OpenID Foundation/CRC
The OpenID Foundation Customer Research Committee (CRC) reaches out to actual and potential adopters of OpenID. The objective is to learn what worked for them and what did not when adopting OpenID, and what the OpenID community needs to do in order:
- to get even broader adoption of OpenID by more parties, in particular sites accepting OpenIDs
- to make existing OpenID deployments more successful (e.g. higher OpenID transaction volume)
It is envisioned that the results of the research will be available to the membership of the OpenID Foundation. If you believe you have some interesting insights, we'd love to hear from you. We currently do not have a separate mailing list, so we encourage you to use the general list.
Members
CRC currently consists of:
- Johannes Ernst, NetMesh (chair)
- Brian Kissel, JanRain
- Scott Kveton, Vidoop
- Raj Mata, Yahoo!
Research Participants
We are interested in learning from:
- Parties that already have implemented OpenID
- Parties that consider implementing OpenID
- Parties that considered and decided against implementing OpenID
- Parties that aware of OpenID but have not considered planning to implement
Candidate Questions
(This is work in progress)
- Problem Set
- What problems are you attempting to solve that seem to relate to OpenID?
- How big are these problems for you?
- What are the relative priorities of these problems?
- Do you think these problems are specific to your company? If not, who else has them?
- What specifically is it about OpenID that makes you look at OpenID for a solution?
- What other approaches are you aware of that might solve these problems instead? Have you investigated them? If so, what is the result of your investigation?
- How do you frame the problem internally? Is it:
- a security problem
- a compliance problem
- an e-business transaction problem (e.g. need to increase on-line transactions by making it easier for customers)
- a cost problem (e.g. password reset costs)
- an infrastructure problem (e.g. to enable new services that currently don't exist)
- Other?
- Is OpenID a complete solution for this set of problems?
- If not, what else do you need?
- If not, does a complete solution exist?
- If not, can you make business-relevant progress in the meantime?
- Does it appear viable to deliver the parts that are missing in your view? Who are you looking toward to deliver them?
- Can you proceed at your own pace, or do you need to wait for other parties to move at the same time?
- What problems do you wish OpenID could solve but (currently) doesn't?
- If you have deployed already:
- How satisfied are you with your deployment?
- Are you planning to broaden / deepen the deployment?
- Which metric are you using as a success criterion?
- Are the actual numbers satisfactory?
- If not, what could be done to make them more satisfactory?
- What degree of security/etc. is required to solve these problems?
- Username/Password
- Hardware tokens
- Client certificates
- Out-of-band validation (e.g. cell phone callback)
- Other
- Are you mainly looking towards reusing the existing authentication infrastructure that you have already with OpenID (e.g. deployed hardware tokens) or are you looking towards introducing new credential types as part of an OpenID initiative?
- Do you require legal agreements (e.g. liability for OPs)
- What problems are you attempting to solve that seem to relate to OpenID?
- OpenID General Awareness
- How did you learn about OpenIDs existence?
- How did you learn what OpenID is and how it works?
- How did you decide that OpenID applies to your business?
- Are you aware of the distinctions between being an OP and an RP?
- technically, including security / trust ramifications
- user experience
- business opportunities / ramifications
- Do you understand the components of the technology stack?
- URLs as identifiers for people
- Yadis discovery
- Authentication
- exchange of attribute information (SREG, AX)
- schemas
- related technologies, e.g. OAuth, FriendFeeds etc.
- Are you aware of the business benefits of supporting OpenID? e.g.
- reduced friction for customer to conduct commerce / engage with your site
- higher revenue (if so, how?), e.g.
- more of the same business
- new business
- lower cost (if so, how?) e.g.
- outsourcing function
- streamlining function
- lower business risk, e.g.
- "personal info that is not stored here cannot be stolen from us"
- potentially higher authentication quality
- Which market segments / product categories / demographics / etc. are ready to use OpenID in your view? Which ones are next? Which ones are last?
- Market Segment / Vertical
- Whose adoption(s) of OpenID would signal to your market segment that adoption of OpenID is becoming safe and/or a must-have feature for you and your competitors?
- Which other segments do market participants in your segment generally reference prior to adoption of similar technologies in your segment?
- Do you see any parallels in adoption of OpenID in your segment with the successful (or not) adoption of other technologies before?
- Which organization(s) would be logical OPs for your segment? And why? E.g.:
- general-purpose e.g. AOL, Yahoo
- a neutral, segment-specific identity provider with its own brand
- the "top dog" in your segment
- all/most market participants
- Which organization(s) would be logical RPs for your segment? e.g.
- all market participants
- only large / medium / small participants
- "suppliers" into the top dogs' supply chains
- What is the business case for OpenID adoption in your segment? Are there one or several? Which one is most realistic in the shortest time for your vertical?
- If OpenID adoption was widespread in your segment, who would win and who would lose? Why? How much difference would it make to which metric?
- Do you see a strategic downside to adopting OpenID in your segment?
- can it be mitigated?
- Which devices / OSs / ... are relevant in your segment?
- What obstacles do you see for broad OpenID adoption and use in your segment?
- technically, e.g.
- security, non-repudiation, mapping to legacy systems/processes, ...
- need new features such as authenticated messaging, OP-initiated SSO, ...
- user experience, e.g.
- does expected user experience map to what your users can understand quickly and will do?
- branding
- business-wise, e.g.
- who pays for the assumption of risk?
- need (more) trusted technology / service providers
- insufficient value proposition
- technically, e.g.
- Company
- Where are you in the internal sales cycle? e.g.
- initial awareness of opportunity and evaluation
- business case made
- executive sponsorship
- project funded
- beta
- deployed
- Which obstacles have you overcome so far? Which do you still need to overcome? e.g.
- (better) understanding of the business opportunity
- (better) articulation of the business opportunity to decision makers
- technology/vendor selection
- project funding
- site owner buy-in
- prioritization viz-a-viz other initiatives
- executive sponsorship
- need other organizations to do something first, e.g.
- deploy vertical-specific OP
- Foundation membership?
- are you a foundation member?
- Why?
- Why not?
- What most important value should the foundation provide to you:
- industry-specific gatherings
- connecting vendors and buyers
- pursuing technical advancement
- OpenID marketing
- in general
- in your specific vertical (which?)
- are you a foundation member?
- Where are you in the internal sales cycle? e.g.

