Re: Google OpenID is now live

2008-04-09 Thread Vinay Gupta
and how it can spread in unexpected ways. If only login were so easy. Vinay -- Vinay Gupta - Designer, Hexayurt Project - an excellent public domain refugee shelter system Gizmo Project VOIP: 775-743-1851 (usually works!) http://hexayurt.com/ Cell: Iceland (+354

Google OpenID is now live

2008-04-09 Thread Vinay Gupta
http://openid-provider.appspot.com/ Somebody used their app hosting service and implemented an OpenID provider. That kind of changes things, doesn't it? Vinay -- Vinay Gupta - Designer, Hexayurt Project - an excellent public domain refugee shelter system Gizmo Project VOIP

Re: password-free login without SSL and OP reliance (an anti-phishing solution)

2007-04-06 Thread Vinay Gupta
fied public key infrastructure. I'm going to need to sit down with your proposal in a great deal of detail, reread some kerberos docs, and hopefully I'll have something more concrete for you next week. Vinay -- Vinay Gupta - Designer, Hexayurt Project - an excellent public domain

Re: Re[3]: Server-to-server channel

2007-04-05 Thread Vinay Gupta
On having your private data cached: the current web model allows businesses to simply own your data into a database, correlate it across multiple databases (doubleclick) and so on. I think that to expect them to give up this privilege (and revenue stream from targeted advertising) is unreal

Re: Server-to-server channel (now: Kerberos, Phishing)

2007-04-05 Thread Vinay Gupta
ell in practice... But the key is that those images have to be private, so that they foe can't spider the page and show you a copy. Vinay -- Vinay Gupta - Designer, Hexayurt Project - an excellent public domain refugee shelter system Gizmo Project VOIP: 775-743-1851 (usually works

Re: Server-to-server channel

2007-04-05 Thread Vinay Gupta
te design for handling network authentication and should probably be considered as a template for subsequent systems. It is old and well examined, and still trusted. Perhaps it would make sense to implement Kerberos over OpenID to solve some or all of these security problems? http://web.mit.edu/Kerb

Re: Server-to-server channel

2007-04-04 Thread Vinay Gupta
don't have a neatly packaged solution for this, but we're dealing with situations which can have very significant legal repercussions: digital signatures are legal for some kinds of transactions in some jurisdictions, and however this is handled is has to have some approach to the questio

Re: Server-to-server channel

2007-04-04 Thread Vinay Gupta
per person... you see where this goes, right? Secondly X509 certificates are very, very broken in terms of delegation semantics and certification semantics (at least in many people's eyes, mine included.) So.. SPKI? (yes, I've been over this territory.... and that's pretty much what

Re: Server-to-server channel

2007-04-03 Thread Vinay Gupta
try provided you with. I should be getting some OSD funding to work on this idea in the next few weeks. Vinay -- Vinay Gupta - Designer, Hexayurt Project - an excellent public domain refugee shelter system Gizmo Project VOIP: 775-743-1851 (usually works!) Cell: Icela