Flickr is looking at some of the same problems. They've just release a
new auth spec:

     http://flickr.com/services/api/auth.spec.html

You probably already seen this but I didn't see any mention on the list.

andrew

On 5/30/05, Joshua Schachter <[EMAIL PROTECTED]> wrote:
> 
> > Cynical people like myself may feel a little uncomfortable giving you
> > guys our username/password. Is there any way this could work with just
> > my username?
> 
> Interesting.
> 
> I much prefer app writers to use the API rather than scrape. Of course,
> 
> I want people writing apps that work on people's data to get some sort of
> consent from the user to use that data; the user inputting the
> username/password clearly gives this consent. However there are obvious
> security reasons to never do that.
> 
> It seems to me that there are several possibilities:
> 
> - there could be a password or key or whatever for the API that lets some
>    third party into a user account in a more limited sense (a sort of
>    weakened trust)
> 
> - you could ask delicious to upload data to the app on behalf for the user
>    (continuing to trust delicious)
> 
> - you could download the posts/all file from the API and
>    upload it to the app separately (no trust exchanged, but least friendly
>    to the user)
> 
> Thoughts?
> _______________________________________________
> discuss mailing list
> [email protected]
> http://lists.del.icio.us/cgi-bin/mailman/listinfo/discuss
> 
>
_______________________________________________
discuss mailing list
[email protected]
http://lists.del.icio.us/cgi-bin/mailman/listinfo/discuss

Reply via email to