[oauth] Re: a simple view of the OAuth security issue

2009-04-27 Thread Eve Maler
Sakimura (=nat) http://www.sakimura.org/en/ Eve Maler eve.maler @ sun.com Emerging Technologies Directorcell +1 425 345 6756 Sun Microsystems Identity Softwarewww.xmlgrrl.com/blog

[oauth] Re: a simple view of the OAuth security issue

2009-04-27 Thread Eve Maler
-- even PINs have social engineering risks, aren't we really just looking for ever-better ways to do weak equivalence rather than testing true equivalence? Eve On Apr 27, 2009, at 8:01 AM, Peter Keane wrote: On Mon, Apr 27, 2009 at 9:42 AM, Eve Maler eve.ma...@sun.com wrote: Other

Re: [oauth] Finer-grained access control in OAuth?

2010-03-20 Thread Eve Maler
/group/oauth?hl=en. Eve Maler e...@xmlgrrl.com http://www.xmlgrrl.com/blog -- You received this message because you are subscribed to the Google Groups OAuth group. To post to this group, send email to oa...@googlegroups.com. To unsubscribe from this group, send email to oauth+unsubscr

[oauth] Good list of OAuth open source?

2011-06-20 Thread Eve Maler
The list at http://oauth.net/code/ seems really random and out of date. Does anyone have a current list of open-source software that supports OAuth, including drafts of 2.0? Thanks, Eve Eve Maler http://www.xmlgrrl.com/blog +1 425 345 6756

Re: [oauth] Question about the OAuth RFC

2013-03-19 Thread Eve Maler
://groups.google.com/groups/opt_out. Eve Maler http://www.xmlgrrl.com/blog +1 425 345 6756 http://www.twitter.com/xmlgrrl -- You received this message because you are subscribed to the Google Groups OAuth group. To unsubscribe from

Re: [oauth] Question about the OAuth RFC

2013-03-20 Thread Eve Maler
a means to do this, yes? It would also allow me to grant access in certain instances based on the way the authentication server is configured, yes? On Wednesday, March 20, 2013 1:01:46 AM UTC-4, Eve Maler wrote: OAuth has a soft assumption, which surfaces in the passage you quote among