<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: OpenID</title>
	<atom:link href="http://enthusiasm.cozy.org/archives/2005/05/openid/feed" rel="self" type="application/rss+xml" />
	<link>http://enthusiasm.cozy.org/archives/2005/05/openid</link>
	<description>Ben Hyde</description>
	<lastBuildDate>Sun, 14 Mar 2010 21:10:43 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: How OpenID works &#124; neumeier.org</title>
		<link>http://enthusiasm.cozy.org/archives/2005/05/openid/comment-page-1#comment-1233</link>
		<dc:creator>How OpenID works &#124; neumeier.org</dc:creator>
		<pubDate>Sun, 04 Jan 2009 19:07:47 +0000</pubDate>
		<guid isPermaLink="false">http://enthusiasm.cozy.org/archives/2005/05/openid/#comment-1233</guid>
		<description>[...] Part 1: http://enthusiasm.cozy.org/archives/2005/05/openid [...]</description>
		<content:encoded><![CDATA[<p>[...] Part 1: <a href="http://enthusiasm.cozy.org/archives/2005/05/openid" rel="nofollow">http://enthusiasm.cozy.org/archives/2005/05/openid</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ascription is an Anathema to any Enthusiasm  &#187; Blog Archive   &#187; OpenID - Part II</title>
		<link>http://enthusiasm.cozy.org/archives/2005/05/openid/comment-page-1#comment-558</link>
		<dc:creator>Ascription is an Anathema to any Enthusiasm  &#187; Blog Archive   &#187; OpenID - Part II</dc:creator>
		<pubDate>Mon, 23 May 2005 16:55:00 +0000</pubDate>
		<guid isPermaLink="false">http://enthusiasm.cozy.org/archives/2005/05/openid/#comment-558</guid>
		<description>[...] 		   	 		 			&#171; Yes, but&#8230; 			 		 	 		 			OpenID - Part II 	 			      					I was confused about OpenID. This posting is second run at explaining how it works. Hopefully I’l [...]</description>
		<content:encoded><![CDATA[<p>[...] 		   	 		 			&laquo; Yes, but&#8230; 			 		 	 		 			OpenID &#8211; Part II 	 			      					I was confused about OpenID. This posting is second run at explaining how it works. Hopefully I’l [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben Hyde</title>
		<link>http://enthusiasm.cozy.org/archives/2005/05/openid/comment-page-1#comment-556</link>
		<dc:creator>Ben Hyde</dc:creator>
		<pubDate>Fri, 20 May 2005 14:34:13 +0000</pubDate>
		<guid isPermaLink="false">http://enthusiasm.cozy.org/archives/2005/05/openid/#comment-556</guid>
		<description>The fine grain control comment was triggered by two things.

In the linked description there appears this bit &quot;... server then returns to the client&#039;s browser the: ... the user&#039;s identity server URL ...
 Perhaps a FOAF URL ...&quot;   That&#039;s a red flag for me; since FOAF tends to encourage users into revealing more information than is actually necessary.

The second reason was that I didn&#039;t see a clear policy to keep what&#039;s revealed extremely minimal; and it&#039;s necessary complement a means to extend that.  Any such mechinism will have to interact with the user to gain his permission, and that notches up the complexity of getting it all right.

Now having been forced to think about this aspect some more I recall that it&#039;s key to get right early that the sources for revealed information not get tied to the vouching entity too tightly.  The vouching entity has a advantagous position, as the first stop for info about the user, and a good design strives to keep the vouching agent with as little information about the user as is technically possible.</description>
		<content:encoded><![CDATA[<p>The fine grain control comment was triggered by two things.</p>
<p>In the linked description there appears this bit &#8220;&#8230; server then returns to the client&#8217;s browser the: &#8230; the user&#8217;s identity server URL &#8230;<br />
 Perhaps a FOAF URL &#8230;&#8221;   That&#8217;s a red flag for me; since FOAF tends to encourage users into revealing more information than is actually necessary.</p>
<p>The second reason was that I didn&#8217;t see a clear policy to keep what&#8217;s revealed extremely minimal; and it&#8217;s necessary complement a means to extend that.  Any such mechinism will have to interact with the user to gain his permission, and that notches up the complexity of getting it all right.</p>
<p>Now having been forced to think about this aspect some more I recall that it&#8217;s key to get right early that the sources for revealed information not get tied to the vouching entity too tightly.  The vouching entity has a advantagous position, as the first stop for info about the user, and a good design strives to keep the vouching agent with as little information about the user as is technically possible.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin Atkins</title>
		<link>http://enthusiasm.cozy.org/archives/2005/05/openid/comment-page-1#comment-557</link>
		<dc:creator>Martin Atkins</dc:creator>
		<pubDate>Fri, 20 May 2005 13:42:04 +0000</pubDate>
		<guid isPermaLink="false">http://enthusiasm.cozy.org/archives/2005/05/openid/#comment-557</guid>
		<description>Regarding the &quot;fine grain control&quot; over what&#039;s revealed, I don&#039;t really see what you mean. The only thing that OpenID reveals is the answer to the question &quot;Does the user own this identity URL?&quot;. I suppose that implicitly reveals a URL for the user, though that URL need point to nothing more interesting than a blank HTML document with a LINK element in its HEAD.

OpenID explicitly avoids profile exchange because that&#039;s someone else&#039;s problem. I believe the current thinking is that the identity URL can also have a FOAF auto-discovery URL which sites could potentially use, though that&#039;s not part of OpenID and something like this will likely just become a de-facto standard as people start to use OpenID for different things.</description>
		<content:encoded><![CDATA[<p>Regarding the &#8220;fine grain control&#8221; over what&#8217;s revealed, I don&#8217;t really see what you mean. The only thing that OpenID reveals is the answer to the question &#8220;Does the user own this identity URL?&#8221;. I suppose that implicitly reveals a URL for the user, though that URL need point to nothing more interesting than a blank HTML document with a LINK element in its HEAD.</p>
<p>OpenID explicitly avoids profile exchange because that&#8217;s someone else&#8217;s problem. I believe the current thinking is that the identity URL can also have a FOAF auto-discovery URL which sites could potentially use, though that&#8217;s not part of OpenID and something like this will likely just become a de-facto standard as people start to use OpenID for different things.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
