IRC Log for #openid on 2010-07-01
Timestamps are in UTC.
- [00:22:37] * Kaliya1 (~Adium@173.180.160.38) Quit (Quit: Leaving.)
- [00:24:42] * karstensrage (~Adium@173-13-190-57-sfba.hfc.comcastbusiness.net) Quit (Quit: Leaving.)
- [00:39:41] * shigeta (~shigeta@sakkgw2.sixapart.jp) has joined #openid
- [01:11:29] * jdk2588 (~chatzilla@117.199.115.127) has joined #openid
- [01:27:58] * jdk2588 (~chatzilla@117.199.115.127) Quit (Read error: No route to host)
- [01:38:40] * flaccid (~flaccid@unaffiliated/flaccid) Quit (Quit: flaccid)
- [01:47:30] * jdk2588 (~chatzilla@117.199.117.22) has joined #openid
- [01:52:31] * jdk2588 (~chatzilla@117.199.117.22) Quit (Ping timeout: 240 seconds)
- [01:54:32] * flaccid (~flaccid@unaffiliated/flaccid) has joined #openid
- [02:16:44] * jdk2588 (~chatzilla@117.199.117.231) has joined #openid
- [02:33:08] * karstensrage (~karstensr@c-71-202-243-186.hsd1.ca.comcast.net) has joined #openid
- [02:35:45] * daleolds (~daleolds@c-174-52-159-100.hsd1.ut.comcast.net) Quit (Quit: Leaving.)
- [03:18:31] * jdk2588 (~chatzilla@117.199.117.231) Quit (Ping timeout: 260 seconds)
- [05:36:10] * jdk2588 (~jdk2588@117.199.120.224) has joined #openid
- [05:40:20] * jdk2588 (~jdk2588@117.199.120.224) Quit (Changing host)
- [05:40:20] * jdk2588 (~jdk2588@unaffiliated/jdk2588) has joined #openid
- [05:59:54] * jdk2588_ (~jdk2588@117.207.87.129) has joined #openid
- [06:00:32] * jdk2588 (~jdk2588@unaffiliated/jdk2588) Quit (Ping timeout: 260 seconds)
- [06:13:31] * jdk2588_ (~jdk2588@117.207.87.129) Quit (Ping timeout: 260 seconds)
- [06:38:11] * plantian (~ian@c-69-181-194-95.hsd1.ca.comcast.net) has joined #openid
- [06:44:49] * jdk2588_ (~jdk2588@117.207.87.129) has joined #openid
- [06:47:50] * jdk2588_ is now known as jdk2588
- [06:48:00] * jdk2588 (~jdk2588@117.207.87.129) Quit (Changing host)
- [06:48:00] * jdk2588 (~jdk2588@unaffiliated/jdk2588) has joined #openid
- [07:01:09] * jdk2588 (~jdk2588@unaffiliated/jdk2588) Quit (Remote host closed the connection)
- [07:01:44] * jdk2588 (~jdk2588@117.207.87.129) has joined #openid
- [07:05:01] * NetersLandreau (~NetersLan@b2.e6.354a.static.theplanet.com) Quit (Ping timeout: 265 seconds)
- [07:12:54] * Kaliya (~Adium@173.180.160.38) has joined #openid
- [07:14:20] * Kaliya (~Adium@173.180.160.38) has left #openid
- [07:20:40] <plantian>
Is it normal for websites with openid logins to use a user's openid url as a unique identifier in their profile url ? Such as www.example.com/users/{openid-url} ?
- [07:29:46] <yangman>
er, yes?
- [07:29:57] <yangman>
it's the one thing that's unique to the user
- [07:30:42] <plantian>
http://wiki.openid.net/Relying-Party-Best-Practices#ClearlyinformtheuseriftheirOpenIDwillbepublished -- weel they kind of dance around it here like its a bad idea
- [07:31:52] <plantian>
yangman: it seems kind of like something you wouldn't want published all over the place
- [07:33:16] <yangman>
oh, you mean as something that's publically visible
- [07:33:28] <yangman>
yeah, poor practice, I suppose
- [07:34:10] <plantian>
Yeah right, so if I want to make nice urls.
- [07:34:33] <plantian>
Otheriwse I have to ask them for a username/url-slug or use some sort of auto generated id or slug.
- [07:35:35] * shigeta (~shigeta@sakkgw2.sixapart.jp) Quit (Quit: Leaving...)
- [08:03:25] * Kaliya (~Adium@173.180.160.38) has joined #openid
- [08:03:52] * jdk2588_ (~jdk2588@117.199.118.79) has joined #openid
- [08:03:55] * jdk2588 (~jdk2588@117.207.87.129) Quit (Ping timeout: 252 seconds)
- [08:04:49] <flaccid>
plantian: unlike other identifiers, an openid identifier URL does not give away anything if designed without personal details
- [08:07:00] <plantian>
flaccid: Right but if its used on two sites publicly then you can assume its the same account right?
- [08:07:13] * Kaliya (~Adium@173.180.160.38) has left #openid
- [08:07:25] <flaccid>
sure
- [08:07:38] <flaccid>
thats kind of what an identity is about
- [08:08:01] <flaccid>
if the user wants to be private the should not be posting public on a public site. nothing new here.
- [08:08:17] <flaccid>
sites control what they expose, not openid
- [08:09:00] <flaccid>
for e.g. email - well if they expose that, you are subject to spam. openid is not like that
- [08:09:20] <plantian>
Right, I don't know, also it just seems weird putting their id out there from a security perspective. I'm just kind of thinking/worrying about it at this point.
- [08:09:48] * jdk2588_ (~jdk2588@117.199.118.79) Quit (Read error: No route to host)
- [08:10:02] <flaccid>
openid only verifies the owner of a URL
- [08:10:16] <flaccid>
URLs have never been a subject of security
- [08:10:23] <flaccid>
how they are served etc. is
- [08:10:51] <flaccid>
if your http server is open to vulns, well that has not much to do with openid itself
- [08:11:14] <flaccid>
on that note, im out to dinner.
- [08:11:31] <plantian>
oh right, so is an openid url different than the login used to validate ownership of the url ?
- [08:11:58] <flaccid>
no, an openid identity is an openid identity which is a URL
- [08:12:21] <flaccid>
openid auth is different
- [08:13:07] <flaccid>
its all based on the fact that you need access to the web server to serve it. if you have that, then it can be verified. if hackers have that, you are screwed more than average. nothing new here
- [08:13:25] <flaccid>
on that note i'm out
- [08:13:27] <plantian>
Yeah right ,okay thanks for the insights.
- [08:13:34] <flaccid>
i doubt you have an insecure web server.
- [08:13:37] <flaccid>
cya
- [08:14:15] * plantian (~ian@c-69-181-194-95.hsd1.ca.comcast.net) Quit (Quit: Leaving.)
- [08:49:05] * jdk2588_ (~jdk2588@117.199.121.52) has joined #openid
- [09:09:31] * NetersLandreau (~NetersLan@b2.e6.354a.static.theplanet.com) has joined #openid
- [09:11:34] * jdk2588_ (~jdk2588@117.199.121.52) Quit (Ping timeout: 252 seconds)
- [10:36:09] * jensn (~Jens@90-229-211-93-no150.tbcn.telia.com) has joined #openid
- [12:16:50] * jdk2588 (~jdk2588@117.199.121.148) has joined #openid
- [12:48:51] * MacTed (~Thud@c-24-61-62-241.hsd1.ma.comcast.net) Quit ()
- [13:09:30] * kengyu (~kengyu@111-184-119-184.cable.dynamic.giga.net.tw) Quit (Ping timeout: 240 seconds)
- [13:29:16] * MacTed (~Thud@63.119.36.36) has joined #openid
- [13:52:57] * Kaliya (~Adium@173.180.160.38) has joined #openid
- [14:04:27] * Kaliya (~Adium@173.180.160.38) Quit (Quit: Leaving.)
- [14:27:00] * jdk2588 (~jdk2588@117.199.121.148) Quit (Read error: Connection reset by peer)
- [14:29:49] * jensn (~Jens@90-229-211-93-no150.tbcn.telia.com) Quit (Quit: jensn)
- [14:29:50] * jdk2588 (~jdk2588@117.199.116.219) has joined #openid
- [15:38:42] * karstensrage (~karstensr@c-71-202-243-186.hsd1.ca.comcast.net) Quit (Quit: Leaving)
- [15:58:55] * antiPoP (~ircap@84.77.7.196) has joined #openid
- [16:13:12] * daleolds (~daleolds@137.65.157.34) has joined #openid
- [16:18:31] * jdk2588 (~jdk2588@117.199.116.219) Quit (Ping timeout: 240 seconds)
- [16:18:51] * jdk2588 (~jdk2588@117.199.113.27) has joined #openid
- [17:14:48] * jensn (~Jens@90-229-211-93-no150.tbcn.telia.com) has joined #openid
- [17:14:57] * antiPoP (~ircap@84.77.7.196) Quit (Quit: IRcap 8.6 )
- [17:18:15] * jdk2588 (~jdk2588@117.199.113.27) Quit (Remote host closed the connection)
- [17:19:00] * jdk2588 (~jdk2588@117.199.113.27) has joined #openid
- [17:34:54] * karstensrage (~Adium@173-13-190-57-sfba.hfc.comcastbusiness.net) has joined #openid
- [17:49:22] * Kaliya (~Adium@173.180.160.38) has joined #openid
- [17:52:35] * Kaliya (~Adium@173.180.160.38) has left #openid
- [18:07:12] * karstensrage1 (~Adium@173-13-190-57-sfba.hfc.comcastbusiness.net) has joined #openid
- [18:07:50] * karstensrage (~Adium@173-13-190-57-sfba.hfc.comcastbusiness.net) Quit (Read error: Connection reset by peer)
- [19:10:18] * jdk2588 (~jdk2588@117.199.113.27) Quit (Remote host closed the connection)
- [19:10:50] * jdk2588 (~jdk2588@117.199.113.27) has joined #openid
- [20:02:35] * singpoly1a (~singpolym@dsl-173-248-203-98.acanac.net) has joined #openid
- [20:03:14] * singpoly1a (~singpolym@dsl-173-248-203-98.acanac.net) Quit (Client Quit)
- [20:05:39] * singpoly1a (~singpolym@dsl-173-248-203-98.acanac.net) has joined #openid
- [20:39:46] * jdk2588 (~jdk2588@117.199.113.27) Quit (Ping timeout: 260 seconds)
- [20:43:01] * jdk2588 (~jdk2588@117.199.113.246) has joined #openid
- [21:27:36] * MacTed (~Thud@63.119.36.36) Quit ()
- [21:45:33] * Kaliya1 (~Adium@173.180.160.38) has joined #openid
- [21:45:57] * Kaliya1 (~Adium@173.180.160.38) has left #openid
- [22:07:06] * jdk2588_ (~jdk2588@117.199.114.10) has joined #openid
- [22:09:09] * jdk2588 (~jdk2588@117.199.113.246) Quit (Ping timeout: 276 seconds)
- [22:35:47] * jdk2588_ (~jdk2588@117.199.114.10) Quit (Read error: Connection reset by peer)
- [22:37:14] * jdk2588_ (~jdk2588@117.199.112.211) has joined #openid
- [22:47:29] * MacTed (~Thud@c-24-61-62-241.hsd1.ma.comcast.net) has joined #openid
- [22:55:57] * jdk2588_ (~jdk2588@117.199.112.211) Quit (Ping timeout: 260 seconds)
- [23:04:07] * Kaliya (~Adium@96.49.117.42) has joined #openid
- [23:05:55] * Kaliya (~Adium@96.49.117.42) has left #openid
- [23:29:48] * Kaliya (~Adium@96.49.117.42) has joined #openid
- [23:48:01] * Kaliya (~Adium@96.49.117.42) Quit (Quit: Leaving.)
- [23:52:18] * Kaliya (~Adium@96.49.117.42) has joined #openid
- [23:56:44] * daleolds (~daleolds@137.65.157.34) Quit (Quit: Leaving.)
- [23:58:44] * singpoly1a (~singpolym@dsl-173-248-203-98.acanac.net) Quit (*.net *.split)
- [23:58:46] * shachaf (~shachaf@208.69.183.87) Quit (*.net *.split)
These logs were automatically created by OpenIDlogbot on
chat.freenode.net
using a modified version of the Java IRC LogBot.