태그 : oauth
2009/03/18 2010년의 페이스북은? [2]
2009/03/04 Lift09 동영상 등
2009/02/27 Plaxo의 OpenID 사용 방법: 92% 성공률 기록 [2]
2009/02/13 OpenID UX Summit 발표자료(2009.2.10) [1]
This week, we received word from the folks at OAuth that they were looking closely at a security issue within the protocol. We take security seriously and felt the responsible thing to do was temporarily disable OAuth while this matter was sorted out. Yahoo and others made similar decisions. The developers working on Twitter projects that are in our beta test group felt this disruption the hardest and their patience is extremely appreciated.[2]

The first flaw is that parameters of HTTP redirects used in OAuth can be tempered with or replayed...
The second and more serious flaw is that the User talking to the Consumer may *not* be the same User talking to the Service Provider.
“This website is registered with SERVICE_PROVIDER_DOMAIN_NAME to make authorization requests, but has not been configured to send requests securely. If you grant access but you did not initiate this request at CONSUMER_DOMAIN_NAME, it may be possible for other users of CONSUMER_DOMAIN_NAME to access your data. We recommend you deny access unless you are certain that you initiated this request directly with CONSUMER_DOMAIN_NAME.”
# by | 2009/04/25 00:38 | OpenID | 트랙백 | 덧글(2)
Social networks have largely been built on the premise of being walled gardens in such a way that users can't communicate or share content or friends across networks;
My prediction is that by the end of the year Facebook will become the most open social network on the social web.
# by | 2009/03/18 23:27 | 기타 ID 동향 | 트랙백 | 덧글(2)
그 밖에 RFID 보안 이슈 등 여러 가지 세션이 있으니 Lift 09 모든 세션의 동영상이 영어/프랑스어로 공개되어 있으니 프로그램 목록을 보시고 관심있는 분들은 참고하시길 바랍니다.
Privacy isn’t just about having something to hide; it’s a basic right that has enormous value to democracy, liberty, and our humanity.
Four years ago, OASIS defined the interaction between XACML and SAML in SAML 2.0 profile of XACML v2.0 [PDF] , part of the XACML 2.0 specification set .
Most knew about OpenID they were unfamiliar with information cards.It was interesting to hear people’s deep concern about corporateinvolvement in the development of these standards - the three corporatenames I mentioned in relationship to information cards seemed to raiseparticular ire - Microsfot, Novell and IBM.
I mentioned Higgins (the open source project) andtalked about the standardization effort at OASIS. This didn’t sway themmuch they “just distrusted” the corporate involvement.
I personally am very clear that corporate involvement is essentialto getting an identity layer to happen. I was re-affirmed in thisexchange in knowing that the corporate perspective is not enough andhaving a trusted space for critical conversations around issues thatarise with identity need a commons for them to occur (that is a spacewhere corporations do note have the ultimate veto about what groups areor are not allowed in the conversation).
If a space like this does notexist to create a dialogue amongst diverse interests and perspectivesthen the risk of it not happening or not getting adoption by people.
# by | 2009/03/04 21:11 | OpenID | 트랙백
This experimental method refers to big, known brands where users were already logged in, it requires zero typing - just two clicks - and it takes advantage of the OpenID authentication opportunity to get quick permission to leverage the well established OAuth data swap to facilitate immediate personalization - at the same time, with nothing but 2 clicks required of users.
No new accounts, no disclosure of Gmail passwords to Plaxo, no risky account scraping and no need to import or find friends on the new service before immediate personalization could be offered.
Only 8% of the people who clicked to log in with a standards based 3rd party authentication ended up deciding to bail instead. That's the kind of ease-of-use that people presumed only Facebook Connect could provide.
# by | 2009/02/27 23:01 | 기타 ID 동향 | 트랙백 | 덧글(2)
# by | 2009/02/13 07:45 | 기타 ID 동향 | 트랙백(1) | 덧글(1)
◀ 이전 페이지다음 페이지 ▶