<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: A Question For Passpack Users With OpenID</title>
	<atom:link href="http://blog.passpack.com/2008/08/a-question-for-passpack-users-with-openid/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.passpack.com/2008/08/a-question-for-passpack-users-with-openid/</link>
	<description>Passpack keeps your logins safe, organized and available 24/7. You can send 100% private messages to people you trust.</description>
	<lastBuildDate>Sat, 06 Mar 2010 15:51:23 +0000</lastBuildDate>
	<generator>http://wordpress.org/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Passpack And OpenID: Under the Hood &#171; Passpack Blog</title>
		<link>http://blog.passpack.com/2008/08/a-question-for-passpack-users-with-openid/comment-page-1/#comment-618</link>
		<dc:creator>Passpack And OpenID: Under the Hood &#171; Passpack Blog</dc:creator>
		<pubDate>Mon, 01 Sep 2008 11:43:34 +0000</pubDate>
		<guid isPermaLink="false">http://passpack.wordpress.com/?p=897#comment-618</guid>
		<description>[...] And OpenID: Under the&#160;Hood  Happy September everyone! Last week we threw around some ideas on which OpenID providers to accept and more importantly which not to [...]</description>
		<content:encoded><![CDATA[<p>[...] And OpenID: Under the&nbsp;Hood  Happy September everyone! Last week we threw around some ideas on which OpenID providers to accept and more importantly which not to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Passpack&#8217;s Whitelist&#8230;It&#8217;s Unanimous &#171; Passpack Blog</title>
		<link>http://blog.passpack.com/2008/08/a-question-for-passpack-users-with-openid/comment-page-1/#comment-617</link>
		<dc:creator>Passpack&#8217;s Whitelist&#8230;It&#8217;s Unanimous &#171; Passpack Blog</dc:creator>
		<pubDate>Tue, 19 Aug 2008 11:38:58 +0000</pubDate>
		<guid isPermaLink="false">http://passpack.wordpress.com/?p=897#comment-617</guid>
		<description>[...] Whitelist&#8230;It&#8217;s&#160;Unanimous  We previously mentioned our thoughts on Passpack and OpenID. The feedback was almost unanimous. You as users all seemed to [...]</description>
		<content:encoded><![CDATA[<p>[...] Whitelist&#8230;It&#8217;s&nbsp;Unanimous  We previously mentioned our thoughts on Passpack and OpenID. The feedback was almost unanimous. You as users all seemed to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tara</title>
		<link>http://blog.passpack.com/2008/08/a-question-for-passpack-users-with-openid/comment-page-1/#comment-616</link>
		<dc:creator>Tara</dc:creator>
		<pubDate>Tue, 12 Aug 2008 08:23:36 +0000</pubDate>
		<guid isPermaLink="false">http://passpack.wordpress.com/?p=897#comment-616</guid>
		<description>@Kevin
Can you point me to the known bad providers? Are they all on PhishTank or are there other resources available? Thanks!

@Nicholas
Touché! I think Francesco is working on delegation support right now.</description>
		<content:encoded><![CDATA[<p>@Kevin<br />
Can you point me to the known bad providers? Are they all on PhishTank or are there other resources available? Thanks!</p>
<p>@Nicholas<br />
Touché! I think Francesco is working on delegation support right now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nicholas Paldino</title>
		<link>http://blog.passpack.com/2008/08/a-question-for-passpack-users-with-openid/comment-page-1/#comment-615</link>
		<dc:creator>Nicholas Paldino</dc:creator>
		<pubDate>Mon, 11 Aug 2008 16:32:51 +0000</pubDate>
		<guid isPermaLink="false">http://passpack.wordpress.com/?p=897#comment-615</guid>
		<description>@Tara

I&#039;m fine if they don&#039;t adhere to the standard, but in that same spirit, you should adhere to the standard as well.  Having some other page that the user is required to put on their site to allow delegation is not in the spirit of the standard.</description>
		<content:encoded><![CDATA[<p>@Tara</p>
<p>I&#8217;m fine if they don&#8217;t adhere to the standard, but in that same spirit, you should adhere to the standard as well.  Having some other page that the user is required to put on their site to allow delegation is not in the spirit of the standard.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin Fox</title>
		<link>http://blog.passpack.com/2008/08/a-question-for-passpack-users-with-openid/comment-page-1/#comment-614</link>
		<dc:creator>Kevin Fox</dc:creator>
		<pubDate>Sun, 10 Aug 2008 00:35:17 +0000</pubDate>
		<guid isPermaLink="false">http://passpack.wordpress.com/?p=897#comment-614</guid>
		<description>In general I think creating a whitelist for OpenID providers is a bad thing.  It sets a bad precedent and creates lots of problems for people who want to run their own provider, use delegation, or just are not using a provider on the whitelist.

There are known bad providers out there, and I would suggest using a blacklist and services like PhishTank.

With that said a list of providers that you can recommend to people who are interested in OpenID, or want to know which one they should use,  would definitely be useful.</description>
		<content:encoded><![CDATA[<p>In general I think creating a whitelist for OpenID providers is a bad thing.  It sets a bad precedent and creates lots of problems for people who want to run their own provider, use delegation, or just are not using a provider on the whitelist.</p>
<p>There are known bad providers out there, and I would suggest using a blacklist and services like PhishTank.</p>
<p>With that said a list of providers that you can recommend to people who are interested in OpenID, or want to know which one they should use,  would definitely be useful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sullof</title>
		<link>http://blog.passpack.com/2008/08/a-question-for-passpack-users-with-openid/comment-page-1/#comment-613</link>
		<dc:creator>sullof</dc:creator>
		<pubDate>Sat, 09 Aug 2008 21:06:47 +0000</pubDate>
		<guid isPermaLink="false">http://passpack.wordpress.com/?p=897#comment-613</guid>
		<description>@Thor Marius K.H
I just tried the PhishTank&#039;s API. We will support them. Thanks.</description>
		<content:encoded><![CDATA[<p>@Thor Marius K.H<br />
I just tried the PhishTank&#8217;s API. We will support them. Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sullof</title>
		<link>http://blog.passpack.com/2008/08/a-question-for-passpack-users-with-openid/comment-page-1/#comment-612</link>
		<dc:creator>sullof</dc:creator>
		<pubDate>Sat, 09 Aug 2008 16:18:55 +0000</pubDate>
		<guid isPermaLink="false">http://passpack.wordpress.com/?p=897#comment-612</guid>
		<description>@Omar Shahine
Yes, we will support delegation.</description>
		<content:encoded><![CDATA[<p>@Omar Shahine<br />
Yes, we will support delegation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tara</title>
		<link>http://blog.passpack.com/2008/08/a-question-for-passpack-users-with-openid/comment-page-1/#comment-611</link>
		<dc:creator>Tara</dc:creator>
		<pubDate>Sat, 09 Aug 2008 15:55:34 +0000</pubDate>
		<guid isPermaLink="false">http://passpack.wordpress.com/?p=897#comment-611</guid>
		<description>Well, looks like the consensus is &quot;definitely not A&quot;. So given that, there&#039;s all the other options and suggestions to look into.

Some combination of optional file / warning messages / &quot;I know you don&#039;t know me but stop bugging me setting&quot; could work.

@Nicholas Paldino
We&#039;ve been testing a bunch of providers, and indeed there are some which appear not to be adhering to the standard. We&#039;ve not completed testing yet, and I would like to approach these providers, but if we&#039;re not wrong in our testing (anything is possible right now) then there would be some providers not on the whitelist because they aren&#039;t adhering to the standard.

@Thor Marius K.H
Excellent point.

@Nicholas Paldino &amp; @GrrYumYum
RE: Our welcome message. Yup, we&#039;re looking into better solutions. The current technique is hard for folks to understand.

Thanks everyone! Keep the suggestions coming - it&#039;s incredibly helpful.</description>
		<content:encoded><![CDATA[<p>Well, looks like the consensus is &#8220;definitely not A&#8221;. So given that, there&#8217;s all the other options and suggestions to look into.</p>
<p>Some combination of optional file / warning messages / &#8220;I know you don&#8217;t know me but stop bugging me setting&#8221; could work.</p>
<p>@Nicholas Paldino<br />
We&#8217;ve been testing a bunch of providers, and indeed there are some which appear not to be adhering to the standard. We&#8217;ve not completed testing yet, and I would like to approach these providers, but if we&#8217;re not wrong in our testing (anything is possible right now) then there would be some providers not on the whitelist because they aren&#8217;t adhering to the standard.</p>
<p>@Thor Marius K.H<br />
Excellent point.</p>
<p>@Nicholas Paldino &amp; @GrrYumYum<br />
RE: Our welcome message. Yup, we&#8217;re looking into better solutions. The current technique is hard for folks to understand.</p>
<p>Thanks everyone! Keep the suggestions coming &#8211; it&#8217;s incredibly helpful.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GrrYumYum</title>
		<link>http://blog.passpack.com/2008/08/a-question-for-passpack-users-with-openid/comment-page-1/#comment-599</link>
		<dc:creator>GrrYumYum</dc:creator>
		<pubDate>Sat, 09 Aug 2008 03:21:15 +0000</pubDate>
		<guid isPermaLink="false">http://passpack.wordpress.com/?p=897#comment-599</guid>
		<description>For me option B would be the most appropriate option, since A is way too restrictive.

As for the welcome message, it is completely useless for me since my IP address changes at regular intervals. An image, as previously suggested by Nicholas Paldino, would serve the purpose much better.

Yahoo!&#039;s sign-in seal works quite nice by making use of Flash to store the image on the users computer, that way it doesn&#039;t get lost if the user clears their browser cookies, and I&#039;m sure only Yahoo! websites can read and display the stored image, preventing phishing attacks.</description>
		<content:encoded><![CDATA[<p>For me option B would be the most appropriate option, since A is way too restrictive.</p>
<p>As for the welcome message, it is completely useless for me since my IP address changes at regular intervals. An image, as previously suggested by Nicholas Paldino, would serve the purpose much better.</p>
<p>Yahoo!&#8217;s sign-in seal works quite nice by making use of Flash to store the image on the users computer, that way it doesn&#8217;t get lost if the user clears their browser cookies, and I&#8217;m sure only Yahoo! websites can read and display the stored image, preventing phishing attacks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thor Marius K.H</title>
		<link>http://blog.passpack.com/2008/08/a-question-for-passpack-users-with-openid/comment-page-1/#comment-601</link>
		<dc:creator>Thor Marius K.H</dc:creator>
		<pubDate>Fri, 08 Aug 2008 18:06:41 +0000</pubDate>
		<guid isPermaLink="false">http://passpack.wordpress.com/?p=897#comment-601</guid>
		<description>option D: Check every site against the PhishTank database using their API, if positive, deny, if negative, accept.</description>
		<content:encoded><![CDATA[<p>option D: Check every site against the PhishTank database using their API, if positive, deny, if negative, accept.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
