the following url prompted me to make this post: https://news.ycombinator.com/item?id=7856911
Note that I'll be using the term OAuth in the general sense because most will know what I mean. I do not mean the specific OAuth standard as much as I mean generic authorization.
I see a lot of people drawing lines, either all, or nothing. I personally don't ever log into anything outside of SO using any sort of OAuth, the reason is quite simple:
I don't want to 'log out' of a half dozen websites because I logged out of FB or gmail.
In my opinion, the actual answer is a balance. Using my FB account to log into my question and answer site (Stack Overflow) is just stupid. They are completely unrelated. Except in specific circumstances (programming related FB account), there is just no reason for it other than "convenience".
OTOH, if I'm playing something like a game that interacts with FB, by all means, use FB as an authentication mechanism.
It's perfectly ok for me to log into all of google's various services/apps (online and off) using Google OAuth, it's retarded for me to do that with a yahoo OAuth (this is just an extreme example, I know you can't currently do that).
This was the travesty that is Jeff Atwood. In my experience, he takes reasonable things to the extreme, and the decision to have SO use OpenID exclusively was an example of that. Pie in the sky theory, but not much more than a pita in practice.
And it shows, if I hit SO while logged into the wrong gmail account, it starts asking me to create another account. I don't want to create another account, nor do I want to link all of my gmail accounts to my SO account, that's an invasion of privacy.
If it isn't related, don't ask people to log in via the OAuth provider.