<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: OpenID 2.0&#8217;s Killer Feature</title>
	<atom:link href="http://barelyenough.org/blog/2007/12/openid-20s-killer-feature/feed/" rel="self" type="application/rss+xml" />
	<link>http://barelyenough.org/blog/2007/12/openid-20s-killer-feature/</link>
	<description></description>
	<pubDate>Thu, 04 Dec 2008 04:33:17 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
		<item>
		<title>By: http://pezra.barelyenough.org/</title>
		<link>http://barelyenough.org/blog/2007/12/openid-20s-killer-feature/#comment-40275</link>
		<dc:creator>http://pezra.barelyenough.org/</dc:creator>
		<pubDate>Wed, 26 Dec 2007 17:59:51 +0000</pubDate>
		<guid isPermaLink="false">http://pezra.barelyenough.org/blog/2007/12/openid-20s-killer-feature/#comment-40275</guid>
		<description>&lt;p&gt;Nilez Parker,&lt;/p&gt;

&lt;p&gt;Unfortunately, I have not really spent a lot of time looking at what OAuth is capable of, so I cannot really say.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Nilez Parker,</p>
<p>Unfortunately, I have not really spent a lot of time looking at what OAuth is capable of, so I cannot really say.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nilez Parker</title>
		<link>http://barelyenough.org/blog/2007/12/openid-20s-killer-feature/#comment-40255</link>
		<dc:creator>Nilez Parker</dc:creator>
		<pubDate>Sat, 22 Dec 2007 02:28:27 +0000</pubDate>
		<guid isPermaLink="false">http://pezra.barelyenough.org/blog/2007/12/openid-20s-killer-feature/#comment-40255</guid>
		<description>&lt;p&gt;above, the reference to "direct identity" really meant "identity discovery"...&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>above, the reference to &#8220;direct identity&#8221; really meant &#8220;identity discovery&#8221;&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nilez Parker</title>
		<link>http://barelyenough.org/blog/2007/12/openid-20s-killer-feature/#comment-40254</link>
		<dc:creator>Nilez Parker</dc:creator>
		<pubDate>Sat, 22 Dec 2007 02:18:14 +0000</pubDate>
		<guid isPermaLink="false">http://pezra.barelyenough.org/blog/2007/12/openid-20s-killer-feature/#comment-40254</guid>
		<description>&lt;p&gt;This new feature is definitely killer. I've spent so much time already trying to figure out if I can accomplish complete transparency between several apps with the current status of OpenId and OAuth.&lt;/p&gt;

&lt;p&gt;It's nice to be able to do direct identity, but that doesn't seem to be all that efficient with OAuth. Wouldn't it be sufficient for an OAuth consumer to pass an openid_url and a kind of permission-to-act-as token, and then the OAuth provider go and authenticate that token with the user's openid_server? In effect, the OAuth consumer has been granted permission to "act as" the user; and the OAuth provider just verifies that fact. What do you think? It'd be less hassle between apps, and zero user interaction.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>This new feature is definitely killer. I&#8217;ve spent so much time already trying to figure out if I can accomplish complete transparency between several apps with the current status of OpenId and OAuth.</p>
<p>It&#8217;s nice to be able to do direct identity, but that doesn&#8217;t seem to be all that efficient with OAuth. Wouldn&#8217;t it be sufficient for an OAuth consumer to pass an openid_url and a kind of permission-to-act-as token, and then the OAuth provider go and authenticate that token with the user&#8217;s openid_server? In effect, the OAuth consumer has been granted permission to &#8220;act as&#8221; the user; and the OAuth provider just verifies that fact. What do you think? It&#8217;d be less hassle between apps, and zero user interaction.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
