[OpenID] Requiring Pseudonymous Identifier
SitG Admin
sysadmin at shadowsinthegarden.com
Wed May 13 15:36:42 UTC 2009
>The OpenID spec is written with one user controlling an identifier
>in mind. RPs all over the world are making that assumption. If an
>shared "group" identifier is ever used to log into any of these RPs,
>then people may be unwittingly sharing their data with a large group
>of people.
Then, am I out of spec for offering a dedicated OP where the *users*
do NOT control the identifier; they merely use
'shadowsinthegarden.com/everyone' to log in with the ACL permitted to
everyone?
(Concerned minds may inquire about squandering CPU cycles on login
that could be achieved with a simple session. I looked into this;
including '#auditing' at the end of a URI should signal to the RP
that it will use OpenID and be transparent about the internals.)
>There are plenty of other more appropriate ways to assert groups.
Consistency, in this case, happily doesn't oblige me to use one of them ;)
-Shade
More information about the general
mailing list