Skip to main content

Jon Phipps's Library tagged authentication   View Popular

23 Sep 08

Usability Research on Federated Login (Google OAuth & Federated Login Research)

    • Federated
      Login has been a "holy grail" in the identity
      community for a long time.  We have known how to do the technical part
      for a long time.  However
      the industry has constantly tried, and failed, to find a model that was
      (1) simple for end users, and (2) had a reasonable trust model between the RP
      (the relying party, which is the site you want to log into) and the IDP
      (the identity provider, who will identify you to the RP).  Google has
      been experimenting with different user interface models for federated
      login using the following design principles:
      • Design for usability
      • Leverage what users already know - In particular, leverage the login models with which end-users have experience
      • Design for widespread adoption -  Don't just focus on a small number of IDPs, or just on technically savvy end-users
      • Allow
        for gradual migration - In particular, make it work for sites that
        already have a large set of user accounts who are authenticated without
        using a federation scheme
      One user interface ("UI") model we have been
      testing has been working surprisingly well.  At this time, we want to share the
      details to gather comments.  We also want to look for websites who could
      help run experiments on this UI design to generate metrics on how well
      it works.
26 Jul 07

Apache 2 :: [PHP] .htpasswd manager

  • This little class allows you to manage and validate against .htpasswd files.

Dev Shed

  • Over the next few
    pages, I'll be showing you how to authenticate users, maintain session
    information and handle login/logout operations, using both built-in Apache
    authentication and custom PHP code.
10 Jan 07

Browser-Based Authentication (BBAuth)

  • You build great web applications. We have millions of users
    who store their data on Yahoo!. Browser-Based Authentication (BBAuth) makes
    it possible for your applications to use that data (with their
    permission).



    BBAuth also offers a Single Sign-On (SSO) facility so that
    existing Yahoo! users can use your services without having to complete
    yet another registration process.

Google Account Authentication

  • Google Accounts authentication for web-based applications allows the application to access a Google service protected by a user's Google account. To maintain a high level of security, the Authentication Proxy interface, AuthSub, enables the application to get an authentication token without ever handling the user's account login information. Using the proxy, the user
    of the web application logs into their account through a Google-supplied login page and consents
    to grant limited access to the web application.
20 Jul 06

Resources, Code and Community for Sxip Network Developers | sxip.org community

  • Sxip (pronounced like "skip") is a simple, secure and open platform for true digital identity. Sites that implement Sxip support are able to easily provide features like single sign-on and automatic form fill. - jonphipps on 2006-07-20

PHP Generic Access Control Lists

  • A PHP class offering Web developers a simple, yet immensely powerful "drop in" permission system to their current Web based applications. - jonphipps on 2006-07-20

Polymer [Polymer Wiki]

  • Fine-grained control over how your users access your data, featuring user permissions and permission groups, reports, forms, ad-hoc queries – all centrally managed. - jonphipps on 2006-07-20

KittenAuth.com | Purr-fect protection against spambots

  • KittenAuth is a cute alternative to text-captchas. - jonphipps on 2006-07-20

Main Page - LID Wiki

  • LID is a quite simple, but powerful technology that empowers individuals to keep control over and manage their on-line digital identities. Unlike most other identity systems, LID is URL-based, fully decentralized and supports multiple underlying protocols - jonphipps on 2006-07-20
1 - 13 of 13
Showing 20 items per page

Highlighter, Sticky notes, Tagging, Groups and Network: integrated suite dramatically boosting research productivity. Learn more »

Join Diigo