Re: [ogpx] A Review of Multi-Domain Use Cases [Was: Re: OpenID and OGP : beginning the discussion ...]

Carlo Wood <carlo@alinoe.com> Tue, 30 June 2009 14:11 UTC

Return-Path: <carlo@alinoe.com>
X-Original-To: ogpx@core3.amsl.com
Delivered-To: ogpx@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 13E033A6E55 for <ogpx@core3.amsl.com>; Tue, 30 Jun 2009 07:11:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.321
X-Spam-Level:
X-Spam-Status: No, score=-1.321 tagged_above=-999 required=5 tests=[AWL=0.109, BAYES_00=-2.599, HELO_EQ_AT=0.424, HOST_EQ_AT=0.745]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 70XqVYOt-qsb for <ogpx@core3.amsl.com>; Tue, 30 Jun 2009 07:11:01 -0700 (PDT)
Received: from viefep12-int.chello.at (viefep12-int.chello.at [62.179.121.32]) by core3.amsl.com (Postfix) with ESMTP id C1E443A6E67 for <ogpx@ietf.org>; Tue, 30 Jun 2009 07:11:00 -0700 (PDT)
Received: from edge05.upc.biz ([192.168.13.212]) by viefep12-int.chello.at (InterMail vM.7.09.01.00 201-2219-108-20080618) with ESMTP id <20090630141038.WQLB14963.viefep12-int.chello.at@edge05.upc.biz>; Tue, 30 Jun 2009 16:10:38 +0200
Received: from mail9.alinoe.com ([77.250.43.12]) by edge05.upc.biz with edge id AEAb1c0CW0FlQed05EAdto; Tue, 30 Jun 2009 16:10:38 +0200
X-SourceIP: 77.250.43.12
Received: from carlo by mail9.alinoe.com with local (Exim 4.69) (envelope-from <carlo@alinoe.com>) id 1MLe2r-0006iE-FZ; Tue, 30 Jun 2009 16:10:49 +0200
Date: Tue, 30 Jun 2009 16:10:49 +0200
From: Carlo Wood <carlo@alinoe.com>
To: Infinity Linden <infinity@lindenlab.com>
Message-ID: <20090630141049.GB24477@alinoe.com>
References: <3a880e2c0906280906i2cdcdaa3m3c1b1ef54e4e5fcb@mail.gmail.com> <20090629105140.GA1053@alinoe.com> <b8ef0a220906290413u5a7358eao300c2ff8ee1ab709@mail.gmail.com> <20090629114512.GC1053@alinoe.com> <b8ef0a220906290751s5131c401h1d55ace39348c89e@mail.gmail.com> <20090629161121.GA17251@alinoe.com> <3a880e2c0906291214g421c5bd8r739b6fb81d5e9836@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <3a880e2c0906291214g421c5bd8r739b6fb81d5e9836@mail.gmail.com>
User-Agent: Mutt/1.5.18 (2008-05-17)
Cc: Meadhbh Siobhan <meadhbh.siobhan@gmail.com>, ogpx@ietf.org
Subject: Re: [ogpx] A Review of Multi-Domain Use Cases [Was: Re: OpenID and OGP : beginning the discussion ...]
X-BeenThere: ogpx@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Virtual Worlds and the Open Grid Protocol <ogpx.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ogpx>, <mailto:ogpx-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ogpx>
List-Post: <mailto:ogpx@ietf.org>
List-Help: <mailto:ogpx-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ogpx>, <mailto:ogpx-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 30 Jun 2009 14:11:02 -0000

On Mon, Jun 29, 2009 at 12:14:07PM -0700, Infinity Linden wrote:
> so yeah. a global identifier of some sort is good. it does not need to
> be an email address, but it will have some of the same
> characteristics: part of it will unambiguously identify the authority
> (i.e. the FQDN of the agent domain host that holds info about the
> agent) and the other half holds the identifier that is unique inside
> that domain. i would vote we use a URI; they have these
> characteristics, and they're not an email address that can be spammed.

Agreed. I'd be fine with an url that includes the authority that holds
my account (login credentials). If only because then all viewers have
a nice point to 'contact' to report abuse.

> but at the end of the day if you want distant systems to be able to
> reference individual agents, you would need a way to address them, and
> unless you wanted to REQUIRE a white list you have to admit the
> possibility that a malicious adversary might try to force the protocol
> or spam you.

I'm not that afraid of spam :). I'm "afraid" that I wouldn't be able
to be a different person in SL, because everyone would be able to
find who I am and what i do in RL with a simple Google on my email
address. This is about privacy.

> i also don't think having two John Jones rezzed in the same region at
> the same time is _that_ big of a problem, provided the region domain
> and the client application have enough information to disambiguate the
> two if it is required.

It's definitely a lesser problem than if there can't be two John Jones
rezzed at the same time!

-- 
Carlo Wood <carlo@alinoe.com>