<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: An insecurity in OpenID, not many dead</title>
	<atom:link href="http://www.lightbluetouchpaper.org/2008/08/09/an-insecurity-in-openid-not-many-dead/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lightbluetouchpaper.org/2008/08/09/an-insecurity-in-openid-not-many-dead/</link>
	<description>Security Research, Computer Laboratory, University of Cambridge</description>
	<lastBuildDate>Fri, 10 Feb 2012 17:31:40 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Robin Wilton</title>
		<link>http://www.lightbluetouchpaper.org/2008/08/09/an-insecurity-in-openid-not-many-dead/comment-page-1/#comment-30015</link>
		<dc:creator>Robin Wilton</dc:creator>
		<pubDate>Thu, 30 Oct 2008 19:02:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=352#comment-30015</guid>
		<description>@Tim - I&#039;m sure he has... if only I were as funny ;^)

@Richard - it&#039;s a bit harsh to suggest that people &quot;shouldn&#039;t trust Sun&quot;; don&#039;t you mean that they shouldn&#039;t trust authentication assertions from Sun&#039;s OpenID Provider? (And if the latter.... does that actually change the OpenID trust model...?)</description>
		<content:encoded><![CDATA[<p>@Tim &#8211; I&#8217;m sure he has&#8230; if only I were as funny ;^)</p>
<p>@Richard &#8211; it&#8217;s a bit harsh to suggest that people &#8220;shouldn&#8217;t trust Sun&#8221;; don&#8217;t you mean that they shouldn&#8217;t trust authentication assertions from Sun&#8217;s OpenID Provider? (And if the latter&#8230;. does that actually change the OpenID trust model&#8230;?)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim</title>
		<link>http://www.lightbluetouchpaper.org/2008/08/09/an-insecurity-in-openid-not-many-dead/comment-page-1/#comment-29726</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Thu, 14 Aug 2008 15:35:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=352#comment-29726</guid>
		<description>I giggled at the penultimate paragraph. I thought Robin Williams had something funny to say about certificates.</description>
		<content:encoded><![CDATA[<p>I giggled at the penultimate paragraph. I thought Robin Williams had something funny to say about certificates.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eduardo Diaz</title>
		<link>http://www.lightbluetouchpaper.org/2008/08/09/an-insecurity-in-openid-not-many-dead/comment-page-1/#comment-29724</link>
		<dc:creator>Eduardo Diaz</dc:creator>
		<pubDate>Wed, 13 Aug 2008 22:18:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=352#comment-29724</guid>
		<description>not very funny, because that small earthquake in Chile caused 30.000 death, Chillán, january 24, 1939...</description>
		<content:encoded><![CDATA[<p>not very funny, because that small earthquake in Chile caused 30.000 death, Chillán, january 24, 1939&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: oregonnerd</title>
		<link>http://www.lightbluetouchpaper.org/2008/08/09/an-insecurity-in-openid-not-many-dead/comment-page-1/#comment-29721</link>
		<dc:creator>oregonnerd</dc:creator>
		<pubDate>Wed, 13 Aug 2008 06:50:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=352#comment-29721</guid>
		<description>Yeah.  I was skeptical to start.  I&#039;m either intrinsically paranoid, I assume that planning will always work as poorly as possible (a linear model in a curvilinear environment has interesting implications, and I don&#039;t believe in bivalue logic), or I think most people are stupid.  Then again, I used a three-value statement behind a two-value intro.
--Glenn
--Blog is on WordPress which appears to be down.  I hope I didn&#039;t get spoofed somehow.</description>
		<content:encoded><![CDATA[<p>Yeah.  I was skeptical to start.  I&#8217;m either intrinsically paranoid, I assume that planning will always work as poorly as possible (a linear model in a curvilinear environment has interesting implications, and I don&#8217;t believe in bivalue logic), or I think most people are stupid.  Then again, I used a three-value statement behind a two-value intro.<br />
&#8211;Glenn<br />
&#8211;Blog is on WordPress which appears to be down.  I hope I didn&#8217;t get spoofed somehow.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Clayton</title>
		<link>http://www.lightbluetouchpaper.org/2008/08/09/an-insecurity-in-openid-not-many-dead/comment-page-1/#comment-29712</link>
		<dc:creator>Richard Clayton</dc:creator>
		<pubDate>Sat, 09 Aug 2008 15:32:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=352#comment-29712</guid>
		<description>@Paul   You&#039;re right that the attack wasn&#039;t preventable: OpenID relies on certificate integrity and this failed. However, without universal use of CRLs you can&#039;t stop people continuing to rely on the certs until they expire -- and CRLs are not widely enough used.

@Bernard  Credentica does have a blacklisting scheme that doesn&#039;t depend on CRLs. But I would not have characterised this as the main justification for (or feature of) the technology!</description>
		<content:encoded><![CDATA[<p>@Paul   You&#8217;re right that the attack wasn&#8217;t preventable: OpenID relies on certificate integrity and this failed. However, without universal use of CRLs you can&#8217;t stop people continuing to rely on the certs until they expire &#8212; and CRLs are not widely enough used.</p>
<p>@Bernard  Credentica does have a blacklisting scheme that doesn&#8217;t depend on CRLs. But I would not have characterised this as the main justification for (or feature of) the technology!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bernard lunn</title>
		<link>http://www.lightbluetouchpaper.org/2008/08/09/an-insecurity-in-openid-not-many-dead/comment-page-1/#comment-29711</link>
		<dc:creator>bernard lunn</dc:creator>
		<pubDate>Sat, 09 Aug 2008 12:09:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=352#comment-29711</guid>
		<description>is this the problem that Credentica aims to solve?</description>
		<content:encoded><![CDATA[<p>is this the problem that Credentica aims to solve?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Crowley</title>
		<link>http://www.lightbluetouchpaper.org/2008/08/09/an-insecurity-in-openid-not-many-dead/comment-page-1/#comment-29710</link>
		<dc:creator>Paul Crowley</dc:creator>
		<pubDate>Sat, 09 Aug 2008 11:11:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/?p=352#comment-29710</guid>
		<description>I&#039;m not sure there&#039;s anything we could or should have done in OpenID that would have prevented such an attack.  The two mechanisms that OpenID uses to verify the identity of a provider (connecting to it in the first place and, optionally, SSL) have been defeated in two separate attacks; what else could we have stood on?</description>
		<content:encoded><![CDATA[<p>I&#8217;m not sure there&#8217;s anything we could or should have done in OpenID that would have prevented such an attack.  The two mechanisms that OpenID uses to verify the identity of a provider (connecting to it in the first place and, optionally, SSL) have been defeated in two separate attacks; what else could we have stood on?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

