[security] passing password on identification request?

SitG Admin sysadmin at shadowsinthegarden.com
Mon Oct 19 22:30:30 UTC 2009


>I see, what's unfortunate is that openId was perfect for the needs 
>of our web application. Unfortunately it won't meet the requirements 
>of our web service,

Can you elaborate on what you're referring to here? (I think you may 
be speaking of the hosting company for your server, and/or possibly 
the software they are using (which lacks a plugin for OpenID?), but 
more information might help :)

>so we may actually choose to write our own system now (seeing as how 
>even oAuth needs manual logging in at some point too).

What would you see as non-manual login? No prompts to the user for 
input? Hardware dongles?

-Shade


More information about the security mailing list