Re: [OpenID] OpenID IPR Policy Draft

2006-12-14 Thread Ben Laurie
On 12/6/06, Recordon, David [EMAIL PROTECTED] wrote: Hey guys, Been working with Gabe, and others, on starting to draft an IPR Policy for OpenID specifications. We'd appreciate feedback in terms of if what is written captures the correct intent of the community? We realize the language

Re: [OpenID] Announcing OpenID Authentication 2.0 - Implementor's Draft 11

2007-01-19 Thread Ben Laurie
On 1/19/07, Recordon, David [EMAIL PROTECTED] wrote: So with great pleasure I get to announce the culmination of about nine months of work between the OpenID, XRI, Sxip, and LID communities in the drafting of OpenID Authentication 2.0. This evening the editors have published the final draft

Re: [OpenID] Announcing OpenID Authentication 2.0 - Implementor's Draft 11

2007-01-21 Thread Ben Laurie
On 1/19/07, Dick Hardt [EMAIL PROTECTED] wrote: On 19-Jan-07, at 6:19 AM, Ben Laurie wrote: Still totally unhappy about the phishing issues, which I blogged about here: http://www.links.org/?p=187 There are numerous ways of solving this. Several standard methods can solve

Re: [OpenID] Announcing OpenID Authentication 2.0 - Implementor'sDraft 11

2007-01-22 Thread Ben Laurie
On 1/22/07, Hallam-Baker, Phillip [EMAIL PROTECTED] wrote: [mailto:[EMAIL PROTECTED] On Behalf Of Ben Laurie More importantly, I think I have a solution that will make both of us happy, but I now have to go and ride my motorbike fast, so I'll detail it later. Now there is an exit line

Re: Announcing OpenID Authentication 2.0 - Implementor'sDraft 11

2007-01-22 Thread Ben Laurie
On 1/22/07, Stephane Bortzmeyer [EMAIL PROTECTED] wrote: On Mon, Jan 22, 2007 at 03:36:44PM +, Ben Laurie [EMAIL PROTECTED] wrote a message of 28 lines which said: The only way that I can see that you are going to circumvent an attempt using existing browser capabilities

Re: [OpenID] Announcing OpenID Authentication 2.0 - Implementor'sDraft 11

2007-01-22 Thread Ben Laurie
On 1/22/07, Hallam-Baker, Phillip [EMAIL PROTECTED] wrote: From: Ben Laurie [mailto:[EMAIL PROTECTED] The only way that I can see that you are going to circumvent an attempt using existing browser capabilities is to introduce a malicious login page is through use of some form

Re: [OpenID] Announcing OpenID Authentication 2.0 - Implementor's Draft 11

2007-01-22 Thread Ben Laurie
On 1/22/07, Ben Laurie [EMAIL PROTECTED] wrote: On 1/22/07, Josh Hoyt [EMAIL PROTECTED] wrote: On 1/22/07, Ben Laurie [EMAIL PROTECTED] wrote: On 1/22/07, Ben Laurie [EMAIL PROTECTED] wrote: OK, the idea is pretty simple. Rather like the OpenID Authentication Security Profiles you