Re: Requiring Pseudonymous Identifier

2009-05-12 Thread Paul Madsen
there are telco use cases where a family member, by dint only of 'subscriber authentication' to the IDP/OP, is able to access shared resources (e.g. family calendar) at an SP/RP. Unlike in Chris's academia case the OP/IDP is itself unable to distinguish a particular user from amongst other

부재 중 회신

2009-05-12 Thread canihop
Hi Friend, How are you doing recently? I would like to introduce you a very good company which I know. Their website is www.myewell.com. They can offer you all kinds of Electronic products like laptops, gps,TV LCD,cell phones,ps3,MP3/4, etcPlease take some time to have a check, There

Re: Does OAuth security vulnerability affect OpenID/OAuth hybrid?

2009-05-12 Thread Allen Tom
Hi Luke, I don't think there's a session fixation issue with Hybrid, but I believe that several individuals raised concerns regarding auto-approval of OAuth tokens using regular OAuth, which is essentially the same thing as checkid_immediate mode in Hybrid. Is there really a reason why an