<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: SXSW Report: A Critical Look at OpenID</title>
	<link>http://drstarcat.com/archives/24</link>
	<description></description>
	<pubDate>Mon, 08 Sep 2008 13:31:57 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.2</generator>
		<item>
		<title>By: Buy cheap phentermine.</title>
		<link>http://drstarcat.com/archives/24#comment-283</link>
		<dc:creator>Buy cheap phentermine.</dc:creator>
		<pubDate>Fri, 01 Aug 2008 17:00:09 +0000</pubDate>
		<guid>http://drstarcat.com/archives/24#comment-283</guid>
		<description>&lt;strong&gt;Buy cheap phentermine....&lt;/strong&gt;

Buy phentermine. Buy phentermine cod. Buy phentermine overnight. Buy phentermine mg. Buy cheap phentermine on line now save. Buy pal pay phentermine using. Buy generic phentermine bloghoster....</description>
		<content:encoded><![CDATA[<p><strong>Buy cheap phentermine&#8230;.</strong></p>
<p>Buy phentermine. Buy phentermine cod. Buy phentermine overnight. Buy phentermine mg. Buy cheap phentermine on line now save. Buy pal pay phentermine using. Buy generic phentermine bloghoster&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OpenID for BtoB? Not So Sure…Yet - Bullblog - Bulldog Solutions</title>
		<link>http://drstarcat.com/archives/24#comment-190</link>
		<dc:creator>OpenID for BtoB? Not So Sure…Yet - Bullblog - Bulldog Solutions</dc:creator>
		<pubDate>Mon, 05 May 2008 16:31:27 +0000</pubDate>
		<guid>http://drstarcat.com/archives/24#comment-190</guid>
		<description>[...] in an article in the April issue of Marketing Watchdog Journal. And check out a great summary here of a SXSW Interactive panel on the [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] in an article in the April issue of Marketing Watchdog Journal. And check out a great summary here of a SXSW Interactive panel on the [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brendan Taylor</title>
		<link>http://drstarcat.com/archives/24#comment-118</link>
		<dc:creator>Brendan Taylor</dc:creator>
		<pubDate>Tue, 25 Mar 2008 15:59:27 +0000</pubDate>
		<guid>http://drstarcat.com/archives/24#comment-118</guid>
		<description>"OpenID along with Oath"

I believe you mean OAuth.</description>
		<content:encoded><![CDATA[<p>&#8220;OpenID along with Oath&#8221;</p>
<p>I believe you mean OAuth.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nikim</title>
		<link>http://drstarcat.com/archives/24#comment-111</link>
		<dc:creator>Nikim</dc:creator>
		<pubDate>Mon, 24 Mar 2008 10:05:14 +0000</pubDate>
		<guid>http://drstarcat.com/archives/24#comment-111</guid>
		<description>Interesting page., guy</description>
		<content:encoded><![CDATA[<p>Interesting page., guy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SXSW: A Critical Look at OpenID &#171; Stone Ward Interactive</title>
		<link>http://drstarcat.com/archives/24#comment-28</link>
		<dc:creator>SXSW: A Critical Look at OpenID &#171; Stone Ward Interactive</dc:creator>
		<pubDate>Thu, 13 Mar 2008 18:29:04 +0000</pubDate>
		<guid>http://drstarcat.com/archives/24#comment-28</guid>
		<description>[...] SXSW Report: A Critical Look at OpenID [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] SXSW Report: A Critical Look at OpenID [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: drstarcat</title>
		<link>http://drstarcat.com/archives/24#comment-27</link>
		<dc:creator>drstarcat</dc:creator>
		<pubDate>Wed, 12 Mar 2008 23:12:47 +0000</pubDate>
		<guid>http://drstarcat.com/archives/24#comment-27</guid>
		<description>Sam Felder also had did a nice (and much shorter) writeup of the panel here: http://www.samfelder.com/2008/03/a-critical-look-at-openid.html</description>
		<content:encoded><![CDATA[<p>Sam Felder also had did a nice (and much shorter) writeup of the panel here: <a href="http://www.samfelder.com/2008/03/a-critical-look-at-openid.html" rel="nofollow">http://www.samfelder.com/2008/03/a-critical-look-at-openid.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The History of Tomorrow&#8217;s Internet: Identity (iCards, pt. 1) &#124; drstarcat.com</title>
		<link>http://drstarcat.com/archives/24#comment-26</link>
		<dc:creator>The History of Tomorrow&#8217;s Internet: Identity (iCards, pt. 1) &#124; drstarcat.com</dc:creator>
		<pubDate>Wed, 12 Mar 2008 16:10:02 +0000</pubDate>
		<guid>http://drstarcat.com/archives/24#comment-26</guid>
		<description>[...] my OpenID report from SXSW I jumped to OpenID briefly, but I want to cover iCards before continuing down that road. iCards are [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] my OpenID report from SXSW I jumped to OpenID briefly, but I want to cover iCards before continuing down that road. iCards are [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sam Hasler</title>
		<link>http://drstarcat.com/archives/24#comment-25</link>
		<dc:creator>Sam Hasler</dc:creator>
		<pubDate>Wed, 12 Mar 2008 10:59:17 +0000</pubDate>
		<guid>http://drstarcat.com/archives/24#comment-25</guid>
		<description>"If someone gets my OpenID, can’t they login to all my sites? Yes, but this happens if they get a hold of your email as well (they can send password reminder requests)."

That's a statement about the impact of either happening, it doesn't address the difference in likelihood of either happening.

Isn't it easier to hack a website to get control of an OpenID URL than it is to hack into an email account?

Or would you really need to hack into the OpenID account (which is distinct from the OpenID URL. i.e. you could control a URL that original defered to a MyOpenID account without knowing anything about the account).

For spammers, hacking OpenID's URLs and searching for where they've been used to post comments on blogs - and so therefore might be whitelisted - could be an easy way to get round stricter comment spam filters.

They might work it the other way of course. find OpenIDs used to post comments, then check if the URL is secure. That could mean that the more you use your OpenID the more you are exposing yourself to spammers trying to hack your OpenID URL.

I wouldn't be surprised if within the next year there someone within the OpenID community who defers their OpenID from a website they manage themselves gets their site hacked and their OpenID used to post comment spam.</description>
		<content:encoded><![CDATA[<p>&#8220;If someone gets my OpenID, can’t they login to all my sites? Yes, but this happens if they get a hold of your email as well (they can send password reminder requests).&#8221;</p>
<p>That&#8217;s a statement about the impact of either happening, it doesn&#8217;t address the difference in likelihood of either happening.</p>
<p>Isn&#8217;t it easier to hack a website to get control of an OpenID URL than it is to hack into an email account?</p>
<p>Or would you really need to hack into the OpenID account (which is distinct from the OpenID URL. i.e. you could control a URL that original defered to a MyOpenID account without knowing anything about the account).</p>
<p>For spammers, hacking OpenID&#8217;s URLs and searching for where they&#8217;ve been used to post comments on blogs - and so therefore might be whitelisted - could be an easy way to get round stricter comment spam filters.</p>
<p>They might work it the other way of course. find OpenIDs used to post comments, then check if the URL is secure. That could mean that the more you use your OpenID the more you are exposing yourself to spammers trying to hack your OpenID URL.</p>
<p>I wouldn&#8217;t be surprised if within the next year there someone within the OpenID community who defers their OpenID from a website they manage themselves gets their site hacked and their OpenID used to post comment spam.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: George Fletcher</title>
		<link>http://drstarcat.com/archives/24#comment-19</link>
		<dc:creator>George Fletcher</dc:creator>
		<pubDate>Tue, 11 Mar 2008 05:05:39 +0000</pubDate>
		<guid>http://drstarcat.com/archives/24#comment-19</guid>
		<description>So yes, I do have gray hair and it's getting grayer by the day:)

As for AOL and Relying Party support. We do support 3rd party OpenID's on dev.aol.com and a couple other sites: ficlets.com (which one best use of CSS) and circavie.com.  We are working to make the relying party support more robust and to cover more services. I don't want to give the impression that AOL is not active in supporting OpenID as a relying party.

On the security front, OpenID 2.0 does require SSL in a few cases so the 2.0 spec is much better from the security perspective.

However, the issue is how much security is needed for the resources being provided. SSL might be overkill. The only minor problem with this logic is that many people use the same password so any insecure channel could compromise their identity.</description>
		<content:encoded><![CDATA[<p>So yes, I do have gray hair and it&#8217;s getting grayer by the day:)</p>
<p>As for AOL and Relying Party support. We do support 3rd party OpenID&#8217;s on dev.aol.com and a couple other sites: ficlets.com (which one best use of CSS) and circavie.com.  We are working to make the relying party support more robust and to cover more services. I don&#8217;t want to give the impression that AOL is not active in supporting OpenID as a relying party.</p>
<p>On the security front, OpenID 2.0 does require SSL in a few cases so the 2.0 spec is much better from the security perspective.</p>
<p>However, the issue is how much security is needed for the resources being provided. SSL might be overkill. The only minor problem with this logic is that many people use the same password so any insecure channel could compromise their identity.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: drstarcat</title>
		<link>http://drstarcat.com/archives/24#comment-18</link>
		<dc:creator>drstarcat</dc:creator>
		<pubDate>Mon, 10 Mar 2008 21:39:47 +0000</pubDate>
		<guid>http://drstarcat.com/archives/24#comment-18</guid>
		<description>Thanks for the post edits.  Email now equals OpenID, Artur is now Swedish!</description>
		<content:encoded><![CDATA[<p>Thanks for the post edits.  Email now equals OpenID, Artur is now Swedish!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
