Hans Granqvist | 1 Jul 11:09

Re: [OpenID] OpenID and SSO

>>"Click to proceed", yes,
>
> There shouldn't even be that, though. Just go to the site and see the
> page. No matter how much you abstract the process of authenticating,
> if they have to take steps to have the service recognize them then
> it's a login.

The entire idea of logging in is a bit of an anachronism. :)

The user should offer to automatically identify and authenticate, and
the RP acts on the credentials if it wants to.

There seems to be a way to do this with OpenID. You need to tweak it
just a bit. I wrote up my thoughts about this a while back:

http://commented.org/blog/2008/1/3/continuous-openid.html

Hans
SitG Admin | 1 Jul 17:55

Re: [OpenID] OpenID and SSO

>http://commented.org/blog/2008/1/3/continuous-openid.html

You were envisioning something like a whitelist? If the user has to 
specify a site to assert their Identity to it, that's a (slightly 
different flow) login process :)

-Shade

Gmane