<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Passwordless MyOpenID</title>
	<atom:link href="http://blog.jonudell.net/2007/12/04/passwordless-myopenid/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.jonudell.net/2007/12/04/passwordless-myopenid/</link>
	<description>Strategies for Internet citizens</description>
	<lastBuildDate>Sat, 11 Feb 2012 19:45:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: steve</title>
		<link>http://blog.jonudell.net/2007/12/04/passwordless-myopenid/#comment-123133</link>
		<dc:creator><![CDATA[steve]]></dc:creator>
		<pubDate>Thu, 17 Apr 2008 16:30:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/12/04/passwordless-myopenid/#comment-123133</guid>
		<description><![CDATA[The team I work with has created a password-less provider service that binds a users account to an strong authentication devices, such as a smart card, fingerprint reader, or USB token:

https://openid.trustbearer.com]]></description>
		<content:encoded><![CDATA[<p>The team I work with has created a password-less provider service that binds a users account to an strong authentication devices, such as a smart card, fingerprint reader, or USB token:</p>
<p><a href="https://openid.trustbearer.com" rel="nofollow">https://openid.trustbearer.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Udell</title>
		<link>http://blog.jonudell.net/2007/12/04/passwordless-myopenid/#comment-101472</link>
		<dc:creator><![CDATA[Jon Udell]]></dc:creator>
		<pubDate>Fri, 07 Dec 2007 17:49:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/12/04/passwordless-myopenid/#comment-101472</guid>
		<description><![CDATA[&quot;How well will OpenID retrofit?&quot;

My hope is that for OpenID, and also CardSpace, we&#039;ll find that over time sites offer us the option to migrate from name/password to these other mechanisms. 

Right now, you&#039;d be the oddball service if you offered an alternative, so there&#039;s no peer pressure to do it. But when things tip, you&#039;ll be the oddball for not offering alternatives. Then you&#039;ll feel that pressure, and will want to do something about it.]]></description>
		<content:encoded><![CDATA[<p>&#8220;How well will OpenID retrofit?&#8221;</p>
<p>My hope is that for OpenID, and also CardSpace, we&#8217;ll find that over time sites offer us the option to migrate from name/password to these other mechanisms. </p>
<p>Right now, you&#8217;d be the oddball service if you offered an alternative, so there&#8217;s no peer pressure to do it. But when things tip, you&#8217;ll be the oddball for not offering alternatives. Then you&#8217;ll feel that pressure, and will want to do something about it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TX972</title>
		<link>http://blog.jonudell.net/2007/12/04/passwordless-myopenid/#comment-101457</link>
		<dc:creator><![CDATA[TX972]]></dc:creator>
		<pubDate>Fri, 07 Dec 2007 17:33:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/12/04/passwordless-myopenid/#comment-101457</guid>
		<description><![CDATA[How well will OpenID retrofit?  Those of us who have been using the internet for a couple of years or more must have accumulated a hundred of more sites that require User ID/Password.  Will OpenID retrofit these?

Rhapsody, Yahoo, email servers, medical insurance site, Youtube, Digg, FlightAware, Slacker, Netflix, Myspace, Hotwire, eBay, university site, MetaFilter, MarketScreen.com, Raging Bull, Sirius Radio, etc., etc.

There are strategies for handling all these passwords --- mostly to use one ID as often as possible and to record all IDs to a word document the name of which is well camouflaged, so as to be of minimal interest to any possible hacker.

If OpenID can not adapt to dozens/hundreds of existing IDs, then I&#039;m afraid it just gets added to the list of one more site&#039;s passwords.  One other concern is how well OpenID&#039;s server is protected from intruders.  My computer is just one of many millions.  Chances are pretty low that I&#039;ll be randomly hit by a hacker.  OpenID is out there labeled as a site containing LOTS of passwords.  That&#039;s so much more attractive to hackers than my one measly computer.  Do I want to open myself to that magnitude of a risk of computer-identity theft?]]></description>
		<content:encoded><![CDATA[<p>How well will OpenID retrofit?  Those of us who have been using the internet for a couple of years or more must have accumulated a hundred of more sites that require User ID/Password.  Will OpenID retrofit these?</p>
<p>Rhapsody, Yahoo, email servers, medical insurance site, Youtube, Digg, FlightAware, Slacker, Netflix, Myspace, Hotwire, eBay, university site, MetaFilter, MarketScreen.com, Raging Bull, Sirius Radio, etc., etc.</p>
<p>There are strategies for handling all these passwords &#8212; mostly to use one ID as often as possible and to record all IDs to a word document the name of which is well camouflaged, so as to be of minimal interest to any possible hacker.</p>
<p>If OpenID can not adapt to dozens/hundreds of existing IDs, then I&#8217;m afraid it just gets added to the list of one more site&#8217;s passwords.  One other concern is how well OpenID&#8217;s server is protected from intruders.  My computer is just one of many millions.  Chances are pretty low that I&#8217;ll be randomly hit by a hacker.  OpenID is out there labeled as a site containing LOTS of passwords.  That&#8217;s so much more attractive to hackers than my one measly computer.  Do I want to open myself to that magnitude of a risk of computer-identity theft?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Udell</title>
		<link>http://blog.jonudell.net/2007/12/04/passwordless-myopenid/#comment-101302</link>
		<dc:creator><![CDATA[Jon Udell]]></dc:creator>
		<pubDate>Fri, 07 Dec 2007 12:31:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/12/04/passwordless-myopenid/#comment-101302</guid>
		<description><![CDATA[&quot;there are pretty serious security issues with it, both at the technical level, and at the social-engineering level.&quot;

Which is why marrying OpenID with a passwordless identity selector is helpful.]]></description>
		<content:encoded><![CDATA[<p>&#8220;there are pretty serious security issues with it, both at the technical level, and at the social-engineering level.&#8221;</p>
<p>Which is why marrying OpenID with a passwordless identity selector is helpful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: martin langhoff</title>
		<link>http://blog.jonudell.net/2007/12/04/passwordless-myopenid/#comment-99756</link>
		<dc:creator><![CDATA[martin langhoff]]></dc:creator>
		<pubDate>Wed, 05 Dec 2007 00:36:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.jonudell.net/2007/12/04/passwordless-myopenid/#comment-99756</guid>
		<description><![CDATA[When discussing OpenID it is important to note that there are pretty serious security issues with it, both at the technical level, and at the social-engineering level. While looking at implementing it for Moodle on the OLPC school server, I&#039;ve had some discussions with Ben Laurie (author of the Apache SSL module, and well versed in PKI and similar arcana). 

See the discussion here
http://lists.laptop.org/pipermail/server-devel/2007-July/000083.html and Ben Laurie&#039;s notes at http://www.links.org/?p=187 and his later blogposts.]]></description>
		<content:encoded><![CDATA[<p>When discussing OpenID it is important to note that there are pretty serious security issues with it, both at the technical level, and at the social-engineering level. While looking at implementing it for Moodle on the OLPC school server, I&#8217;ve had some discussions with Ben Laurie (author of the Apache SSL module, and well versed in PKI and similar arcana). </p>
<p>See the discussion here<br />
<a href="http://lists.laptop.org/pipermail/server-devel/2007-July/000083.html" rel="nofollow">http://lists.laptop.org/pipermail/server-devel/2007-July/000083.html</a> and Ben Laurie&#8217;s notes at <a href="http://www.links.org/?p=187" rel="nofollow">http://www.links.org/?p=187</a> and his later blogposts.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

