<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: OpenID &#8211; Part III &#8211; PingPong</title>
	<atom:link href="http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/feed" rel="self" type="application/rss+xml" />
	<link>http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong</link>
	<description>Ben Hyde</description>
	<lastBuildDate>Tue, 31 Jan 2012 13:18:45 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: How OpenID works &#124; neumeier.org</title>
		<link>http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/comment-page-1#comment-1234</link>
		<dc:creator>How OpenID works &#124; neumeier.org</dc:creator>
		<pubDate>Sun, 04 Jan 2009 19:08:06 +0000</pubDate>
		<guid isPermaLink="false">http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/#comment-1234</guid>
		<description>[...] Part3 and flowchart: http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong [...]</description>
		<content:encoded><![CDATA[<p>[...] Part3 and flowchart: <a href="http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong" rel="nofollow">http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Security Roundtable &#187; Blog Archive &#187; The Security Roundtable for February 2007 - OpenID</title>
		<link>http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/comment-page-1#comment-582</link>
		<dc:creator>The Security Roundtable &#187; Blog Archive &#187; The Security Roundtable for February 2007 - OpenID</dc:creator>
		<pubDate>Thu, 15 Mar 2007 19:55:18 +0000</pubDate>
		<guid isPermaLink="false">http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/#comment-582</guid>
		<description>[...] OpenID pingpong - http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/ [...]</description>
		<content:encoded><![CDATA[<p>[...] OpenID pingpong &#8211; <a href="http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/" rel="nofollow">http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: it06.free.fr - Openid : une nouvelle vision décentralisée de la gestion de l’identité numérique.</title>
		<link>http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/comment-page-1#comment-581</link>
		<dc:creator>it06.free.fr - Openid : une nouvelle vision décentralisée de la gestion de l’identité numérique.</dc:creator>
		<pubDate>Sun, 11 Mar 2007 21:13:47 +0000</pubDate>
		<guid isPermaLink="false">http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/#comment-581</guid>
		<description>[...] La dynamique complète d’authentification est donnée dans l’article &#8220;openid pingpong&#8221;. [...]</description>
		<content:encoded><![CDATA[<p>[...] La dynamique complète d’authentification est donnée dans l’article &#8220;openid pingpong&#8221;. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charles Darke</title>
		<link>http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/comment-page-1#comment-580</link>
		<dc:creator>Charles Darke</dc:creator>
		<pubDate>Tue, 06 Mar 2007 13:25:28 +0000</pubDate>
		<guid isPermaLink="false">http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/#comment-580</guid>
		<description>At or around stage 9 in the diagram. If Bob turned evil and wanted to log onto Trevor site (impersonating Alice) could Bob do this? That is, Bob would log on to Trevor and use any information previously given by Alice etc. to try to authenticate.</description>
		<content:encoded><![CDATA[<p>At or around stage 9 in the diagram. If Bob turned evil and wanted to log onto Trevor site (impersonating Alice) could Bob do this? That is, Bob would log on to Trevor and use any information previously given by Alice etc. to try to authenticate.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brian</title>
		<link>http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/comment-page-1#comment-579</link>
		<dc:creator>Brian</dc:creator>
		<pubDate>Wed, 28 Feb 2007 10:17:25 +0000</pubDate>
		<guid isPermaLink="false">http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/#comment-579</guid>
		<description>@Cheryl - As you pointed out, the basic problem to solve is how to verify if the person entering the URL is actually the person who OWNS the URL.

Steve doesn&#039;t actually know anything about the person entering the URL on his web page.  The URL says to ask Victor, so Steve will actually make the request to Victor indirectly, by redirecting Alice&#039;s browser to an authentication URL at Victor.  Thus, Victor will receive Alice&#039;s cookies in this redirected request, and these cookies may contain a token that represents Alice&#039;s login session with Victor, if she has already logged into Victor once before.  In this case, Victor knows Alice already, and also knows if the URL belongs to Alice.  Thus, Victor can answer YES or NO and sign the answer using a shared key only Victor and Steve know.  The signed answer is sent back to Steve and Steve can verify the signature came from Victor.

If Alice has never logged into Victor before, Alice will not yet have a session cookie with Victor, and Victor will present Alice with a login page. Alice (or the bad guy using Alice&#039;s URL) must now log into Victor with a username/password and get a session cookie with Victor before Victor can answer Steve with YES or NO.

So you cannot simply pose as Alice by using her URL on an OpenID site, unless you know Alice&#039;s username/password with Victor. If you are Alice, and you&#039;ve already logged into Victor once, you can use your OpenID  URL at any OpenID site without ever needing to enter a username/password again (until your session expires with Victor)

Hope that clears it up.
Cheers!
-- Brian</description>
		<content:encoded><![CDATA[<p>@Cheryl &#8211; As you pointed out, the basic problem to solve is how to verify if the person entering the URL is actually the person who OWNS the URL.</p>
<p>Steve doesn&#8217;t actually know anything about the person entering the URL on his web page.  The URL says to ask Victor, so Steve will actually make the request to Victor indirectly, by redirecting Alice&#8217;s browser to an authentication URL at Victor.  Thus, Victor will receive Alice&#8217;s cookies in this redirected request, and these cookies may contain a token that represents Alice&#8217;s login session with Victor, if she has already logged into Victor once before.  In this case, Victor knows Alice already, and also knows if the URL belongs to Alice.  Thus, Victor can answer YES or NO and sign the answer using a shared key only Victor and Steve know.  The signed answer is sent back to Steve and Steve can verify the signature came from Victor.</p>
<p>If Alice has never logged into Victor before, Alice will not yet have a session cookie with Victor, and Victor will present Alice with a login page. Alice (or the bad guy using Alice&#8217;s URL) must now log into Victor with a username/password and get a session cookie with Victor before Victor can answer Steve with YES or NO.</p>
<p>So you cannot simply pose as Alice by using her URL on an OpenID site, unless you know Alice&#8217;s username/password with Victor. If you are Alice, and you&#8217;ve already logged into Victor once, you can use your OpenID  URL at any OpenID site without ever needing to enter a username/password again (until your session expires with Victor)</p>
<p>Hope that clears it up.<br />
Cheers!<br />
&#8211; Brian</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cheryl</title>
		<link>http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/comment-page-1#comment-578</link>
		<dc:creator>Cheryl</dc:creator>
		<pubDate>Wed, 31 Jan 2007 00:35:10 +0000</pubDate>
		<guid isPermaLink="false">http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/#comment-578</guid>
		<description>First off, I&#039;m a non-techie.

I&#039;m getting confused at steps 12-14. How does Victor check that it&#039;s actually Alice who is asking and not just someone who knows Alice&#039;s OpenID URL?

Thanks.</description>
		<content:encoded><![CDATA[<p>First off, I&#8217;m a non-techie.</p>
<p>I&#8217;m getting confused at steps 12-14. How does Victor check that it&#8217;s actually Alice who is asking and not just someone who knows Alice&#8217;s OpenID URL?</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen Pascoe&#8217;s Blog&#187; Blog Archive
 &#187; OpenID and LID compared</title>
		<link>http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/comment-page-1#comment-577</link>
		<dc:creator>Stephen Pascoe&#8217;s Blog&#187; Blog Archive
 &#187; OpenID and LID compared</dc:creator>
		<pubDate>Fri, 13 Oct 2006 15:15:05 +0000</pubDate>
		<guid isPermaLink="false">http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/#comment-577</guid>
		<description>[...] ely documented here. I recommend looking at the diagram  Ben Hyde&#8217;s blog entry to see a visual representation of the process. LID: The protocol [...]</description>
		<content:encoded><![CDATA[<p>[...] ely documented here. I recommend looking at the diagram  Ben Hyde&#8217;s blog entry to see a visual representation of the process. LID: The protocol [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lopo Lencastre de Almeida</title>
		<link>http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/comment-page-1#comment-576</link>
		<dc:creator>Lopo Lencastre de Almeida</dc:creator>
		<pubDate>Tue, 04 Jul 2006 15:29:54 +0000</pubDate>
		<guid isPermaLink="false">http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/#comment-576</guid>
		<description>This is very interesting for remote administration (TAx Authorities, Healthcare systems, etc).
We are going to look further on this to deal with remote identification in Care2x and Care3G.

Thanks for the nice explanation and all comments.

Best regards</description>
		<content:encoded><![CDATA[<p>This is very interesting for remote administration (TAx Authorities, Healthcare systems, etc).<br />
We are going to look further on this to deal with remote identification in Care2x and Care3G.</p>
<p>Thanks for the nice explanation and all comments.</p>
<p>Best regards</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: This Old Network  &#187; OpenID enabled claimID - almost here</title>
		<link>http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/comment-page-1#comment-575</link>
		<dc:creator>This Old Network  &#187; OpenID enabled claimID - almost here</dc:creator>
		<pubDate>Tue, 06 Jun 2006 17:39:30 +0000</pubDate>
		<guid isPermaLink="false">http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/#comment-575</guid>
		<description>[...] t couple weeks getting claimID ready for her transition to being both an OpenID server and consumer.  We will be able to add a layer of user-centered verification and [...]</description>
		<content:encoded><![CDATA[<p>[...] t couple weeks getting claimID ready for her transition to being both an OpenID server and consumer.  We will be able to add a layer of user-centered verification and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steven J. Murdoch</title>
		<link>http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/comment-page-1#comment-574</link>
		<dc:creator>Steven J. Murdoch</dc:creator>
		<pubDate>Wed, 17 May 2006 19:43:14 +0000</pubDate>
		<guid isPermaLink="false">http://enthusiasm.cozy.org/archives/2005/05/openid-part-iii-pingpong/#comment-574</guid>
		<description>I also produced a &lt;a href=&quot;http://www.cl.cam.ac.uk/users/sjm217/misc/openid-protocol.pdf&quot; rel=&quot;nofollow&quot;&gt;protocol diagram&lt;/a&gt;, which goes into a little bit more detail in the message content/cryptography, and includes the association phase, but otherwise is largely similar. I hope it will also be of help.</description>
		<content:encoded><![CDATA[<p>I also produced a <a href="http://www.cl.cam.ac.uk/users/sjm217/misc/openid-protocol.pdf" rel="nofollow">protocol diagram</a>, which goes into a little bit more detail in the message content/cryptography, and includes the association phase, but otherwise is largely similar. I hope it will also be of help.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

