[security] [OpenID] Re: generation fragments

SitG Admin sysadmin at shadowsinthegarden.com
Fri Sep 5 04:40:02 UTC 2008


Not CRL's, time delineations.

We don't need to worry about generation fragments (or a lack thereof) 
if the list tells us that a URI changed hands upon a certain date. It 
can change hands as often as it wants, all we need to do is check the 
list for an entry and, if we find one, see what the latest date was. 
Anything before that, not the same user.

More overhead, though. A few more bytes to store a datestamp for each 
user, and (if an entry was found) appending it to their username "URI 
since [date]".

-Shade



More information about the security mailing list