[OAUTH-WG] Re: DNS Handles

Aaron Parecki <aaron@parecki.com> Tue, 21 January 2025 20:18 UTC

Return-Path: <aaron@parecki.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BDC90C169402 for <oauth@ietfa.amsl.com>; Tue, 21 Jan 2025 12:18:00 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.105
X-Spam-Level:
X-Spam-Status: No, score=-2.105 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=parecki.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pxSAg9MBTNut for <oauth@ietfa.amsl.com>; Tue, 21 Jan 2025 12:17:56 -0800 (PST)
Received: from mail-vs1-xe2c.google.com (mail-vs1-xe2c.google.com [IPv6:2607:f8b0:4864:20::e2c]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0E78EC14F5E5 for <oauth@ietf.org>; Tue, 21 Jan 2025 12:17:55 -0800 (PST)
Received: by mail-vs1-xe2c.google.com with SMTP id ada2fe7eead31-4afe4f1ce18so1638733137.3 for <oauth@ietf.org>; Tue, 21 Jan 2025 12:17:55 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=parecki.com; s=google; t=1737490674; x=1738095474; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=APsjsS9uEVfg6WQCHjpkKPKlZX7/xZrpB42fo6wO87U=; b=F28j4nAd4uGiUdPgkO1PAJRisf76lKpgqmLdecH9h/eBJ8T4XkwMXKzdA6HoBiqLDH GZXwc9VG/QPRxDM5EH8tzBOJidyQ9Vfj34yMEuzyUDRK1Y5SJgcqAftyrj0ydrRpkgju 0sm//PwtVtBKczRQReQ0mEIWUEdhPPvozEyFvIYkMdPGzrVHiKdqGEUEZjlfY69xav/H 7vPg2+OZS8LS6WxVnW0AtxbUl+UsRKzK4Q7agm81T+OGJpnjOwYc3iE0Z+K95gmlnouX swevHl/GZ0IHzfA/D6kb1iFfPdrOh9ILyEdz9BYoeHquBRMGWel3l4omu5CgkvTyuC/G lkKA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1737490674; x=1738095474; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=APsjsS9uEVfg6WQCHjpkKPKlZX7/xZrpB42fo6wO87U=; b=Cf+K4hQilXHSA/wGAxQ/2OEHO0Gu1c5POVBWXVmEpdSe3JXfurV1dxd99qWJdlSolk Izv5miajRq685jk5TzDnIbIWWCuaZAta4wPR83jMI9OWPBZRf9IDdJ3gHW4y2AzVH4pv f/Z2lT1gYrdWGvnbUOicxccnvB+mYqKSO4xaaSjBaZ9RArKsBWWufc/4woMde/cM19qG lGKP5ovU0RoR6kLMVwxDkIMi/fgntVs7Rrcz/7sla5+NoynHaQ5/jeqgz2JR/eftvUKr jzM3tLBb+ewwaGngbhiMqXzoy+1Z/VktaCZwZw+bmHiSPway9MJIhbe1eWCIThpRrdO7 DYOw==
X-Gm-Message-State: AOJu0Yx50ryX7NrK0lQuxKNzoVxxTBQrcFqhKy4TtDSx0f7dRuRgyb8g JSmhdll6IC4hMDx5G/Hi4fpk2wdAxguaJ8JHiJX59llYudVBmlDDG+/GyNiNNktg4H/xkjfarYw =
X-Gm-Gg: ASbGnct/EI5bGHDg49XD0OUziVcHA8T2sOd5yJ2l8FatRUhbgpvpOF7tf5+YKLwCfXr NpUhTdwCHHENcd2sP6n6oZnvov/0IN8Xa3lt2P7wrJmMlB1sVUxJsUfcXm8f/ERXWAYAzhGrluo PAx5cqRbpX4Lha3yz+j/KIpTo8ZwCsTbADkvnXOZbCfEIUO+tnlqnteXvkpYIBy0/CVJP9VyrU+ qSbHK9f8OqU8LgA2u/hHQskFnnB86fl+vATyIU2ox/boeSmctnWz40k4RvpZtwnvam5z+hl6Eod 6KD69yBE8jDyznDU2p85Uefy1OhbzdPA
X-Google-Smtp-Source: AGHT+IE+s+w7GEmJ3z+pn/LrTgecNhWh9hBBfxyVTeldR6NAHGosfnYKNYMTFzr4VBmaOJf8NQ9cRg==
X-Received: by 2002:a05:6102:374e:b0:4b6:d773:afca with SMTP id ada2fe7eead31-4b6d773b459mr3488976137.16.1737490674469; Tue, 21 Jan 2025 12:17:54 -0800 (PST)
Received: from mail-vk1-f175.google.com (mail-vk1-f175.google.com. [209.85.221.175]) by smtp.gmail.com with ESMTPSA id a1e0cc1a2514c-8642ccac9d9sm2552423241.33.2025.01.21.12.17.53 for <oauth@ietf.org> (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 21 Jan 2025 12:17:53 -0800 (PST)
Received: by mail-vk1-f175.google.com with SMTP id 71dfb90a1353d-518ae5060d4so1696090e0c.0 for <oauth@ietf.org>; Tue, 21 Jan 2025 12:17:53 -0800 (PST)
X-Received: by 2002:a05:6122:8c5:b0:518:8bfe:d5f0 with SMTP id 71dfb90a1353d-51d51a6e4f3mr13617201e0c.0.1737490672921; Tue, 21 Jan 2025 12:17:52 -0800 (PST)
MIME-Version: 1.0
References: <CAMm+Lwgykk+B2UspfXBcLipFiTifNBf-WG-DeXPpWT39syqqVg@mail.gmail.com> <CAD9ie-tYsCODGfNTBDZgr46s4O4B9-u79jR=G10y4sN5HBiKgQ@mail.gmail.com> <CAMm+Lwje3G7EPkapFfVksbNtPN11LOs7Gj3Jj09uuFyvAb4FRQ@mail.gmail.com> <CAJot-L06J-T7vK2FJY4JGFQj4Zu=xFyNnKpnNM2SktCpOuTDKw@mail.gmail.com> <CAMm+Lwg+OizX_+bW7gkFqE3S6OGdF=h=7hpMSgnREWiqawiA5g@mail.gmail.com> <CAJot-L1rbkYg3rooqLrWw5StrqJMFZp7puc4GK+ACOqPtVbaig@mail.gmail.com> <CAMm+Lwj6qFy+njAd1T1F70EieJfxHCnkEcVLiGf8u7gSjhg0Kw@mail.gmail.com>
In-Reply-To: <CAMm+Lwj6qFy+njAd1T1F70EieJfxHCnkEcVLiGf8u7gSjhg0Kw@mail.gmail.com>
From: Aaron Parecki <aaron@parecki.com>
Date: Tue, 21 Jan 2025 12:17:42 -0800
X-Gmail-Original-Message-ID: <CAGBSGjr_9zw6=9EhDM7X6pDu2FxtOcjHycZhw=0QKoFhq2Kfaw@mail.gmail.com>
X-Gm-Features: AbW1kvZg-HsppZ8krR8xIbdDQNKoK1EGPlwLkkRm8cb4A2JEexISRjlJ8VAKKk4
Message-ID: <CAGBSGjr_9zw6=9EhDM7X6pDu2FxtOcjHycZhw=0QKoFhq2Kfaw@mail.gmail.com>
To: Phillip Hallam-Baker <phill@hallambaker.com>
Content-Type: multipart/alternative; boundary="0000000000005c3c5d062c3d12e9"
Message-ID-Hash: HFELFYSOTDIAJNC22ZMKGZFQ452BRNLI
X-Message-ID-Hash: HFELFYSOTDIAJNC22ZMKGZFQ452BRNLI
X-MailFrom: aaron@parecki.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: oauth@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Re: DNS Handles
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/rDQtnTLfVsROsnFpWAmv78b4MSc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>

Phillip, please take a look at this spec which is a complete description of
everything to implement a profile of OAuth based on DNS handles:

https://indieauth.spec.indieweb.org

I also have a blog post that talks about this architecture from an OAuth
POV: https://aaronparecki.com/2018/07/07/7/oauth-for-the-open-web

This has been deployed for many years, though not at the scale of BlueSky.
There's a few commercial services that use it, there's plugins for
Wordpress and Drupal, and a bunch of home-grown implementations.

I've been breaking up the spec into smaller I-Ds, most recently presenting
this at the OAuth interim meeting earlier this month:

https://datatracker.ietf.org/doc/html/draft-parecki-oauth-client-id-scheme
https://datatracker.ietf.org/doc/html/draft-parecki-oauth-client-id-metadata-document

These are also what the BlueSky implementation is based on.

Aaron

On Tue, Jan 21, 2025 at 12:03 PM Phillip Hallam-Baker <phill@hallambaker.com>
wrote:

> On Tue, Jan 21, 2025 at 2:43 PM Warren Parad <wparad@rhosys.ch> wrote:
>
>> The only thing lacking is a base of authentication service providers that
>>> are willing to give users control.
>>
>>
>> As someone who works for one of those "authentication service providers",
>> what exactly would we need to support that we don't already?
>>
>
> I am writing a draft. The short answer is almost nothing. But not nothing.
>
> The longer answer is that we need to have:
>
> 1) A detailed explanation that puts ALL the information needed to
> implement against the profile in one place. I am working on an Internet
> draft to do exactly that.
>
> 2) A discussion of how to best present the scheme as something whose
> primary purpose is as an authentication provider rather than an account
> with one social media property that can also be used elsewhere.
>
> 3) A discussion of how to use the DNS handles to enable end-to-end secure
> messaging. If Bob is reading a comment by Alice under @alice.example.com,
> that is the handle he is likely to want to use to message her.
>
> 4) A discussion about what else we might want a DNS handle provider to
> support. I have a prototype running that extends to supporting the IoT
> requirements raised in SETTLE.
>
> Right now, we have 'a' way to do this which is not necessarily the best
> way or the way that allows us to grow in all the ways we might want in the
> future.
>
> I have a history of being able to market protocols and get them into
> widespread use. I haven't always been successful but have more successes
> than failures and I think I know what it takes to make DNS Handles widely
> used, which businesses I need to approach, etc. etc.
>
> The reason I am raising this here now, is that before I go round to the
> DNS registrars (and their affiliates) and the VPN providers and such to say
> this is the thing to do, I want to make sure we have everything straight at
> a technical level so we are all on the same page.
>
>
> _______________________________________________
> OAuth mailing list -- oauth@ietf.org
> To unsubscribe send an email to oauth-leave@ietf.org
>