-
Website
http://mashable.com/ -
Original page
http://mashable.com/2008/07/28/openid-and-oauth/ -
Subscribe
All Comments -
Community
-
Top Commenters
-
Robert Basil
142 comments · 8 points
-
Jennifer Van Grove
151 comments · 23 points
-
r0cketman22
317 comments · 52 points
-
rajagiri4
160 comments · 2 points
-
barringtonarch
152 comments · 4 points
-
-
Popular Threads
-
Enter the Zappos Sharing Happiness $3,000 Shopping Spree Giveaway Contest
12 hours ago · 112 comments
-
Redbox: The Enemy of the Entertainment Industry? [STUDY]
3 hours ago · 14 comments
-
Holiday Mojo: What Kind of Seasonal Twitter User Are You?
5 hours ago · 14 comments
-
Head to Head: Chrome for Mac vs. Chrome for Windows
8 hours ago · 22 comments
-
Your Next Car Radio Might Be Pandora
11 hours ago · 32 comments
-
Enter the Zappos Sharing Happiness $3,000 Shopping Spree Giveaway Contest
Rick Butts
These three will make our online services adoption experience more transparent.
The three elements for successful Mashup sign-on process:
http://usingit.wordpress.com/2008/07/25/singe-w...
Keren
A couple notes... I think of OAuth as your valet key for the web, you give an OAuth token to Flickr to just get your Gmail contacts, as opposed to giving a full username and password.
OpenID as a SSO has quite a bit of promise, though there are some potential downsides. With all your eggs protected in one basket you want to make sure that basket is secure. We require two-factor auth for our provider at http://myVidoop.com and there are a couple other providers that license our tech like Clickpass, or if you have a paypal token you can use Verisign. If you are familiar with Infocards there are a couple OpenID providers that have Infocard support. Whatever OpenID provider you go with I highly suggest making sure they take security seriously.
There is a neat site dedicated to helping 'bug' websites about OpenID support at http://demand.openid.net/
If you do not want to spend money for Roboform we have a free password manager that ties in to your myVidoop account. I actually use it all the time and it has saved me lots of time and allowed me to ditch the notepad totally.
For anyone interested in what Chris Messina is currently up to check out http://diso-project.org/ The project is aiming to create a single package for the many 'distributed social networking components' currently floating around.
Cheers,
Kevin
I think it is worth pointing out another standard which is around with a rather similar name.
OATH works in a related space to OAUTH and
I have posted something here which explains what OATH is relative to OAUTH and OPEN ID.
Thanks
Mike
http://blogs.verisign.com/identity-emea/
Mike
The only problem with OAUTH is that it only lasts for a little while. Which is good in some cases - but bad in others.
What if a user wants to give facebook constant access to their twitter updates? with OAUTH the user would have to give facebook that approval everyday!