Passpack and OpenID in 2008: a password manager's login
In September 2008 the online password manager Passpack accepted OpenID and social logins. What it tried, the paradox behind it and how managers sign in now.
HistoryPublished
In September 2008 an online password manager announced that you could sign in with accounts you already had elsewhere. Passpack, a browser-based password manager, said it supported OpenID as third-party authentication, and OpenID Europe passed the news on in a short post dated 17 September 2008.
What was announced
According to the archived post, Passpack had first declared that it was becoming an OpenID relying party. It had integrated its first third-party logins, Google and Windows Live. On 17 September 2008 it added two more, Facebook and Yahoo. The post does not say how many users took up the option, and we did not find figures.
In the vocabulary of OpenID, Passpack became a relying party: a service that accepts proof of identity from somebody else instead of running its own password check. The term is explained in What is a relying party?. The list of providers is revealing. Google and Microsoft announced their OpenID provider support only at the end of October 2008, so the early Google and Windows Live logins probably used those companies’ own sign-in interfaces, and the post simply groups them as third-party authentication. Facebook had unveiled its own login for other sites in July 2008 and made it widely available in December, a story told in Facebook Connect vs OpenID.
The paradox of logging in to a vault
A password manager is the one service where a weak login matters most, because it protects everything else. Accepting a login from Google or Facebook makes signing in easier, but it also means that the account which opens the door is controlled by a third party, with that party’s recovery process and that party’s risk of being phished.
The way out is to separate two things that are easy to confuse. Authentication answers who may reach the stored data. Decryption answers who can actually read it. A well-designed online password manager encrypts data on the user’s device with a key the provider never sees, so that even a successful login does not reveal passwords on its own. Whether Passpack’s design kept sign-in and decryption apart, and what the service looks like today, are things we could not re-verify in October 2026, so read the vendor’s own documentation before relying on any claim about it.
The same separation is what matters today. When you assess a manager, ask whether a stolen login alone is enough to read the vault. The password manager guide explains the model, and the comparison of password managers shows how current products handle it.
What changed since 2008
Three things are different now.
- Social login became normal. Buttons for Google, Apple and others are everywhere, and their technology is OpenID Connect and OAuth 2.0 rather than OpenID 2.0. See Sign in with Google or Apple.
- Passkeys replace many passwords. Several current password managers let you unlock or sign in with a passkey, so the login to the vault does not depend on a typed secret. Passkeys explained covers the basics.
- Zero-knowledge designs became the norm. Encrypting on the device and never sending the master key is now the baseline for serious managers, and independent audits are a normal part of how vendors earn trust.
Why this story belongs in the archive
The Passpack item shows how quickly OpenID’s promise, one login for many sites, met the question of trust. Who is the provider, what does the relying party risk, and what does the user stand to lose if either is compromised? These are the same questions the EU Digital Identity Wallet has to answer at the scale of a whole continent, a thread picked up in Five lessons from OpenID for the EU wallet.
You can follow the wider story in the OpenID timeline.
The facts about the 2008 announcement come from the archived OpenID Europe post. Passpack’s current status was not confirmed when this page was written in October 2026.
More in History
Clavid 2008: Switzerland's first OpenID identity provider
Clavid, a Swiss OpenID provider, added smart cards, YubiKey, fingerprints and client certificates in 2008. What it built, why it mattered and what became of it.
Five lessons from OpenID for the EU Digital Identity Wallet
What the rise and fall of OpenID 2.0 teaches the EU wallet: usability, both sides of the market, phishing, assurance and who sees your logins.
From Microsoft Passport to passkeys: 25 years of SSO
From Microsoft Passport and the Liberty Alliance to OpenID, social login, FIDO2 and passkeys: how the dream of one safe login for everything changed form.
From OpenID to OpenID Connect: what changed in 2014
OpenID Connect replaced OpenID 2.0 in February 2014. What was kept, what was thrown away, and why building login on top of OAuth 2.0 finally worked.
From OpenID to the EU wallet: the road to user-controlled ID
OpenID promised to put users in charge of their identity in 2005. The EU Digital Identity Wallet is the state-backed attempt, built on OpenID4VP and OpenID4VCI.
Google and Windows Live ID open up to OpenID, October 2008
In late October 2008 Microsoft previewed an OpenID provider for Windows Live ID and Google announced limited provider support. What each did and did not offer.