<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=Content-Type content="text/html; charset=us-ascii">
<meta name=Generator content="Microsoft Word 11 (filtered medium)">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]-->
<style>
<!--
/* Font Definitions */
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:sans-serif;
        panose-1:0 0 0 0 0 0 0 0 0 0;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman";}
h1
        {margin-top:12.0pt;
        margin-right:0in;
        margin-bottom:3.0pt;
        margin-left:0in;
        page-break-after:avoid;
        font-size:16.0pt;
        font-family:Arial;
        font-weight:bold;}
h2
        {margin-top:12.0pt;
        margin-right:0in;
        margin-bottom:3.0pt;
        margin-left:0in;
        page-break-after:avoid;
        font-size:14.0pt;
        font-family:Arial;
        font-weight:bold;
        font-style:italic;}
h3
        {margin-top:12.0pt;
        margin-right:0in;
        margin-bottom:3.0pt;
        margin-left:0in;
        page-break-after:avoid;
        font-size:12.0pt;
        font-family:Arial;
        font-weight:bold;}
h4
        {margin-top:12.0pt;
        margin-right:0in;
        margin-bottom:3.0pt;
        margin-left:0in;
        page-break-after:avoid;
        font-size:10.0pt;
        font-family:"Times New Roman";
        font-weight:bold;
        font-style:italic;}
p.MsoHeader, li.MsoHeader, div.MsoHeader
        {margin:0in;
        margin-bottom:.0001pt;
        border:none;
        padding:0in;
        font-size:10.0pt;
        font-family:Arial;}
p.MsoFooter, li.MsoFooter, div.MsoFooter
        {margin:0in;
        margin-bottom:.0001pt;
        border:none;
        padding:0in;
        font-size:10.0pt;
        font-family:Arial;}
p.MsoTitle, li.MsoTitle, div.MsoTitle
        {margin-top:0in;
        margin-right:0in;
        margin-bottom:9.0pt;
        margin-left:0in;
        text-align:center;
        font-size:16.0pt;
        font-family:Arial;
        font-weight:bold;}
p.MsoBodyText, li.MsoBodyText, div.MsoBodyText
        {margin-top:0in;
        margin-right:0in;
        margin-bottom:6.0pt;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman";}
p.MsoSubtitle, li.MsoSubtitle, div.MsoSubtitle
        {margin-top:0in;
        margin-right:0in;
        margin-bottom:.25in;
        margin-left:0in;
        text-align:center;
        font-size:12.0pt;
        font-family:Arial;}
a:link, span.MsoHyperlink
        {color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {color:purple;
        text-decoration:underline;}
p
        {mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman";}
tt
        {font-family:"Courier New";}
p.Quote, li.Quote, div.Quote
        {margin-top:0in;
        margin-right:.5in;
        margin-bottom:6.0pt;
        margin-left:.5in;
        font-size:12.0pt;
        font-family:"Times New Roman";
        font-style:italic;}
p.Wiki, li.Wiki, div.Wiki
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";}
p.Graphic, li.Graphic, div.Graphic
        {margin-top:0in;
        margin-right:0in;
        margin-bottom:6.0pt;
        margin-left:0in;
        text-align:center;
        font-size:10.0pt;
        font-family:Arial;
        font-style:italic;}
span.EmailStyle28
        {mso-style-type:personal-reply;
        font-family:Arial;
        color:navy;}
/* Page Definitions */
@page
        {mso-endnote-separator:url("cid:header.htm\@01C6F3BB.D7B20580") es;
        mso-endnote-continuation-separator:url("cid:header.htm\@01C6F3BB.D7B20580") ecs;}
@page Section1
        {size:8.5in 11.0in;
        margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
        {page:Section1;}
/* List Definitions */
@list l0
        {mso-list-id:-132;
        mso-list-type:simple;
        mso-list-template-ids:-1328661930;}
@list l0:level1
        {mso-level-tab-stop:1.25in;
        mso-level-number-position:left;
        margin-left:1.25in;
        text-indent:-.25in;}
@list l1
        {mso-list-id:-131;
        mso-list-type:simple;
        mso-list-template-ids:-909054546;}
@list l1:level1
        {mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        margin-left:1.0in;
        text-indent:-.25in;}
@list l2
        {mso-list-id:-130;
        mso-list-type:simple;
        mso-list-template-ids:531935922;}
@list l2:level1
        {mso-level-tab-stop:.75in;
        mso-level-number-position:left;
        margin-left:.75in;
        text-indent:-.25in;}
@list l3
        {mso-list-id:-129;
        mso-list-type:simple;
        mso-list-template-ids:2046339550;}
@list l3:level1
        {mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l4
        {mso-list-id:-128;
        mso-list-type:simple;
        mso-list-template-ids:82112870;}
@list l4:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:1.25in;
        mso-level-number-position:left;
        margin-left:1.25in;
        text-indent:-.25in;
        font-family:Symbol;}
@list l5
        {mso-list-id:-127;
        mso-list-type:simple;
        mso-list-template-ids:-1405587484;}
@list l5:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        margin-left:1.0in;
        text-indent:-.25in;
        font-family:Symbol;}
@list l6
        {mso-list-id:-126;
        mso-list-type:simple;
        mso-list-template-ids:828961842;}
@list l6:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:.75in;
        mso-level-number-position:left;
        margin-left:.75in;
        text-indent:-.25in;
        font-family:Symbol;}
@list l7
        {mso-list-id:-125;
        mso-list-type:simple;
        mso-list-template-ids:1053828088;}
@list l7:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Symbol;}
@list l8
        {mso-list-id:-120;
        mso-list-type:simple;
        mso-list-template-ids:-2021464228;}
@list l8:level1
        {mso-level-tab-stop:.25in;
        mso-level-number-position:left;
        margin-left:.25in;
        text-indent:-.25in;}
@list l9
        {mso-list-id:-119;
        mso-list-type:simple;
        mso-list-template-ids:445916746;}
@list l9:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:.25in;
        mso-level-number-position:left;
        margin-left:.25in;
        text-indent:-.25in;
        font-family:Symbol;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
-->
</style>
<!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=EN-US link=blue vlink=purple>
<div class=Section1>
<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>+1. I use it daily already. Ph-Off is a
great solution and one that would benefit from wide distribution. Eventually this
type of “website whitelisting” should be built directly in the
browser, the same way IE 7 and Firefox 2 are already building in a blacklist
notification feature for detecting phishing sites.<o:p></o:p></span></font></p>
<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p>
<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>=Drummond <o:p></o:p></span></font></p>
<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p>
<div>
<div class=MsoNormal align=center style='text-align:center'><font size=3
face="Times New Roman"><span style='font-size:12.0pt'>
<hr size=2 width="100%" align=center tabindex=-1>
</span></font></div>
<p class=MsoNormal><b><font size=2 face=Tahoma><span style='font-size:10.0pt;
font-family:Tahoma;font-weight:bold'>From:</span></font></b><font size=2
face=Tahoma><span style='font-size:10.0pt;font-family:Tahoma'>
general-bounces@openid.net [mailto:general-bounces@openid.net] <b><span
style='font-weight:bold'>On Behalf Of </span></b>Recordon, David<br>
<b><span style='font-weight:bold'>Sent:</span></b> Thursday, October 19, 2006
11:30 AM<br>
<b><span style='font-weight:bold'>To:</span></b> andy.dale@ootao.com<br>
<b><span style='font-weight:bold'>Cc:</span></b> Digital Identity Exchange;
specs@openid.net; general@openid.net<br>
<b><span style='font-weight:bold'>Subject:</span></b> RE: Re[2]: [dix] Re:
Gathering requirements for in-browserOpenIDsupport</span></font><o:p></o:p></p>
</div>
<p class=MsoNormal><font size=3 face="Times New Roman"><span style='font-size:
12.0pt'><o:p> </o:p></span></font></p>
<p class=MsoNormal><font size=2 color=blue face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:blue'>Andy,</span></font><o:p></o:p></p>
<p class=MsoNormal><font size=2 color=blue face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:blue'>I think it is incredibly useful in showing
the technology needed to help protect users with systems like this. I'd
love to see it as part of the Heraldry project, you are already a
committer, assuming you'd be willing to contribute it.</span></font><o:p></o:p></p>
<p class=MsoNormal><font size=3 face="Times New Roman"><span style='font-size:
12.0pt'> <o:p></o:p></span></font></p>
<p class=MsoNormal><font size=2 color=blue face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:blue'>--David</span></font><o:p></o:p></p>
<p class=MsoNormal><font size=3 face="Times New Roman"><span style='font-size:
12.0pt'><o:p> </o:p></span></font></p>
<div class=MsoNormal align=center style='text-align:center'><font size=3
face="Times New Roman"><span style='font-size:12.0pt'>
<hr size=2 width="100%" align=center tabIndex=-1>
</span></font></div>
<p class=MsoNormal style='margin-bottom:12.0pt'><b><font size=2 face=Tahoma><span
style='font-size:10.0pt;font-family:Tahoma;font-weight:bold'>From:</span></font></b><font
size=2 face=Tahoma><span style='font-size:10.0pt;font-family:Tahoma'>
specs-bounces@openid.net [mailto:specs-bounces@openid.net] <b><span
style='font-weight:bold'>On Behalf Of </span></b>andy.dale@ootao.com<br>
<b><span style='font-weight:bold'>Sent:</span></b> Wednesday, October 18, 2006
11:44 PM<br>
<b><span style='font-weight:bold'>To:</span></b> Digital Identity Exchange<br>
<b><span style='font-weight:bold'>Cc:</span></b> Digital Identity Exchange;
specs@openid.net; general@openid.net<br>
<b><span style='font-weight:bold'>Subject:</span></b> Re: Re[2]: [dix] Re:
Gathering requirements for in-browser OpenIDsupport</span></font><o:p></o:p></p>
<p class=MsoNormal style='margin-bottom:12.0pt'><font size=3
face="Times New Roman"><span style='font-size:12.0pt'><br>
</span></font><font size=2 face=sans-serif><span style='font-size:10.0pt;
font-family:sans-serif'>I'd be interested to hear if people think the ph-off
plugin is useful or not.... If not why not? </span></font><br>
<br>
<font size=2 face=sans-serif><span style='font-size:10.0pt;font-family:sans-serif'>If
people think it's useful then I will happily extend it and make it more usable
and I will put it into whatever open source project would like to house it. </span></font><br>
<br>
<font size=2 face=sans-serif><span style='font-size:10.0pt;font-family:sans-serif'>I
built it as a proof of concept that it _could_ be done... Now the question of
_should_ it be done :-)</span></font> <br>
<br>
<font size=2 face=sans-serif><span style='font-size:10.0pt;font-family:sans-serif'>http://chile.ootao.com/phoff/</span></font>
<br>
<br>
<br>
<font size=2 face=sans-serif><span style='font-size:10.0pt;font-family:sans-serif'>Andy
Dale<br>
ooTao, Inc.<br>
<br>
Phone: 877-213-7935<br>
Fax: 877-213-7935<br>
<br>
i-name: =Andy.Dale<br>
http://xri.net/=andy.dale<br>
<br>
***************************************************************************<br>
If you don't have an i-name yet use this link to visit one of our partners and
buy one:<br>
<br>
http://www.ezibroker.net/partners.html<br>
<br>
***************************************************************************<br>
</span></font><br>
<br>
<o:p></o:p></p>
<table class=MsoNormalTable border=0 cellpadding=0 width="100%"
style='width:100.0%'>
<tr>
<td width="40%" valign=top style='width:40.0%;padding:.75pt .75pt .75pt .75pt'>
<p class=MsoNormal><b><font size=1 face=sans-serif><span style='font-size:
7.5pt;font-family:sans-serif;font-weight:bold'>Chris Drake
<christopher@pobox.com></span></font></b><font size=1 face=sans-serif><span
style='font-size:7.5pt;font-family:sans-serif'> </span></font><o:p></o:p></p>
<p><font size=1 face=sans-serif><span style='font-size:7.5pt;font-family:
sans-serif'>10/18/2006 07:20 PM</span></font> <o:p></o:p></p>
<table class=MsoNormalTable border=1 cellpadding=0>
<tr>
<td valign=top bgcolor=white style='background:white;padding:.75pt .75pt .75pt .75pt'>
<p class=MsoNormal align=center style='text-align:center'><font size=1
face=sans-serif><span style='font-size:7.5pt;font-family:sans-serif'>Please
respond to<br>
Digital Identity Exchange <dix@ietf.org></span></font><o:p></o:p></p>
</td>
</tr>
</table>
<p><font size=3 face="Times New Roman"><span style='font-size:12.0pt'><o:p></o:p></span></font></p>
</td>
<td width="59%" valign=top style='width:59.0%;padding:.75pt .75pt .75pt .75pt'>
<table class=MsoNormalTable border=0 cellpadding=0 width="100%"
style='width:100.0%'>
<tr>
<td valign=top style='padding:.75pt .75pt .75pt .75pt'>
<p class=MsoNormal align=right style='text-align:right'><font size=1
face=sans-serif><span style='font-size:7.5pt;font-family:sans-serif'>To</span></font><o:p></o:p></p>
</td>
<td valign=top style='padding:.75pt .75pt .75pt .75pt'>
<p class=MsoNormal><font size=1 face=sans-serif><span style='font-size:
7.5pt;font-family:sans-serif'>Scott Kveton <scott@janrain.com></span></font>
<o:p></o:p></p>
</td>
</tr>
<tr>
<td valign=top style='padding:.75pt .75pt .75pt .75pt'>
<p class=MsoNormal align=right style='text-align:right'><font size=1
face=sans-serif><span style='font-size:7.5pt;font-family:sans-serif'>cc</span></font><o:p></o:p></p>
</td>
<td valign=top style='padding:.75pt .75pt .75pt .75pt'>
<p class=MsoNormal><font size=1 face=sans-serif><span style='font-size:
7.5pt;font-family:sans-serif'>specs@openid.net, general@openid.net, Mike
Glover <mpg4@janrain.com>, Digital Identity Exchange
<dix@ietf.org></span></font> <o:p></o:p></p>
</td>
</tr>
<tr>
<td valign=top style='padding:.75pt .75pt .75pt .75pt'>
<p class=MsoNormal align=right style='text-align:right'><font size=1
face=sans-serif><span style='font-size:7.5pt;font-family:sans-serif'>Subject</span></font><o:p></o:p></p>
</td>
<td valign=top style='padding:.75pt .75pt .75pt .75pt'>
<p class=MsoNormal><font size=1 face=sans-serif><span style='font-size:
7.5pt;font-family:sans-serif'>Re[2]: [dix] Re: Gathering requirements for
in-browser OpenID support</span></font><o:p></o:p></p>
</td>
</tr>
</table>
<p class=MsoNormal><font size=3 face="Times New Roman"><span
style='font-size:12.0pt'><o:p> </o:p></span></font></p>
<table class=MsoNormalTable border=0 cellpadding=0>
<tr>
<td valign=top style='padding:.75pt .75pt .75pt .75pt'>
<p class=MsoNormal><font size=3 face="Times New Roman"><span
style='font-size:12.0pt'><o:p> </o:p></span></font></p>
</td>
<td valign=top style='padding:.75pt .75pt .75pt .75pt'>
<p class=MsoNormal><font size=3 face="Times New Roman"><span
style='font-size:12.0pt'><o:p> </o:p></span></font></p>
</td>
</tr>
</table>
<p class=MsoNormal><font size=3 face="Times New Roman"><span
style='font-size:12.0pt'><o:p></o:p></span></font></p>
</td>
</tr>
</table>
<p class=MsoNormal style='margin-bottom:12.0pt'><font size=3
face="Times New Roman"><span style='font-size:12.0pt'><br>
<br>
<br>
</span></font><tt><font size=2 face="Courier New"><span style='font-size:10.0pt'>Hi
Scott,</span></font></tt><font size=2 face="Courier New"><span
style='font-size:10.0pt;font-family:"Courier New"'><br>
<br>
<tt><font face="Courier New">All solutions for client-based MITM and phishing
prevention can easily</font></tt><br>
<tt><font face="Courier New">be built on top of OpenID 2.0 if we adopt the
OpenIDHTTPAuth proposal.</font></tt><br>
<br>
<tt><font face="Courier New">We can then leave these people to build their
tools and protection</font></tt><br>
<tt><font face="Courier New">howsoever they like, safe in the knowledge that
when it's *done*,</font></tt><br>
<tt><font face="Courier New">there will be a range of new plugins that will
immediately work with</font></tt><br>
<tt><font face="Courier New">all OpenID 2.0 enabled sites - and best of all -
it does not have to</font></tt><br>
<tt><font face="Courier New">hold up the OpenID 2.0 development in the
meantime.</font></tt><br>
<br>
<tt><font face="Courier New">The only thing we need to give to these tools is a
way to get the</font></tt><br>
<tt><font face="Courier New">login process started - that is - OpenIDHTTPAuth:
the downloaded</font></tt><br>
<tt><font face="Courier New">plugin needs to be able to get an entry point for
the OpenID CGI code</font></tt><br>
<tt><font face="Courier New">on the web site.</font></tt><br>
<br>
<tt><font face="Courier New">-----------</font></tt><br>
<br>
<tt><font face="Courier New">Here is a copy of my vote to include the above
proposal, which</font></tt><br>
<tt><font face="Courier New">contains more info abut it too:</font></tt><br>
<br>
<br>
<tt><font face="Courier New">Hi,</font></tt><br>
<br>
<tt><font face="Courier New">Why's this proposal "depreciated" ?</font></tt><br>
<tt><font face="Courier New">( http://www.lifewiki.net/openid/OpenIDProposals )</font></tt><br>
<br>
<tt><font face="Courier New">I'm casting my vote here:</font></tt><br>
<br>
<tt><font face="Courier New">+1 to [PROPOSAL] bare response / bare request</font></tt><br>
<br>
<tt><font face="Courier New">Besides the listed uses, it also allows IdPs to
layer privacy and</font></tt><br>
<tt><font face="Courier New">delegation easily on top of OpenID, as well as
permitting cool future</font></tt><br>
<tt><font face="Courier New">features (like letting a user change something at
their IdP, and have</font></tt><br>
<tt><font face="Courier New">that change be "pushed out" to all
relevant RPs).</font></tt><br>
<br>
<tt><font face="Courier New">This is a small and simple to implement
"hook" which I believe will be</font></tt><br>
<tt><font face="Courier New">the dominating bit of OpenID protocol use in
future.</font></tt><br>
<br>
<tt><font face="Courier New">Alternatively - if we can standardize a way for
the OpenIDHTTPAuth</font></tt><br>
<tt><font face="Courier New">proposed extension to discover the RP's OpenID
"entry point" [so as to</font></tt><br>
<tt><font face="Courier New">reliably eliminate the "optional" first
step proposed here</font></tt><br>
<tt><font face="Courier New">http://www.lifewiki.net/openid/OpenIDHTTPAuth ] -
this is a good</font></tt><br>
<tt><font face="Courier New">working alterative way to accommodate the
"bare response" part that we</font></tt><br>
<tt><font face="Courier New">need.</font></tt><br>
<br>
<tt><font face="Courier New">So...</font></tt><br>
<br>
<tt><font face="Courier New">+1 to OpenIDHTTPAuth - on the proviso RP's publish
an endpoint URL</font></tt><br>
<tt><font face="Courier New">
that's somehow available to scripts, plugins,</font></tt><br>
<tt><font face="Courier New">
software agents that encounter OpenID login</font></tt><br>
<tt><font face="Courier New">
pages.</font></tt><br>
<br>
<tt><font face="Courier New">
Suggestion: (for OpenID-enabled login pages):-</font></tt><br>
<br>
<tt><font face="Courier New"> <link rel="openid.httpauth"
href="http://my.rp.com/openid/blah.cgi"></font></tt><br>
<br>
<tt><font face="Courier New">-----------</font></tt><br>
<br>
<br>
<tt><font face="Courier New">Kind Regards,</font></tt><br>
<tt><font face="Courier New">Chris Drake</font></tt><br>
<br>
<br>
<tt><font face="Courier New">Thursday, October 19, 2006, 6:07:08 AM:</font></tt><br>
<br>
<tt><font face="Courier New">>> It is vulnerable to a man in the middle
attack - the RP, instead of</font></tt><br>
<tt><font face="Courier New">>> redirecting to the IdP redirects to itself
or some other site in</font></tt><br>
<tt><font face="Courier New">>> cahoots, then proxies the conversation
between the user and the IdP</font></tt><br>
<tt><font face="Courier New">>> thereby compromising the users (global)
credentials as they pass through.</font></tt><br>
<br>
<tt><font face="Courier New">SK> Right, we've known about this for quite
some time unfortunately there hasn't</font></tt><br>
<tt><font face="Courier New">SK> be a particularly easy solution to it and I
classify this as one of those</font></tt><br>
<tt><font face="Courier New">SK> "The Internet Sucks" problems.
I'm not saying we shouldn't/couldn't do</font></tt><br>
<tt><font face="Courier New">SK> anything about it I just think the right
solution that mixes</font></tt><br>
<tt><font face="Courier New">SK> ease-of-implementation and user need hasn't
been found yet.</font></tt><br>
<br>
<tt><font face="Courier New">>> There really needs to be user-agent
support to avoid that - either</font></tt><br>
<tt><font face="Courier New">>> something CardSpace like, or browser
plugin that only ever presents a</font></tt><br>
<tt><font face="Courier New">>> pre-authenticated user.</font></tt><br>
<br>
<tt><font face="Courier New">SK> I think we're headed in this direction.
However, we have to crawl before we</font></tt><br>
<tt><font face="Courier New">SK> can walk. At least solving a big
chunk of the use cases, getting some</font></tt><br>
<tt><font face="Courier New">SK> momentum behind the platform and solving a
specific problem for users</font></tt><br>
<tt><font face="Courier New">SK> *today* is better than trying to build the
perfect tool. We can talk and</font></tt><br>
<tt><font face="Courier New">SK> talk on these lists but we really don't
know how users are going to use this</font></tt><br>
<tt><font face="Courier New">SK> stuff (or abuse it for that matter) until
its out there and working in the</font></tt><br>
<tt><font face="Courier New">SK> wild.</font></tt><br>
<br>
<tt><font face="Courier New">SK> I can't emphasize more the fact that with
every passing day that we don't</font></tt><br>
<tt><font face="Courier New">SK> have OpenID v2.0 out the door, we're losing
momentum from fixing specific</font></tt><br>
<tt><font face="Courier New">SK> user problems that are solved in the
existing specification.</font></tt><br>
<br>
<tt><font face="Courier New">SK> - Scott</font></tt><br>
<br>
<tt><font face="Courier New">SK>
_______________________________________________</font></tt><br>
<tt><font face="Courier New">SK> general mailing list</font></tt><br>
<tt><font face="Courier New">SK> general@openid.net</font></tt><br>
<tt><font face="Courier New">SK> http://openid.net/mailman/listinfo/general</font></tt><br>
<br>
<br>
<br>
<br>
<tt><font face="Courier New">_______________________________________________</font></tt><br>
<tt><font face="Courier New">dix mailing list</font></tt><br>
<tt><font face="Courier New">dix@ietf.org</font></tt><br>
<tt><font face="Courier New">https://www1.ietf.org/mailman/listinfo/dix</font></tt></span></font><o:p></o:p></p>
</div>
</body>
</html>