Subject: CAcert Code Development list.
List archive
- From: Ian G <iang AT iang.org>
- To: cacert-devel AT lists.cacert.org
- Subject: Re: Security of OAuth and OpenID
- Date: Mon, 13 Jul 2009 12:15:39 +0200
On 13/7/09 00:34, Michael Tänzer wrote:
I think the new design is good (as far as I'm able to tell) but using
techniques like OAuth and OpenID might have some security implications
which have to be considered. If we keep the number of third party
applications low and make them look like they are not separate systems
but one (same design and same domain) these risks would be minimized.
Right, we are on the same page. OpenID won't be used, period. It might or might not be offered, but only to infrastructure systems (like the wiki, etc). That decision is out of scope for Birdshack.
OAuth might be used. When I read the basic architecture, it claimed it would do crypto authentication using fixed public key pairs. If this is what it does, we'll be fine. If not we'll likely replace it with something that does.
In my mind, for now, this probably means that the only apps that can access the API will need to be registered. It won't be totally open.
iang
- Security of OAuth and OpenID, Michael Tänzer, 07/10/2009
- Re: Security of OAuth and OpenID, Alejandro Mery Pellegrini, 07/10/2009
- Re: Security of OAuth and OpenID, Michael Tänzer, 07/11/2009
- Re: Security of OAuth and OpenID, Mario Lipinski, 07/11/2009
- Re: Security of OAuth and OpenID, Michael Tänzer, 07/12/2009
- Re: Security of OAuth and OpenID, Sam Johnston, 07/12/2009
- Re: Security of OAuth and OpenID, Michael Tänzer, 07/12/2009
- Re: Security of OAuth and OpenID, Ian G, 07/13/2009
- Re: Security of OAuth and OpenID, Michael Tänzer, 07/12/2009
- Re: Security of OAuth and OpenID, Mario Lipinski, 07/11/2009
- Re: Security of OAuth and OpenID, Michael Tänzer, 07/11/2009
- Re: Security of OAuth and OpenID, Ian G, 07/11/2009
- Re: Security of OAuth and OpenID, Michael Tänzer, 07/11/2009
- Re: Security of OAuth and OpenID, Ian G, 07/11/2009
- Re: Security of OAuth and OpenID, Michael Tänzer, 07/11/2009
- Re: Security of OAuth and OpenID, Markus Warg, 07/13/2009
- Re: Security of OAuth and OpenID, Alejandro Mery Pellegrini, 07/10/2009
Archive powered by MHonArc 2.6.16.