<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Time is ripe for distributed authentication</title>
	<atom:link href="http://jk3.us/2005/07/14/time-is-ripe-for-distibuted-authentication/feed/" rel="self" type="application/rss+xml" />
	<link>http://jk3.us/2005/07/14/time-is-ripe-for-distibuted-authentication/</link>
	<description>...or something along those lines</description>
	<lastBuildDate>Thu, 29 Mar 2012 17:20:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Jay Knight &#187; On Avoiding the Password &#8216;Explosion&#8217;</title>
		<link>http://jk3.us/2005/07/14/time-is-ripe-for-distibuted-authentication/#comment-21</link>
		<dc:creator>Jay Knight &#187; On Avoiding the Password &#8216;Explosion&#8217;</dc:creator>
		<pubDate>Mon, 04 Dec 2006 21:05:05 +0000</pubDate>
		<guid isPermaLink="false">http://jk3.us/?p=13#comment-21</guid>
		<description>[...] This just re-iterates what I&#8217;ve said before: &#8220;Time is ripe for distributed authentication.&#8221; [...]</description>
		<content:encoded><![CDATA[<p>[...] This just re-iterates what I&#8217;ve said before: &#8220;Time is ripe for distributed authentication.&#8221; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Administrator</title>
		<link>http://jk3.us/2005/07/14/time-is-ripe-for-distibuted-authentication/#comment-20</link>
		<dc:creator>Administrator</dc:creator>
		<pubDate>Sat, 16 Jul 2005 22:58:17 +0000</pubDate>
		<guid isPermaLink="false">http://jk3.us/?p=13#comment-20</guid>
		<description>David... yes, drupal is a step in the right direction... If that guy used his drupal id on all the drupal sites he used (let&#039;s assume he uses a lot), then a compromised password could be rememdied by a single change.  However, as you said, you still enter your password on every site, which almost defeats the purpose :)</description>
		<content:encoded><![CDATA[<p>David&#8230; yes, drupal is a step in the right direction&#8230; If that guy used his drupal id on all the drupal sites he used (let&#8217;s assume he uses a lot), then a compromised password could be rememdied by a single change.  However, as you said, you still enter your password on every site, which almost defeats the purpose <img src='http://jk3.us/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Roussel</title>
		<link>http://jk3.us/2005/07/14/time-is-ripe-for-distibuted-authentication/#comment-19</link>
		<dc:creator>David Roussel</dc:creator>
		<pubDate>Sat, 16 Jul 2005 22:26:14 +0000</pubDate>
		<guid isPermaLink="false">http://jk3.us/?p=13#comment-19</guid>
		<description>Note that Drupal already supports distributed authentication.

For example look in this thread, http://www.spreadfirefox.com/?q=node/view/16836 search for vwx.  See how the guy has logged in with his drupal.org id into the SpreadFirefox.com site.

Granted it&#039;s not as nice a OpenID, as the password goes through the server.  See here for more details http://drupal.org/node/19113</description>
		<content:encoded><![CDATA[<p>Note that Drupal already supports distributed authentication.</p>
<p>For example look in this thread, <a href="http://www.spreadfirefox.com/?q=node/view/16836" rel="nofollow">http://www.spreadfirefox.com/?q=node/view/16836</a> search for vwx.  See how the guy has logged in with his drupal.org id into the SpreadFirefox.com site.</p>
<p>Granted it&#8217;s not as nice a OpenID, as the password goes through the server.  See here for more details <a href="http://drupal.org/node/19113" rel="nofollow">http://drupal.org/node/19113</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Administrator</title>
		<link>http://jk3.us/2005/07/14/time-is-ripe-for-distibuted-authentication/#comment-18</link>
		<dc:creator>Administrator</dc:creator>
		<pubDate>Fri, 15 Jul 2005 23:36:36 +0000</pubDate>
		<guid isPermaLink="false">http://jk3.us/?p=13#comment-18</guid>
		<description>Grauw, with &lt;b&gt;distributed&lt;/b&gt; authentication (with openid, anyway), you don&#039;t have to provide your password to the site author at all, just to your identity server.  Then there is no way for all the sites you use to misuse the data (they don&#039;t have it).

Also, when it&#039;s distributed, you really truly have a single password to worry about... Not just using the same one on every site.  If you think your password has been compromised, change it.  Once.  Not &quot;the password of any accounts where you use the same password.&quot;</description>
		<content:encoded><![CDATA[<p>Grauw, with <b>distributed</b> authentication (with openid, anyway), you don&#8217;t have to provide your password to the site author at all, just to your identity server.  Then there is no way for all the sites you use to misuse the data (they don&#8217;t have it).</p>
<p>Also, when it&#8217;s distributed, you really truly have a single password to worry about&#8230; Not just using the same one on every site.  If you think your password has been compromised, change it.  Once.  Not &#8220;the password of any accounts where you use the same password.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Laurens Holst</title>
		<link>http://jk3.us/2005/07/14/time-is-ripe-for-distibuted-authentication/#comment-17</link>
		<dc:creator>Laurens Holst</dc:creator>
		<pubDate>Fri, 15 Jul 2005 23:28:46 +0000</pubDate>
		<guid isPermaLink="false">http://jk3.us/?p=13#comment-17</guid>
		<description>Hashing passwords with a hash function like SHA1 or MD5 before storing will of course achieve exactly the same effect, and can easily be implemented... â€˜Distributed authenticationâ€™ is not the only solution.

Problem is, then you are depending on the site author to do The Right Thing. Which apparantly wasnâ€™t the case with SFx.

~Grauw</description>
		<content:encoded><![CDATA[<p>Hashing passwords with a hash function like SHA1 or MD5 before storing will of course achieve exactly the same effect, and can easily be implemented&#8230; â€˜Distributed authenticationâ€™ is not the only solution.</p>
<p>Problem is, then you are depending on the site author to do The Right Thing. Which apparantly wasnâ€™t the case with SFx.</p>
<p>~Grauw</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Administrator</title>
		<link>http://jk3.us/2005/07/14/time-is-ripe-for-distibuted-authentication/#comment-16</link>
		<dc:creator>Administrator</dc:creator>
		<pubDate>Fri, 15 Jul 2005 23:04:10 +0000</pubDate>
		<guid isPermaLink="false">http://jk3.us/?p=13#comment-16</guid>
		<description>That&#039;s pretty good list.  I don&#039;t claim to be any sort of expert on the subject, but I&#039;ve read up a little.  Here are some thoughts on a few items from your list:


Pubcookie: works fairly well for a small set of sites.  We implemented at my alma mater for all the many web services available, it&#039;s still dependant (I think) on a centralized server, no good for &quot;the whole web&quot;
LDAP: Would be a great backend for an identity server, but by itself I&#039;m afraid it would not be simple enough... would you have to log in as ldap://server.com/cn=Name,dc=server,dc=com, or whatever.
Identity Commons: it looks like they had the right idea, but 1) I can&#039;t find specs and 2) It looks like their site hasn&#039;t been updated in a year or so.
OpenSSO: Looks like another one aimed at a smaller set of sites, and not the web at large
Shibboleth: again, not for web at large
SourceID: no comment... can&#039;t figure anything out from their site.


Several of these are based on &lt;a href=&quot;http://en.wikipedia.org/wiki/SAML&quot; rel=&quot;nofollow&quot;&gt;SAML&lt;/a&gt;, which might be a good thing.  XML is good, but may be more than is needed for simple identification... it may be good for sharing data between your identity server and some web service. Thoughts?</description>
		<content:encoded><![CDATA[<p>That&#8217;s pretty good list.  I don&#8217;t claim to be any sort of expert on the subject, but I&#8217;ve read up a little.  Here are some thoughts on a few items from your list:</p>
<p>Pubcookie: works fairly well for a small set of sites.  We implemented at my alma mater for all the many web services available, it&#8217;s still dependant (I think) on a centralized server, no good for &#8220;the whole web&#8221;<br />
LDAP: Would be a great backend for an identity server, but by itself I&#8217;m afraid it would not be simple enough&#8230; would you have to log in as ldap://server.com/cn=Name,dc=server,dc=com, or whatever.<br />
Identity Commons: it looks like they had the right idea, but 1) I can&#8217;t find specs and 2) It looks like their site hasn&#8217;t been updated in a year or so.<br />
OpenSSO: Looks like another one aimed at a smaller set of sites, and not the web at large<br />
Shibboleth: again, not for web at large<br />
SourceID: no comment&#8230; can&#8217;t figure anything out from their site.</p>
<p>Several of these are based on <a href="http://en.wikipedia.org/wiki/SAML" rel="nofollow">SAML</a>, which might be a good thing.  XML is good, but may be more than is needed for simple identification&#8230; it may be good for sharing data between your identity server and some web service. Thoughts?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Lanphier</title>
		<link>http://jk3.us/2005/07/14/time-is-ripe-for-distibuted-authentication/#comment-15</link>
		<dc:creator>Rob Lanphier</dc:creator>
		<pubDate>Fri, 15 Jul 2005 22:09:06 +0000</pubDate>
		<guid isPermaLink="false">http://jk3.us/?p=13#comment-15</guid>
		<description>OpenID does seem to have the momentum right now.  What are some of the other solutions you&#039;ve looked into?  &lt;a href=&quot;http://spectaclar.org/wiki/Authentication_Systems&quot; rel=&quot;nofollow&quot;&gt;Here&#039;s a list of the solutions I&#039;ve compiled so far&lt;/a&gt;, and I&#039;d love it if you could add to it anything that you&#039;re aware of.

Thanks
Rob</description>
		<content:encoded><![CDATA[<p>OpenID does seem to have the momentum right now.  What are some of the other solutions you&#8217;ve looked into?  <a href="http://spectaclar.org/wiki/Authentication_Systems" rel="nofollow">Here&#8217;s a list of the solutions I&#8217;ve compiled so far</a>, and I&#8217;d love it if you could add to it anything that you&#8217;re aware of.</p>
<p>Thanks<br />
Rob</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic page generated in 0.235 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2012-05-12 00:10:27 -->

