[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: OpenID
From: |
Davi Leal |
Subject: |
Re: OpenID |
Date: |
Mon, 2 Jun 2008 09:27:48 +0200 |
User-agent: |
KMail/1.9.7 |
> Proposed roadmap:
>
> 1. Follow adding improvements.
>
> 2. Finish the development of the volunteers and pledges feature.
...
> 5. Analyze the OpenID idea.
> It was task: http://savannah.nongnu.org/task/?6782
I propose the project do not use any OpenID shared identity services. If
nobody disagree we should close such task adding a reference to the below
rationale:
Rationale:
* If GNU Herds add OpenID support, any security problem at the OpenID
servers will be a very serious security problem for GNU Herds.
* What OpenID servers GNU Herds would support? The more OpenID
servers GNU Herds support the more security risk paths for the
GNU Herds project.
Note the OpenID use delegates the authentication process which is
a central security piece.
IMHO the above rationale is enough to reject the OpenID use. Additionally:
* Note maybe the GNU Heds project will make bank transactions. So
the above problems are even more critic.
It could be other problems not analyzed here.
--
As usual we could be wrong. Please let this mailing list know about any
mistake in the above rationale.
- Re: DB vs FS based webapp architectures -- web 2.0 -- RSS, etc., (continued)
- Re: DB vs FS based webapp architectures -- web 2.0 -- RSS, etc., Davi Leal, 2008/05/08
- Re: DB vs FS based webapp architectures -- web 2.0 -- RSS, etc., Antenore Gatta, 2008/05/09
- Re: DB vs FS based webapp architectures -- web 2.0 -- RSS, etc., Davi Leal, 2008/05/09
- Re: DB vs FS based webapp architectures -- web 2.0 -- RSS, etc., Antenore Gatta, 2008/05/19
- Re: DB vs FS based webapp architectures -- web 2.0 -- RSS, etc., Antenore Gatta, 2008/05/19
- Re: DB vs FS based webapp architectures -- web 2.0 -- RSS, etc., Antenore Gatta, 2008/05/19
- Re: DB vs FS based webapp architectures -- web 2.0 -- RSS, etc., MJ Ray, 2008/05/19
- Re: gnuherds-app-dev mungs Reply-To and surprises people, Davi Leal, 2008/05/19
- Re: DB vs FS based webapp architectures -- web 2.0 -- RSS, etc., Dave Crossland, 2008/05/19
- Re: web 2.0, Davi Leal, 2008/05/19
- Re: OpenID,
Davi Leal <=
- Re: DB vs FS, Davi Leal, 2008/05/08
- Re: DB vs FS, Dion Rasmussen, 2008/05/09
- Re: cookies vs http authentication, Davi Leal, 2008/05/08
- Re: cookies vs http authentication, Dion Rasmussen, 2008/05/09
- Re: cookies vs http authentication, Chris Carpita, 2008/05/09
- Re: Cookie-over-HTTPS vs HTTP authentication, Davi Leal, 2008/05/09