IRC Log for #openid on 2007-11-12
Timestamps are in UTC.
- [00:24:43] * cote (n=cote@71.Red-212-170-20.staticIP.rima-tde.net) Quit (Read error: 110 (Connection timed out))
- [00:38:33] * shigeta (n=shigeta@124.32.114.226) has joined #openid
- [01:11:30] * tom__ (n=tom@cpe-66-68-116-179.austin.res.rr.com) has joined #openid
- [01:11:38] * tom__ is now known as tbbrown
- [01:22:55] * SvenDowideit (n=SvenDowi@twiki/developer/SvenDowideit) Quit (Remote closed the connection)
- [01:32:38] * lopnor (n=lopnor@122.1.9.166) Quit (Read error: 104 (Connection reset by peer))
- [01:50:59] * lopnor (n=lopnor@122.1.9.166) has joined #openid
- [02:05:59] * nainu (n=nainu@210.109.102.112) Quit (Remote closed the connection)
- [02:07:15] <PibbRelay`>
<samsm> I've wondered the same thing about 1.1 vs. 2.0.
- [02:08:33] <PibbRelay`>
<samsm> I can appreciate the caution involved with taking awhile to settle on version 2, but I suspect it makes OpenId seem more complex than it needs to be.
- [02:16:32] <PibbRelay`>
<samsm> I guess I'm saying that if you have to ask, you want 1.1. 1.1 is fine. 1.1 isn't in flux. 1.1 will still be ok once 2.0 is out.
- [02:16:44] <PibbRelay`>
<samsm> No?
- [02:37:50] <tbbrown>
exit
- [02:37:54] * tbbrown (n=tom@cpe-66-68-116-179.austin.res.rr.com) Quit ("leaving")
- [02:51:00] * SteveA (n=steve@canonical/launchpad/SteveA) Quit (kubrick.freenode.net irc.freenode.net)
- [02:51:02] * SteveA (n=steve@canonical/launchpad/SteveA) has joined #openid
- [02:52:31] * peace-keeper (n=peace-ke@chello084114169104.2.15.vie.surfer.at) has joined #openid
- [04:29:38] * lopnor (n=lopnor@122.1.9.166) Quit (Read error: 104 (Connection reset by peer))
- [04:46:56] * lopnor (n=lopnor@122.1.9.166) has joined #openid
- [04:47:53] * dynex (n=dynex@c-69-249-94-118.hsd1.nj.comcast.net) has joined #openid
- [05:08:46] * SvenDowideit (n=SvenDowi@twiki/developer/SvenDowideit) has joined #openid
- [05:50:50] * dynex (n=dynex@c-69-249-94-118.hsd1.nj.comcast.net) Quit ("pthread_cancel(dynex);")
- [05:51:46] * stu1 (n=stub@ppp-58.8.211.15.revip2.asianet.co.th) has joined #openid
- [05:51:46] * stub (n=stub@canonical/launchpad/stub) Quit (Nick collision from services.)
- [05:52:02] * stu1 is now known as stub
- [06:21:17] * peace-keeper (n=peace-ke@chello084114169104.2.15.vie.surfer.at) Quit (Read error: 110 (Connection timed out))
- [07:06:57] * peace-keeper (n=peace-ke@chello084114169104.2.15.vie.surfer.at) has joined #openid
- [08:24:53] * peace-keeper (n=peace-ke@chello084114169104.2.15.vie.surfer.at) Quit (Read error: 110 (Connection timed out))
- [09:41:16] * pvandewyngaerde (n=pvandewy@88.174-136-217.adsl-dyn.isp.belgacom.be) has joined #openid
- [10:18:34] * shigeta (n=shigeta@124.32.114.226) Quit ("Leaving...")
- [10:56:43] * andreas (n=andreas@lade.uninett.no) has joined #openid
- [10:56:49] <andreas>
hi
- [10:56:53] <andreas>
anyone awake?
- [11:09:36] <tjohns>
Ya, for a little while at least
- [11:16:28] <andreas>
i am holding a presentation on openid tomorrow, and trying to get an overview of imporant things to say about it
- [11:16:40] <andreas>
at a identity conference in europe
- [11:19:22] <tjohns>
Have you looked through the slides from past presentations?
- [11:19:46] <andreas>
actually no, is they avail on openid.net ?
- [11:19:53] <andreas>
i don't know much about openid
- [11:20:03] <tjohns>
I don't think so, they're scattered around the net.
- [11:20:06] <tjohns>
One sec...
- [11:20:26] <andreas>
but just read to the specs right now, and one short question... spec says openid plays nice with Ajax (never have to leave the site etc...)
- [11:20:30] <andreas>
how is that possible
- [11:20:58] <andreas>
you cannot redirect an xhttprequest as far as i know
- [11:21:54] <andreas>
And: Is seatbelt worth testing ?
- [11:26:55] <tjohns>
I've never used the AJAX functionality myself. It's definitely a little tricky. I believe you need to display a link that the user has to click, possibly opening itself up in a new window.
- [11:27:04] <tjohns>
There's a discussion about it here: http://openid.net/pipermail/security/2006-November/000161.html
- [11:28:09] <tjohns>
Because of the redirect requirement, I think most of the time it's better to do non-AJAX authentication if at all possible.
- [11:29:45] <andreas>
btw: my name is andreas solberg. I'm from the federation world (with shibboleth and saml 2.0 and similar) and new here.. trying to look at possibilities to bridge our world to yours
- [11:29:46] <tjohns>
As for Seatbelt, it's definitely a neat idea to combat phishing. I've never used it myself (I usually use Safari or Camino, neither work with FF plugins), but Verisign's description of it is pretty straightforward.
- [11:29:56] <tjohns>
Ah, cool.
- [11:30:10] <andreas>
who are you btw?
- [11:30:23] <andreas>
seem to be alot of idlers here on the channel :)
- [11:30:37] <tjohns>
Ya, I'm just a lurker for the most part. ;)
- [11:31:01] <tjohns>
The name's Trevor Johns. I'm a student at USC.
- [11:31:09] <andreas>
ok, nice to meet you
- [11:31:27] <andreas>
are you much into the security considerations of openid?
- [11:32:27] <tjohns>
Ya
- [11:33:13] <andreas>
i know openid has got alot of critisism for security. Do you know the biggest "issues" ?
- [11:33:49] <andreas>
i know phishing is a problem, but that is not specific to openid i think. same for all auth mechs on the net.
- [11:34:27] <tjohns>
Ya, phishing is pretty much the same problem everybody's facing right now. How do you prove that who you're giving your password to is who you think they are.
- [11:35:08] <andreas>
and possible DNS attacking the consumer
- [11:35:13] <andreas>
would be a risk
- [11:35:34] <andreas>
if you have a non-SSL enabled openid
- [11:36:01] <tjohns>
Right, and I think that's mentioned directly in the OpenID 2.0 draft
- [11:36:21] <andreas>
ah yes. actually I have not yet looked into openid 2.0 yet.
- [11:36:32] <tjohns>
Another problem is that OpenID doesn't actually provide any proof as to who somebody is
- [11:36:33] <andreas>
do you know the most significant features or changes with it?
- [11:36:47] <tjohns>
All it says is that "this person owns the URI http://foo.com"
- [11:36:58] <andreas>
Yes, that is one valid point, although openid never really tries to achive that
- [11:37:11] <andreas>
i know sun implemented a twist of that
- [11:37:23] <andreas>
bounding specific trust to certain providers
- [11:37:38] <tjohns>
That's also where things like federations become useful.
- [11:38:24] <tjohns>
There's a list of the changes in OpenID 2.0 here: http://wiki.openid.net/OpenIDChanges
- [11:39:00] <andreas>
thanks
- [11:39:15] <tjohns>
Two of the bigger changes, I think, are allowing XRIs and official Yadis support
- [11:40:22] <andreas>
Do you know if the consumer should verify that the returned identity is the same as the one sent in the checkid_setup request?
- [11:40:48] <andreas>
I know some setup a service where you could enter http://openid.example.com in the openid field at the consumer
- [11:41:08] <andreas>
and the provider sent back the right ID depending on the username you used.
- [11:41:17] <andreas>
it worked, but I am not sure if it should have worked
- [11:42:08] <tjohns>
Hm, that's interesting, I'm not sure about that.
- [11:47:14] <tjohns>
Here's a couple of presentations I'd recommend going through:
- [11:47:22] <tjohns>
http://video.google.com/videoplay?docid=2288395847791059857
- [11:47:22] <tjohns>
http://www.slideshare.net/keepthebyte/openid-authentication
- [11:47:38] <andreas>
thanks
- [11:48:02] <tjohns>
The slides for the Google one are posted here, if you want to skip the video: http://www.slideshare.net/simon/the-implications-of-openid
- [12:07:34] * bortzmeyer (n=stephane@189.76.97.252) has joined #openid
- [12:45:00] * Flenser (n=Miranda@hiddenisland.plus.com) has joined #openid
- [13:20:00] * andreas (n=andreas@lade.uninett.no) Quit ("Quitting!")
- [13:25:22] * _keturn (n=acapnoti@pdpc/supporter/sustaining/keturn) Quit (Read error: 110 (Connection timed out))
- [13:26:50] * rorek (n=rorek@c-71-236-228-127.hsd1.or.comcast.net) Quit (Read error: 110 (Connection timed out))
- [13:27:40] * jrbot (n=supybot@c-71-236-228-127.hsd1.or.comcast.net) Quit (Read error: 110 (Connection timed out))
- [13:28:32] * chowells79 (n=chowells@c-71-236-228-127.hsd1.or.comcast.net) Quit (Read error: 110 (Connection timed out))
- [13:34:23] * cote (n=cote@213.99.42.134) has joined #openid
- [13:47:22] * digitalspaghetti (n=digitals@drupal.org/user/88490/view) has joined #openid
- [13:49:09] * shigeta (n=shigeta@79.125.111.219.dy.bbexcite.jp) has joined #openid
- [13:55:54] * tjohns (n=tjohns@cpe-76-170-58-80.socal.res.rr.com) Quit ()
- [14:01:48] * cote (n=cote@213.99.42.134) Quit ()
- [14:08:47] * cote (n=cote@213.99.42.134) has joined #openid
- [14:28:08] * cote (n=cote@213.99.42.134) Quit ()
- [14:30:56] * bortzmeyer (n=stephane@189.76.97.252) has left #openid
- [14:35:05] * samyboy (n=samyboy@85-218-12-245.dclient.lsne.ch) has joined #openid
- [14:41:52] * marclaporte (n=Marc_Lap@tikiwiki/marclaporte) Quit (Read error: 110 (Connection timed out))
- [14:45:11] * cote (n=cote@213.99.42.134) has joined #openid
- [14:52:02] <samyboy>
#j /linuxfr
- [14:52:30] <samyboy>
pardon :/
- [14:52:44] <samyboy>
sry
- [14:58:25] * shigeta (n=shigeta@79.125.111.219.dy.bbexcite.jp) Quit ()
- [15:03:33] <samyboy>
I'm getting an error 500 on the openidenabled.com website
- [15:03:47] <samyboy>
http://openidenabled.com/resources/openid-test/checkup/start?openid_url=http%3A%2F%2Fopenid.wng.ch%2Fuser%2Fsam
- [15:05:18] * m-q (n=matthias@75-57.wlan.rz.uni-potsdam.de) has joined #openid
- [15:06:52] <m-q>
hi everybody. i have a question regarding the php openid library 2.0.0-rc2. according from the version name, i guess we can start deploy an openid-provider based on this version without expecting dramatic API changes towards the 2.0.0 release?
- [15:07:35] <m-q>
thx
- [15:15:15] * peace-keeper (n=peace-ke@chello084114169104.2.15.vie.surfer.at) has joined #openid
- [15:18:55] * marclaporte (n=Marc_Lap@tikiwiki/marclaporte) has joined #openid
- [15:18:55] <jibot>
marclaporte is Marc Laporte from Tiki CMS/Groupware
- [15:54:21] * mq__ (n=matthias@75-35.wlan.rz.uni-potsdam.de) has joined #openid
- [15:56:32] * m-q (n=matthias@75-57.wlan.rz.uni-potsdam.de) Quit (Read error: 110 (Connection timed out))
- [15:57:15] * mq__ (n=matthias@75-35.wlan.rz.uni-potsdam.de) Quit (Read error: 104 (Connection reset by peer))
- [16:07:41] * johill_ is now known as johill
- [16:17:32] * idnar (i=mithrand@unaffiliated/idnar) Quit (Nick collision from services.)
- [16:17:35] * idnar_ (i=mithrand@unaffiliated/idnar) has joined #openid
- [16:18:15] * idnar_ is now known as idnar
- [16:18:22] * cote (n=cote@213.99.42.134) Quit ()
- [16:29:32] * cote (n=cote@213.99.42.134) has joined #openid
- [16:36:28] * jcassee (n=jcassee@wlan-145-94-216-84.wlan.tudelft.nl) has joined #openid
- [16:36:39] <jcassee>
hi all
- [16:36:42] <jcassee>
any active people here?
- [16:38:53] * jcassee (n=jcassee@wlan-145-94-216-84.wlan.tudelft.nl) has left #openid
- [16:40:23] * jcassee (n=jcassee@wlan-145-94-216-84.wlan.tudelft.nl) has joined #openid
- [16:40:40] * jcassee (n=jcassee@wlan-145-94-216-84.wlan.tudelft.nl) has left #openid
- [16:55:06] * digitalspaghetti (n=digitals@drupal.org/user/88490/view) Quit ()
- [17:05:36] <PibbRelay`>
<VxJasonxV> a few
- [17:05:39] <PibbRelay`>
<VxJasonxV> also depends on your definition of active :)
- [17:06:43] * samyboy (n=samyboy@85-218-12-245.dclient.lsne.ch) Quit ()
- [17:09:56] * rorek (n=rorek@c-71-236-228-127.hsd1.or.comcast.net) has joined #openid
- [17:09:57] * chowells79 (n=chowells@c-71-236-228-127.hsd1.or.comcast.net) has joined #openid
- [17:09:57] <jibot>
chowells79 is yet another Janrain idler.
- [17:10:27] * _keturn (n=acapnoti@pdpc/supporter/sustaining/keturn) has joined #openid
- [17:10:31] * cote (n=cote@213.99.42.134) Quit ()
- [17:11:10] * digitalspaghetti (n=digitals@drupal.org/user/88490/view) has joined #openid
- [17:13:19] * jrbot (n=supybot@c-71-236-228-127.hsd1.or.comcast.net) has joined #openid
- [17:21:54] * mq__ (n=matthias@p54BEEB3C.dip.t-dialin.net) has joined #openid
- [17:27:22] * gchaix (n=gchaix@osuosl/staff/gchaix) has joined #openid
- [17:27:50] * gchaix (n=gchaix@osuosl/staff/gchaix) has left #openid
- [17:34:09] * samyboy (n=samyboy@85-218-12-245.dclient.lsne.ch) has joined #openid
- [17:50:37] <PibbRelay`>
<samsm> I try to at least take a walk every day.
- [17:59:06] * samyboy (n=samyboy@85-218-12-245.dclient.lsne.ch) Quit ()
- [18:04:08] * Flenser (n=Miranda@twiki/developer/SamHasler) Quit (Read error: 104 (Connection reset by peer))
- [18:07:03] * digitalspaghetti (n=digitals@drupal.org/user/88490/view) Quit ()
- [18:21:10] * cote (n=cote@71.Red-212-170-20.staticIP.rima-tde.net) has joined #openid
- [18:30:09] * falkor81 (n=brianlan@rrcs-24-106-184-150.se.biz.rr.com) has joined #openid
- [18:42:45] * tom____ (n=tom@cpe-66-68-116-179.austin.res.rr.com) has joined #openid
- [18:43:33] * tom____ is now known as tbbrown
- [18:48:33] * NASA (n=nasa@78-62-27-29.ip.zebra.lt) has joined #openid
- [18:51:32] <NASA>
hi everyone
- [19:09:22] * amir (n=Miranda@gentoo/developer/amir) Quit (Remote closed the connection)
- [19:11:32] * amir (n=Miranda@gentoo/developer/amir) has joined #openid
- [19:31:01] * jrbot (n=supybot@c-71-236-228-127.hsd1.or.comcast.net) Quit (Read error: 113 (No route to host))
- [19:31:05] * rorek (n=rorek@c-71-236-228-127.hsd1.or.comcast.net) Quit (Read error: 113 (No route to host))
- [19:31:57] * _keturn (n=acapnoti@pdpc/supporter/sustaining/keturn) Quit (Read error: 113 (No route to host))
- [19:32:49] * chowells79 (n=chowells@c-71-236-228-127.hsd1.or.comcast.net) Quit (Read error: 113 (No route to host))
- [19:48:06] * pvandewyngaerde (n=pvandewy@88.174-136-217.adsl-dyn.isp.belgacom.be) Quit ("http://www.last.fm/user/pvandewyngaerde/ http://www.jamendo.com http://amarok.kde.org/")
- [19:48:57] * mq__ (n=matthias@p54BEEB3C.dip.t-dialin.net) Quit ("Ex-Chat")
- [19:52:22] * jrbot (n=supybot@c-71-236-228-127.hsd1.or.comcast.net) has joined #openid
- [20:15:20] * pvandewyngaerde (n=pvandewy@49.30-201-80.adsl-dyn.isp.belgacom.be) has joined #openid
- [20:26:19] * Loolyan (i=Al@gateway/tor/x-a9ab31758dcec06f) has joined #openid
- [20:51:39] * michelp (n=michelp@69-30-72-119.dq1sf.easystreet.com) Quit ("Ex-Chat")
- [21:43:14] * tbbrown (n=tom@cpe-66-68-116-179.austin.res.rr.com) Quit ("leaving")
- [21:47:02] * NASA (n=nasa@78-62-27-29.ip.zebra.lt) Quit ("Ate")
- [21:53:24] * cote (n=cote@71.Red-212-170-20.staticIP.rima-tde.net) Quit (Read error: 104 (Connection reset by peer))
- [21:55:41] * cote (n=cote@71.Red-212-170-20.staticIP.rima-tde.net) has joined #openid
- [21:59:26] * tjohns (n=tjohns@cpe-76-170-58-80.socal.res.rr.com) has joined #openid
- [22:01:46] * Roebot (n=AaronF@ip68-101-200-165.sd.sd.cox.net) has joined #openid
- [22:05:56] * falkor81 (n=brianlan@rrcs-24-106-184-150.se.biz.rr.com) Quit ()
- [22:15:36] * Zottel34 (n=Andi@rx11557.cip.uni-regensburg.de) Quit ()
- [22:24:16] * SvenDowideit (n=SvenDowi@twiki/developer/SvenDowideit) Quit (Read error: 110 (Connection timed out))
- [22:30:33] * SvenDowideit (n=SvenDowi@twiki/developer/SvenDowideit) has joined #openid
- [23:14:26] * pvandewyngaerde (n=pvandewy@49.30-201-80.adsl-dyn.isp.belgacom.be) Quit ("http://www.last.fm/user/pvandewyngaerde/ http://www.jamendo.com http://amarok.kde.org/")
- [23:16:03] * Roebot (n=AaronF@ip68-101-200-165.sd.sd.cox.net) Quit ("Leaving")
- [23:24:16] * Roebot (n=AaronF@ip68-101-200-165.sd.sd.cox.net) has joined #openid
- [23:43:16] * marclaporte (n=Marc_Lap@tikiwiki/marclaporte) Quit (Read error: 110 (Connection timed out))
- [23:43:36] * marclaporte (n=Marc_Lap@tikiwiki/marclaporte) has joined #openid
These logs were automatically created by OpenIDlogbot on
chat.freenode.net
using a modified version of the Java IRC LogBot.