Bring back the legacy sign‑in method with separate Internet Identity anchors

OpenID has been implemented in a privacy preserving way, the provider (e.g. Google) does not know which identity has been signed into, neither does it know which dapps that identity has signed into.

As for security, the implementation relies upon signatures end to end, so security relies upon the trust the user puts in the provider (e.g. Google) to not be compromised. This isn’t very different from users storing their passkeys in e.g. Google Passwords or Apple Passwords, the platform defaults for most passkey users.

To clarify, passkeys are still supported in II 2.0, using OpenID is optional and not required. Users can also link/unlink their OpenID accounts from access methods and switch to passkeys at any time vice versa.

Most issues I’ve seen in the community is regarding the switch to discoverable passkeys, a topic that’s entirely orthogonal to OpenID authentication.

As for OpenID and user adoption, this lowered the adoption friction significantly for dapps e.g. the majority of new Caffeine users use OpenID.

Why isn’t the legacy page working? I need it to try a recovery of my Internet Identity with the old page. My IPhone has saved a passkey for the old page, but it’s not working with the new page. Also my recovery phrase isn’t working. But the legacy page shows a Canister Error page.

On your iPhone, go to id.ai/recovery → Legacy identity → follow instructions

Yeah, I’ve tried that, but it didn’t work. That’s why I need to try with the old legacy page

I bought a yubikey as a backup in the ii1 days, it stopped working after 2 years no idea why. I suspect the shift to dependence on Google / Apple was one of the reasons the privacy and security focused Jan Camenisch left Dfinity. Dom keeps trying to fix things that aren’t broken while the stuff that’s broken in the IC ecosystem remains broken.