[OpenID] Anonymous, meaningless?

SitG Admin sysadmin at shadowsinthegarden.com
Thu Sep 4 04:21:32 UTC 2008


>I daresay your concerns are completely valid (except that 512 bytes 
>* 2000 users = 1 MB, != 1GB).

I've said this before, but I suck at math :)

>A standard policy web email services employ is "if you don't stop by 
>once in six months, your account is deleted".  You could perhaps do 
>the same.

Another area where I strive for (yet fail to reach) perfection in my code ;)

Perhaps "if you don't stop by in 6 months, maintenance routines will 
check your site to see if it's still up, and if there isn't an active 
URI there anymore, your account will be presumed unrenewable and 
removed", with several checks occurring over a period of a month just 
to be sure the site wasn't suffering some downtime, before giving up 
on it. (Or much sooner if the *site* was up but *that URI* wasn't 
around anymore.) Not sure how this would interact with URI's that the 
site would normally identify with generation fragments, though.

Come to think of it, how do generation fragments work on sites that 
aren't offering OpenID to all their users, but where the individual 
users are just adding their own OpenID headers to each page? How does 
an OP determine that www.somehost.com/user is a different user than 
it was 2 months ago, when the site permits someone else to recreate 
with the same name so soon after deletion? I guess that would go into 
an "OP best practices" list, to be careful about giving the same 
generational identifier to someone who has to reset their account 
with the OP using nothing more than "I have this URI *now*." (though 
what being careful would *mean* in this context, I have no idea).

-Shade



More information about the general mailing list