openideurope.eu

Passpack and OpenID in 2008: a password manager's login

In September 2008 the online password manager Passpack accepted OpenID and social logins. What it tried, the paradox behind it and how managers sign in now.

HistoryPublished

In September 2008 an online password manager announced that you could sign in with accounts you already had elsewhere. Passpack, a browser-based password manager, said it supported OpenID as third-party authentication, and OpenID Europe passed the news on in a short post dated 17 September 2008.

What was announced

According to the archived post, Passpack had first declared that it was becoming an OpenID relying party. It had integrated its first third-party logins, Google and Windows Live. On 17 September 2008 it added two more, Facebook and Yahoo. The post does not say how many users took up the option, and we did not find figures.

In the vocabulary of OpenID, Passpack became a relying party: a service that accepts proof of identity from somebody else instead of running its own password check. The term is explained in What is a relying party?. The list of providers is revealing. Google and Microsoft announced their OpenID provider support only at the end of October 2008, so the early Google and Windows Live logins probably used those companies’ own sign-in interfaces, and the post simply groups them as third-party authentication. Facebook had unveiled its own login for other sites in July 2008 and made it widely available in December, a story told in Facebook Connect vs OpenID.

The paradox of logging in to a vault

A password manager is the one service where a weak login matters most, because it protects everything else. Accepting a login from Google or Facebook makes signing in easier, but it also means that the account which opens the door is controlled by a third party, with that party’s recovery process and that party’s risk of being phished.

The way out is to separate two things that are easy to confuse. Authentication answers who may reach the stored data. Decryption answers who can actually read it. A well-designed online password manager encrypts data on the user’s device with a key the provider never sees, so that even a successful login does not reveal passwords on its own. Whether Passpack’s design kept sign-in and decryption apart, and what the service looks like today, are things we could not re-verify in October 2026, so read the vendor’s own documentation before relying on any claim about it.

The same separation is what matters today. When you assess a manager, ask whether a stolen login alone is enough to read the vault. The password manager guide explains the model, and the comparison of password managers shows how current products handle it.

What changed since 2008

Three things are different now.

  • Social login became normal. Buttons for Google, Apple and others are everywhere, and their technology is OpenID Connect and OAuth 2.0 rather than OpenID 2.0. See Sign in with Google or Apple.
  • Passkeys replace many passwords. Several current password managers let you unlock or sign in with a passkey, so the login to the vault does not depend on a typed secret. Passkeys explained covers the basics.
  • Zero-knowledge designs became the norm. Encrypting on the device and never sending the master key is now the baseline for serious managers, and independent audits are a normal part of how vendors earn trust.

Why this story belongs in the archive

The Passpack item shows how quickly OpenID’s promise, one login for many sites, met the question of trust. Who is the provider, what does the relying party risk, and what does the user stand to lose if either is compromised? These are the same questions the EU Digital Identity Wallet has to answer at the scale of a whole continent, a thread picked up in Five lessons from OpenID for the EU wallet.

You can follow the wider story in the OpenID timeline.

The facts about the 2008 announcement come from the archived OpenID Europe post. Passpack’s current status was not confirmed when this page was written in October 2026.

More in History