[oauth] Re: [OpenID] Can we make a seamless OpenID mobile experience?

2009-04-12 Thread Nat Sakimura
ds? >> >> So I'm just putting it out there. >> >> >> > > ___ > general mailing list > gene...@openid.net > http://openid.net/mailman/listinfo/general > -- Nat Sakimura (=nat) http://www.sakimura.org/en/

[oauth] Re: a simple view of the OAuth security issue

2009-04-25 Thread Nat Sakimura
itably does). >> >> It's probably worth thinking about what "verification" means and how >> that might be achieved.  Otherwise, I think the community needs to >> decide if "minimizing possibility" is enough. >> >> --peter keane &

[oauth] Re: Moving forward

2009-04-28 Thread Nat Sakimura
k   | http://panoptic.com/ >   "He realized the fastest way to change is to laugh at your own >     folly -- then you can let go and quickly move on." (p. 70) > > > > -- Nat Sakimura (=nat) http://www.sakimura.org/en/ --~--~-~--~~~---~--~

[oauth] Re: Moving forward

2009-04-28 Thread Nat Sakimura
> > --peter > >> And yes, making request tokens one-time only is a MUST, IMHO. >> >> -- >> Dossy Shiobara              | do...@panoptic.com | http://dossy.org/ >> Panoptic Computer Network   | http://panoptic.com/ >>   "He realized the fastest way to

[oauth] Re: Moving forward

2009-04-28 Thread Nat Sakimura
correlation problem (privacy), but since S cannot learn too much activity of V at C, it probably would not be that bad. And, yes. This is not a technical approach, but legal and social approach, but is valid IMHO. =nat On Wed, Apr 29, 2009 at 11:01 AM, George Fletcher wrote: > > Nat Sakimura

[oauth] Re: Moving forward

2009-04-29 Thread Nat Sakimura
problem is that the > consumer was compromised through another means in the first place. > > In the case of applications that are distributed to end users, this > becomes a DRM problem and not one we can solve without user education > and due signaling and out-of-band trust metrics on the s

[oauth] Re: Moving forward

2009-04-29 Thread Nat Sakimura
On Thu, Apr 30, 2009 at 7:05 AM, Blaine Cook wrote: > > On Wed, Apr 29, 2009 at 3:46 PM, Nat Sakimura wrote: >> >> The other approach is to make it clear that OAuth is Grant (S:V:Data to C:*) >> so that the users will be fully aware of the consequence. That will ke

[oauth] Signing method for XRD

2009-06-09 Thread Nat Sakimura
uld the community feel that this is simple enough? I would appreciate your insight/opinion/input into this matter. Best, -- Nat Sakimura (=nat) http://www.sakimura.org/en/ --~--~-~--~~~---~--~~ You received this message because you are subscribed to the Google Gro

Re: [oauth] Is OAuth death?

2012-03-20 Thread Nat Sakimura
To post to this group, send email to oauth@googlegroups.com. > To unsubscribe from this group, send email to > oauth+unsubscr...@googlegroups.com. > For more options, visit this group at > http://groups.google.com/group/oauth?hl=en. > > -- Nat Sakimura (=nat) Chairman, OpenID Founda

Re: [oauth] Is OAuth death?

2012-08-01 Thread Nat Sakimura
t now. > >>>> > >>>> steve. > >>>> > >>>> > >>>> On Jul 29, 2012, at 6:24 AM, André Fiedler wrote: > >>>> > >>>>> OAuth 2.0 and the Road to Hell: > >>>>> http://hueniverse.com/2012/07/oauth-

Re: [oauth] Is OAuth death?

2012-08-02 Thread Nat Sakimura
> Yes, indeed - just saw that on twitter, after sending the below. That's > good news - do you know what the expectation is for finalization? > > thanks and all the best, > steve. > > On Aug 1, 2012, at 11:42 PM, Nat Sakimura wrote: > > Hi Steve, > > Actually, the O

Re: [oauth] External OAuth Provider

2013-03-10 Thread Nat Sakimura
in. Now on click of button on this >> site, I want to redirect to another site using the same credentials i.e. >> Single Sign On feature. Is it possible using Auth Provider? >> >> Please guide me.. >> >> -- >> You received this message because you are subscri

Re: [oauth] Registration for Devices

2013-04-29 Thread Nat Sakimura
ally appreciate any help or pointers on this? > > Thanks > > -- > You received this message because you are subscribed to the Google Groups > "OAuth" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to oauth+unsubscr...

Re: [oauth] OAuth Scope with read only resource

2013-06-03 Thread Nat Sakimura
Yes, you can. =nat via iPhone Jun 4, 2013 2:41、Giri Guntipalli のメッセージ: Hi OAuth scope can include method also? i would like to define scope which includes few of the resource for only GET method others for GET and PUT etc.. OAUTH spec only defines format of the scope name, configuration of OAu

Re: [oauth] Re: Oauth 2.0 login restriction

2013-11-02 Thread Nat Sakimura
eciate all >> the help provide. >> > -- > You received this message because you are subscribed to the Google Groups > "OAuth" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to oauth+unsubscr...@googlegroups.com. &g

Re: [oauth] Preventing OAuth client from maliciously modifying user's request

2014-05-21 Thread Nat Sakimura
To unsubscribe from this group and stop receiving emails from it, send an > email to oauth+unsubscr...@googlegroups.com. > For more options, visit https://groups.google.com/d/optout. > -- Nat Sakimura (=nat) Chairman, OpenID Foundation http://nat.sakimura.org/ @_nat_en -- You received t

Re: [oauth] Preventing OAuth client from maliciously modifying user's request

2014-05-21 Thread Nat Sakimura
r to process it. > > - Fajar Ardian > > On Thu, May 22, 2014 at 9:09 AM, Nat Sakimura wrote: > >> No. >> >> This is equally true for an App as well. The App may modify your tweet. >> This is a kind of things which should more effectively dealt with ToS >>

Re: [oauth] Preventing OAuth client from maliciously modifying user's request

2014-05-22 Thread Nat Sakimura
esource > server enforces single use on? > > What I'm suggesting is that perhaps the use case could be satisfied with > existing spec flows and bespoke use of scope fields, with single use access > tokens. > > > - Reply message - > From: "Nat Sakimura&quo

Re: [oauth] OAuth and RESTful

2014-07-08 Thread Nat Sakimura
e Google Groups > "OAuth" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to oauth+unsubscr...@googlegroups.com. > For more options, visit https://groups.google.com/d/optout. > -- Nat Sakimura (=nat) Chairman, Open

Re: [oauth] OAuth 2.0 flow in iOS :: Apple rejecting opening up Safari

2015-05-08 Thread Nat Sakimura
Thanks Dick. OIDF is also trying to write a white paper why in-app browser for this purpose is a bad idea. =nat via iPhone 2015/05/09 4:28、Dick Hardt のメッセージ: > Glad to know I was not missing something. > > I explained all the logic in my first response to the reviewer. Next response > was

Re: [oauth] OAuth 2.0 flow in iOS :: Apple rejecting opening up Safari

2015-06-08 Thread Nat Sakimura
iew Board: >>>>>>> >>>>>>> (highlighting is mine) >>>>>>> >>>>>>> Hello Dick, >>>>>>>> >>>>>>>> We are writing to let you know the results of your appeal for your &g

Re: [oauth] Map Access Token to Domain

2015-06-09 Thread Nat Sakimura
s going on here? > > -- > You received this message because you are subscribed to the Google Groups > "OAuth" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to oauth+unsubscr...@googlegroups.com > . > For more options, vi

Re: [oauth] Map Access Token to Domain

2015-06-10 Thread Nat Sakimura
d to the Google Groups > "OAuth" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to oauth+unsubscr...@googlegroups.com . > For more options, visit https://groups.google.com/d/optout. > -- Nat Sakimura (=nat) Chairman, OpenID Foun