Marcel Weiss's Library tagged → View Popular, Search in Google
Mindmap zu Identität, Facebook Connect, OpenID und co.; gestartet von Marshall Kirkpatrick von ReadWriteWeb
-
Kim Cameron explains the phishing attack in greater detail and notes: “The problem here is that redirection to the home site is under the control of the evil party, and the user gives that party enough information to sink her. Further, the whole process can be fully automated.” Elsewhere, Kim points out “think of what we unleash with OpenID… It’s way easier for the evil site to scoop the skin of a user’s OpenID service because - are you ready? - the user helps out by entering her honeypot’s URL! By playing back her OpenID skin the evil site can trick the user into revealing her creds. But these are magic creds, the keys to her whole kingdom!”
-
Marco Slot in his “Beginner’s guide to OpenID phishing” demonstrates the phishing problem by providing code samples. Quoting: “There’s a new phish in town and it is big and easy to catch. A single OpenID may be used for hundres of websites. This alone makes OpenID more vulnerable as losing one password means you’ve lost them all. Moreover, each of those OpenID enabled websites is able to trick the user into giving away her password. […] Would your grandma notice http://f5888d0b1.07e1c41c97a.be/a15 is not her real openid provider?”
- 11 more annotation(s)...
-
We’re pleased to announce that we’ve built a ClaimID application for Facebook. This simple application will display your verified ClaimID account (verified with OpenID) on your Facebook profile, allowing people who visit your profile to have a trusted link to your ClaimID page.
-
So what is Pibb? Well, like I have mentioned above it’s a communication tool which allows users to either connect with a single person or with an entire group, a channel. At first glance it looks a lot like IRC with some graphics to make it more appealing; channels contribute to that assumption. Though people can start different threads in a channel which help keeping track of discussions.
-
Pibb is a promising application which could serve as an instant messenger, an IRC alternative, and a message board. Since channels can be private and all messages are sent over SSL it could be an alternative to the mentioned communication services and make it predestined even for communication within company teams.
-
Es wäre in der Tat praktisch, wenn irgend eine pfiffige Entwicklung die andauernden Registrier- und Anmeldeorgien bei all den neuen und bunten Web-Diensten überflüssig machen könnte. Derzeit sind einige Systeme in Entwicklung oder bereits im Einsatz, die ein Ende der Username-Passwort-Hantiererei versprechen.
Der Politologe Ralf Bendraht mahnt zur Vorsicht: In diesen Identitäts-Silos sammeln sich Datenmengen an, die genaueste Rückschlüsse über unser aller Web-Aktivitäten erlauben.
-
Nein, OpenID bietet *keinen* Spamschutz. Erstens kann sich jeder beliebige viele OpenIDs besorgen und zweitens, was viel wichtiger ist, jeder kann OpenID-Provider sein. D.h. wenn die Spammer wollen, könnten sie alle ihre Domains in Provider umwandeln und sich dort OpenIDs generieren.
Im Prinzip ist eine OpenID in Hinsicht auf Authentizität *erstmal* nicht mehr wert als eine Email-Adresse, die sich ebenfalls leicht fälschen lässt. Bei einer OpenID kannst du aber, nachdem du ihr vertraust, sagen, dass derjenige, der sich mit ihr einloggt auch wirklich ihr Besitzer ist. Entspricht also ungefähr einer vom User bestätigten Emailadresse.
-
wpopenid is a Wordpress plugin by Alan Castonguay that enables commenters to authenticate using their OpenID. This page is for my fork of wpopenid that adds a few features as well as fixes a few bugs. I would like to contribute these fixes back to the main project, but simply haven’t been able to get in touch with Alan yet. Visit the main wpopenid homepage to get an idea of what the plugin does, then view my detailed list of changes below.
-
- Make a new directory on my server and install the files. I chose http://www.douglaskarr.com/OpenID/
- I added redirectors to my WordPress header file that redirects any OpenID requests:
<link rel="openid.server" href="http://www.douglaskarr.com/http://www.douglaskarr/OpenID/MyID.php">
<link rel=”openid.delegate” href=”http://www.douglaskarr/OpenID/MyID.php”> - I had to configure my password by encrypting my login, realm (this is phpMyID), and password. To do this, I popped a PHP file up on the server with the following code:
I’ve configured phpMyID tonight in a few minutes and it tested and worked great. I chose the easiest option for Single User configuration so I only had to do a few things:
-
<?php echo md5(login:realm:password);>- I copied that encrypted string into the configuration for the ID file and I was up and running!
- To test, I simply had to login using a simple URL
- I then logged out
- 1 more annotation(s)...
-
Two weeks ago Microsoft, Verisign, JanRain (a Portland-based startup), and SXIP ( Vancouver-based startup) announced that they would work with SixApart (early supporters, acceptors, and providers of OpenID) to support OpenID and integrate it with Vista's Identity manager CardSpace (Radar post). There was no mention of MSN or Live becoming acceptors or providers of OpenID. Last week AOL announced that they would become providers of OpenID, giving anyone who has an AIM account an OpenID (Radar post). Earlier this week Digg announced that they would become both a provider and an acceptor (Radar post).
-
OpenID Pros
- 7 more annotation(s)...
-
Late last week AOL announced its support of the open identity system OpenID, for all 63 million of their AOL/AIM Ids (for those looking for a quick introduction to OpenID, click here). The details of the announcement, via the dev.aol.com blog, are as follows:
-
- Every AOL/AIM user now has at least one OpenID URI, http://openid.aol.com/screenname.
- This experimental OpenID 1.1 Provider service is available now and AOL is conducting compatibility tests.
- AOL's blogging platform has enabled basic OpenID 1.1 in beta, so every beta blog URI is also a basic OpenID identifier. (No Yadis yet.)
- AOL doesn't yet accept OpenID identities within their products as a relying party, but they're actively working on it. That roll-out is likely to be gradual.
- AOL is tracking the OpenID 2.0 standardization effort and plan to support it after it becomes final.
- 2 more annotation(s)...
-
One of the new features we dropped into ClaimID was an easy snippet of code that allows you to make your blog an OpenID (you could always do this before, we just auto-generate the code for you).
Selected Tags
Related Tags
Top Contributors
Groups interested in openid
-
OPENID_Jommla_CB
some open ID system ,could b...
Items: 9 | Visits: 32
Created by: doingtoing
-
Web SSO
Items: 9 | Visits: 22
Created by: Paulo Nogueira
-
identity
Items: 12 | Visits: 18
Created by: Andrew Sun
Diigo is about better ways to research, share and collaborate on information. Learn more »
Join Diigo
