<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: OpenID 2.0&#8217;s Killer Feature</title>
	<atom:link href="http://barelyenough.org/blog/2007/12/openid-20s-killer-feature/feed/" rel="self" type="application/rss+xml" />
	<link>http://barelyenough.org/blog/2007/12/openid-20s-killer-feature/</link>
	<description></description>
	<lastBuildDate>Mon, 08 Mar 2010 17:12:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Does OpenID Have an Identity Crisis? &#171; hueniverse</title>
		<link>http://barelyenough.org/blog/2007/12/openid-20s-killer-feature/comment-page-1/#comment-76387</link>
		<dc:creator>Does OpenID Have an Identity Crisis? &#171; hueniverse</dc:creator>
		<pubDate>Tue, 08 Sep 2009 06:59:50 +0000</pubDate>
		<guid isPermaLink="false">http://pezra.barelyenough.org/blog/2007/12/openid-20s-killer-feature/#comment-76387</guid>
		<description>&lt;p&gt;[...] key to brand-driven login, of course, is Directed Identity. It&#8217;s the feature of OpenID in which the user does not enter his OpenID URI, but instead, [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] key to brand-driven login, of course, is Directed Identity. It&#8217;s the feature of OpenID in which the user does not enter his OpenID URI, but instead, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: http://pezra.barelyenough.org/</title>
		<link>http://barelyenough.org/blog/2007/12/openid-20s-killer-feature/comment-page-1/#comment-40275</link>
		<dc:creator>http://pezra.barelyenough.org/</dc:creator>
		<pubDate>Wed, 26 Dec 2007 17:59:51 +0000</pubDate>
		<guid isPermaLink="false">http://pezra.barelyenough.org/blog/2007/12/openid-20s-killer-feature/#comment-40275</guid>
		<description>&lt;p&gt;Nilez Parker,&lt;/p&gt;

&lt;p&gt;Unfortunately, I have not really spent a lot of time looking at what OAuth is capable of, so I cannot really say.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Nilez Parker,</p>
<p>Unfortunately, I have not really spent a lot of time looking at what OAuth is capable of, so I cannot really say.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nilez Parker</title>
		<link>http://barelyenough.org/blog/2007/12/openid-20s-killer-feature/comment-page-1/#comment-40255</link>
		<dc:creator>Nilez Parker</dc:creator>
		<pubDate>Sat, 22 Dec 2007 02:28:27 +0000</pubDate>
		<guid isPermaLink="false">http://pezra.barelyenough.org/blog/2007/12/openid-20s-killer-feature/#comment-40255</guid>
		<description>&lt;p&gt;above, the reference to &quot;direct identity&quot; really meant &quot;identity discovery&quot;...&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>above, the reference to &#8220;direct identity&#8221; really meant &#8220;identity discovery&#8221;&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nilez Parker</title>
		<link>http://barelyenough.org/blog/2007/12/openid-20s-killer-feature/comment-page-1/#comment-40254</link>
		<dc:creator>Nilez Parker</dc:creator>
		<pubDate>Sat, 22 Dec 2007 02:18:14 +0000</pubDate>
		<guid isPermaLink="false">http://pezra.barelyenough.org/blog/2007/12/openid-20s-killer-feature/#comment-40254</guid>
		<description>&lt;p&gt;This new feature is definitely killer. I&#039;ve spent so much time already trying to figure out if I can accomplish complete transparency between several apps with the current status of OpenId and OAuth.&lt;/p&gt;

&lt;p&gt;It&#039;s nice to be able to do direct identity, but that doesn&#039;t seem to be all that efficient with OAuth. Wouldn&#039;t it be sufficient for an OAuth consumer to pass an openid_url and a kind of permission-to-act-as token, and then the OAuth provider go and authenticate that token with the user&#039;s openid_server? In effect, the OAuth consumer has been granted permission to &quot;act as&quot; the user; and the OAuth provider just verifies that fact. What do you think? It&#039;d be less hassle between apps, and zero user interaction.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>This new feature is definitely killer. I&#8217;ve spent so much time already trying to figure out if I can accomplish complete transparency between several apps with the current status of OpenId and OAuth.</p>
<p>It&#8217;s nice to be able to do direct identity, but that doesn&#8217;t seem to be all that efficient with OAuth. Wouldn&#8217;t it be sufficient for an OAuth consumer to pass an openid_url and a kind of permission-to-act-as token, and then the OAuth provider go and authenticate that token with the user&#8217;s openid_server? In effect, the OAuth consumer has been granted permission to &#8220;act as&#8221; the user; and the OAuth provider just verifies that fact. What do you think? It&#8217;d be less hassle between apps, and zero user interaction.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
