian OpenID server, on which several services with many users would authenticate.
- 18 March 2008. The first Romanian OpenID server went live at an address with the Romanian country code, built with help from the Romanian company Netbridge. The post called it a milestone, with more to do, including a new look.
- 17 April 2008. An approximate translation of a Romanian article reported that the government wanted OpenID as the preferred sign-in for official sites, but had described the technology as not very accurate for verifying users’ credentials. To close the gap it involved mobile operators and other companies as a buffer for checking credentials.
That last point is the interesting one. OpenID could show that the same person controlled an account. It could not say that the person was who they claimed to be. A state that wanted a binding link to a real identity needed a trusted party behind the login, which is what the Romanian authorities appear to have been designing.
We could not find documentation showing that the programme was implemented as announced, nor that OpenID became the official login for Romanian public services. If you know a reliable source, please tell the editorial team. What Romania does today is described on our Romania country page.
The rest of Eastern Europe: representatives, not pilots
The brief entries about Russia, Serbia, Belarus, North Macedonia and Albania are sometimes read as government pilots. The texts do not say that. Between July and October 2008 the blog welcomed a new country representative for each of them. These were volunteers: a software entrepreneur, a technology entrepreneur, an academic, a telecoms engineer and a researcher. Each post gave a short biography, listed which countries still had no representative, and invited others to volunteer.
The address of the Russian post contains the letters ‘un’, but the archived text itself only announces the appointment. We found no source for a United Nations project and do not claim one.
The picture is of a volunteer network spreading east in 2008. How that network was organised is described in the European OpenID community. Its members had enthusiasm and contacts, but not mandates to speak for their governments. Please treat them as community outposts, not as official programmes. Following the 2008 announcements, we found no documented government use of OpenID in these five countries.
Why governments hesitated
Governments need three things that OpenID 2.0 did not provide by itself.
- A defined level of identity assurance. A login from a free provider says little about who is behind it. EU rules today grade electronic identification as low, substantial or high. See levels of assurance.
- Legal accountability. If a login is wrongly accepted, someone must be responsible. A voluntary, decentralised network of providers had no one in that role.
- Cross-border recognition. Even if one country built a system, other states had to trust it. That became the work of the EU’s eIDAS rules, described in cross-border eID.
The idea that a login could be federated across many providers remained attractive. It lives on in identity federation and in national eID hubs.
What remains
Romania’s 2008 attempt belongs to a longer line of public-sector experiments with logging in once and using many services. The EU Digital Identity Wallet is the current answer, and it puts the state, not a free provider, at the top of the trust chain. For the sequence of events, see the OpenID timeline.
Based on the archived OpenID Europe blog posts of March to October 2008. The posts name individuals; we deliberately do not.
More in History
Clavid 2008: Switzerland's first OpenID identity provider
Clavid, a Swiss OpenID provider, added smart cards, YubiKey, fingerprints and client certificates in 2008. What it built, why it mattered and what became of it.
Facebook Connect vs OpenID: how social login won
Facebook Connect arrived in 2008 as OpenID was gaining support. Why a single branded button beat an open standard, and what social login costs users today.
Five lessons from OpenID for the EU Digital Identity Wallet
What the rise and fall of OpenID 2.0 teaches the EU wallet: usability, both sides of the market, phishing, assurance and who sees your logins.
From Microsoft Passport to passkeys: 25 years of SSO
From Microsoft Passport and the Liberty Alliance to OpenID, social login, FIDO2 and passkeys: how the dream of one safe login for everything changed form.
From OpenID to OpenID Connect: what changed in 2014
OpenID Connect replaced OpenID 2.0 in February 2014. What was kept, what was thrown away, and why building login on top of OAuth 2.0 finally worked.
From OpenID to the EU wallet: the road to user-controlled ID
OpenID promised to put users in charge of their identity in 2005. The EU Digital Identity Wallet is the state-backed attempt, built on OpenID4VP and OpenID4VCI.