[OpenID] Re: RP's storing user-data at OP's (but inaccessible to OP's)

SitG Admin sysadmin at shadowsinthegarden.com
Fri May 1 15:54:06 UTC 2009


To clarify, since I noticed that I sent a similar idea to Chris 
Messina a while back (on portable data),

>Just an odd thought that came to me while considering OAuth; and 
>also while wondering how to privately store users' data off-site so 
>that my RP wouldn't need to retain any data on users at ALL;

I wasn't thinking of data that "belongs to" the user, here; just 
details like "This is the user's configuration settings; their 
preferred 'skin' for our interface, etcetera." - if the OP can hold 
onto these for the user, great! But still encrypted, because it's 
between the user and a RP how that user wants to view that RP's site; 
nobody else's business.

-Shade



More information about the general mailing list