Re: [dix] Re: Gathering requirements for in-browser OpenID support

Pete Rowley <prowley@redhat.com> Wed, 18 October 2006 17:50 UTC

Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1GaFYY-0006u3-JH; Wed, 18 Oct 2006 13:50:18 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1GaFYX-0006ty-30 for dix@ietf.org; Wed, 18 Oct 2006 13:50:17 -0400
Received: from mx1.redhat.com ([66.187.233.31]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1GaFYT-0003TC-Pq for dix@ietf.org; Wed, 18 Oct 2006 13:50:17 -0400
Received: from int-mx1.corp.redhat.com (int-mx1.corp.redhat.com [172.16.52.254]) by mx1.redhat.com (8.12.11.20060308/8.12.11) with ESMTP id k9IHo7fL015092; Wed, 18 Oct 2006 13:50:07 -0400
Received: from potter.sfbay.redhat.com (potter.sfbay.redhat.com [172.16.27.15]) by int-mx1.corp.redhat.com (8.13.1/8.13.1) with ESMTP id k9IHnuwO020732; Wed, 18 Oct 2006 13:49:56 -0400
Received: from [172.16.25.166] (dhcp-172-16-25-166.sfbay.redhat.com [172.16.25.166]) by potter.sfbay.redhat.com (8.12.11.20060308/8.12.11) with ESMTP id k9IHntrD009956; Wed, 18 Oct 2006 13:49:55 -0400
Message-ID: <45366942.50307@redhat.com>
Date: Wed, 18 Oct 2006 10:49:54 -0700
From: Pete Rowley <prowley@redhat.com>
User-Agent: Thunderbird 1.5.0.7 (X11/20060911)
MIME-Version: 1.0
To: Digital Identity Exchange <dix@ietf.org>
Subject: Re: [dix] Re: Gathering requirements for in-browser OpenID support
References: <4533DD00.6060501@mozilla.com> <C1592C34.AC79%scott@janrain.com> <20061018171523.GD25194@narn.hozed.org>
In-Reply-To: <20061018171523.GD25194@narn.hozed.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 36c793b20164cfe75332aa66ddb21196
Cc: Scott Kveton <scott@janrain.com>, general@openid.net
X-BeenThere: dix@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
Reply-To: Digital Identity Exchange <dix@ietf.org>
List-Id: Digital Identity Exchange <dix.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/dix>, <mailto:dix-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/dix>
List-Post: <mailto:dix@ietf.org>
List-Help: <mailto:dix-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/dix>, <mailto:dix-request@ietf.org?subject=subscribe>
Content-Type: multipart/mixed; boundary="===============1993786508=="
Errors-To: dix-bounces@ietf.org

Troy Benjegerdes wrote:
> On Mon, Oct 16, 2006 at 12:31:48PM -0700, Scott Kveton wrote:
>   
>> Hey Rob,
>>  
>>     
>>> I'm trying to gather requirements for OpenID support. I think I have a
>>> reasonable understanding of the draft, but part of the appeal of OpenID
>>> is that it doesn't necessarily require browser vendors to do anything :)
>>>
>>> I've seen the proposed 2617-style HTTP authentication scheme on the
>>> wiki. What else could browser vendors do to make OpenID a smoother
>>> experience for users?
>>>       
>> As I posted on the Mozilla wiki:
>>
>> http://wiki.mozilla.org/Firefox/Feature_Brainstorming#Identity
>>
>> I'd love to see some anti-phishing mojo baked into the browser.  If the user
>> could set their trusted IdP (or multiple as the case may be) in the browser
>> and then have the browser do something obvious when the users is presented
>> with an "untrusted" page asking for their password that would be great IMHO.
>>     
>
> I think there needs to be more overlap between the people on the OpenID
> list and people on the IETF DIX list... Both of these groups of people
> seem to have similiar ideas, and different approaches. A real solution
> to this distributed identity problem is going to involve both groups.
>
>   
If there is going to be a "mojo" in the browser then I think it ought to 
just take care of the authentication itself i.e. the site never gets an 
opportunity to be MITM because users appear to them to always be 
previously authenticated. I also think it _is_ a requirement that the 
browser vendors support this - right now you have to trust that the RP 
is a white hat.

-- 
Pete

_______________________________________________
dix mailing list
dix@ietf.org
https://www1.ietf.org/mailman/listinfo/dix