[OpenID] Requiring Pseudonymous Identifier

SitG Admin sysadmin at shadowsinthegarden.com
Wed May 13 15:36:42 UTC 2009


>The OpenID spec is written with one user controlling an identifier 
>in mind.  RPs all over the world are making that assumption.  If an 
>shared "group" identifier is ever used to log into any of these RPs, 
>then people may be unwittingly sharing their data with a large group 
>of people.

Then, am I out of spec for offering a dedicated OP where the *users* 
do NOT control the identifier; they merely use 
'shadowsinthegarden.com/everyone' to log in with the ACL permitted to 
everyone?

(Concerned minds may inquire about squandering CPU cycles on login 
that could be achieved with a simple session. I looked into this; 
including '#auditing' at the end of a URI should signal to the RP 
that it will use OpenID and be transparent about the internals.)

>There are plenty of other more appropriate ways to assert groups.

Consistency, in this case, happily doesn't oblige me to use one of them ;)

-Shade



More information about the general mailing list