Google, IBM, Microsoft, Yahoo join the OpenID Foundation
On 7 February 2008 Google, IBM, Microsoft, VeriSign and Yahoo became corporate board members of the OpenID Foundation. What it meant and how to read the data.
HistoryPublished
On 7 February 2008 the OpenID Foundation announced that Google, IBM, Microsoft, VeriSign and Yahoo had joined as its first corporate board members. The old European OpenID site reposted the press release on 10 February. This page is a historical retrospective. openideurope.eu is today an independent guide with no connection to these companies, to the OpenID Foundation or to the former OpenID Europe Foundation.
What was announced
The press release, distributed from the Foundation’s base in Oregon, said that the five companies had become corporate board members. The Foundation described itself as an open forum to promote, protect and enable OpenID technology. It had been formed in June 2007 to support the technology that the community had developed. Members, it said, included individuals, students, non-profits, start-ups and industry giants.
Each company’s statement stressed a different theme:
- Google spoke about a web built on open standards available to everyone.
- IBM pointed to privacy concerns and identity theft and to its work on user-centric identity in open source.
- Microsoft said it had helped shape the Foundation’s open policy framework, and the release credited it with donating legal resources.
- VeriSign stressed that networked identity and authentication would be core services for its future business.
- Yahoo said it had worked with the Foundation for a year on the intellectual property framework and the final 2.0 specification, and was adopting OpenID for all of its roughly 248 million active registered users. See Yahoo becomes an OpenID provider in 2008.
Why the legal framework mattered
Behind the corporate quotes sat something less glamorous but more important: a contribution framework. Under the Foundation’s policy, anyone who contributed to a specification agreed to a patent non-assertion arrangement, so that implementers could use the result without fear of lawsuits. This is what companies needed before building on a protocol, and it helped explain why OpenID Authentication 2.0 was finished in December 2007 with so many corporate legal teams involved. The old European site also republished the full Intellectual Property Rights Policy.
Reading the numbers
The release cited more than 10,000 websites with OpenID logins and an estimated 350 million OpenID-enabled URLs. Those two figures describe different things. The number of sites is a count of places where a user could in principle log in. The number of URLs came largely from large providers that had made every account usable as an OpenID. It tells you how many accounts could do it, not how many people ever did. A few months later a blog post on the same site claimed that a further provider announcement had brought the total “well over 500 million”, again counting potential users. Treat these figures as signs of momentum, not measures of use.
Two foundations, not one
The reposting is a good moment to separate two organisations that shared a name. The OpenID Foundation is a US non-profit formed in June 2007; it owns the process for the specifications and, today, publishes OpenID Connect and the protocols for the EU wallet. The OpenID Europe Foundation was a separate Belgian association that wanted to represent OpenID in Europe; its history is in What was the OpenID Europe Foundation?. The European site’s own “Join” page, in fact, also invited visitors to donate to the US Foundation. The two were linked by a shared goal, not by a legal merger as far as the public record shows.
What happened afterwards
The corporate backing did not secure a mass user base. Google, Microsoft and others added OpenID provider features later in 2008 (see Google and Windows Live ID open up to OpenID), yet social login and later OAuth-based sign-in won with the public. The Foundation itself went on to a long life: it moved to OpenID Connect in 2014 and now lists working groups on digital credentials, authorisation and identity assurance, with a changed roster of corporate board members. A reader may find the first board a useful early example of how a standards body secures industry support. The reasons for the later decline are in Why OpenID 2.0 faded. For how federated login works generally, see Identity federation explained, and for every date see the OpenID timeline. The Foundation’s present-day flagship, OpenID Connect, is the direct descendant of this early industry alliance. Current information is at the OpenID Foundation.
More in History
Clavid 2008: Switzerland's first OpenID identity provider
Clavid, a Swiss OpenID provider, added smart cards, YubiKey, fingerprints and client certificates in 2008. What it built, why it mattered and what became of it.
Facebook Connect vs OpenID: how social login won
Facebook Connect arrived in 2008 as OpenID was gaining support. Why a single branded button beat an open standard, and what social login costs users today.
Five lessons from OpenID for the EU Digital Identity Wallet
What the rise and fall of OpenID 2.0 teaches the EU wallet: usability, both sides of the market, phishing, assurance and who sees your logins.
From Microsoft Passport to passkeys: 25 years of SSO
From Microsoft Passport and the Liberty Alliance to OpenID, social login, FIDO2 and passkeys: how the dream of one safe login for everything changed form.
From OpenID to OpenID Connect: what changed in 2014
OpenID Connect replaced OpenID 2.0 in February 2014. What was kept, what was thrown away, and why building login on top of OAuth 2.0 finally worked.
From OpenID to the EU wallet: the road to user-controlled ID
OpenID promised to put users in charge of their identity in 2005. The EU Digital Identity Wallet is the state-backed attempt, built on OpenID4VP and OpenID4VCI.