<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: OpenID versus OAuth from the user&#8217;s perspective</title>
	<atom:link href="http://cakebaker.42dh.com/2008/04/01/openid-versus-oauth-from-the-users-perspective/feed/" rel="self" type="application/rss+xml" />
	<link>http://cakebaker.42dh.com/2008/04/01/openid-versus-oauth-from-the-users-perspective/</link>
	<description>baking cakes with CakePHP</description>
	<lastBuildDate>Tue, 31 Jan 2012 15:12:14 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: cakebaker</title>
		<link>http://cakebaker.42dh.com/2008/04/01/openid-versus-oauth-from-the-users-perspective/comment-page-1/#comment-199497</link>
		<dc:creator>cakebaker</dc:creator>
		<pubDate>Wed, 04 May 2011 14:03:29 +0000</pubDate>
		<guid isPermaLink="false">http://cakebaker.42dh.com/?p=592#comment-199497</guid>
		<description>@Peter: You are welcome!</description>
		<content:encoded><![CDATA[<p>@Peter: You are welcome!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter Monras</title>
		<link>http://cakebaker.42dh.com/2008/04/01/openid-versus-oauth-from-the-users-perspective/comment-page-1/#comment-199333</link>
		<dc:creator>Peter Monras</dc:creator>
		<pubDate>Mon, 02 May 2011 23:18:33 +0000</pubDate>
		<guid isPermaLink="false">http://cakebaker.42dh.com/?p=592#comment-199333</guid>
		<description>Thanks for this article, now I finally understand :)</description>
		<content:encoded><![CDATA[<p>Thanks for this article, now I finally understand :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ingo-Stefan Schilling</title>
		<link>http://cakebaker.42dh.com/2008/04/01/openid-versus-oauth-from-the-users-perspective/comment-page-1/#comment-174848</link>
		<dc:creator>Ingo-Stefan Schilling</dc:creator>
		<pubDate>Mon, 20 Sep 2010 17:18:01 +0000</pubDate>
		<guid isPermaLink="false">http://cakebaker.42dh.com/?p=592#comment-174848</guid>
		<description>@zibin: For now, you might want to have a look into Googles step2 project: http://code.google.com/p/step2/ and http://step2.googlecode.com/svn/spec/openid_oauth_extension/latest/openid_oauth_extension.html which tries to marry both into one - and the server at least works and some libraries seem to exist as well.</description>
		<content:encoded><![CDATA[<p>@zibin: For now, you might want to have a look into Googles step2 project: <a href="http://code.google.com/p/step2/" rel="nofollow">http://code.google.com/p/step2/</a> and <a href="http://step2.googlecode.com/svn/spec/openid_oauth_extension/latest/openid_oauth_extension.html" rel="nofollow">http://step2.googlecode.com/svn/spec/openid_oauth_extension/latest/openid_oauth_extension.html</a> which tries to marry both into one &#8211; and the server at least works and some libraries seem to exist as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cakebaker</title>
		<link>http://cakebaker.42dh.com/2008/04/01/openid-versus-oauth-from-the-users-perspective/comment-page-1/#comment-174169</link>
		<dc:creator>cakebaker</dc:creator>
		<pubDate>Sat, 11 Sep 2010 14:34:39 +0000</pubDate>
		<guid isPermaLink="false">http://cakebaker.42dh.com/?p=592#comment-174169</guid>
		<description>@Bell: Yes, it looks promising, though currently it is &quot;only&quot; a proposal.</description>
		<content:encoded><![CDATA[<p>@Bell: Yes, it looks promising, though currently it is &#8220;only&#8221; a proposal.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bell</title>
		<link>http://cakebaker.42dh.com/2008/04/01/openid-versus-oauth-from-the-users-perspective/comment-page-1/#comment-173382</link>
		<dc:creator>Bell</dc:creator>
		<pubDate>Mon, 06 Sep 2010 18:53:59 +0000</pubDate>
		<guid isPermaLink="false">http://cakebaker.42dh.com/?p=592#comment-173382</guid>
		<description>Thank you very much for the OpenID Connect link cakebaker. That looks like a fantastic step in the right direction.</description>
		<content:encoded><![CDATA[<p>Thank you very much for the OpenID Connect link cakebaker. That looks like a fantastic step in the right direction.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cakebaker</title>
		<link>http://cakebaker.42dh.com/2008/04/01/openid-versus-oauth-from-the-users-perspective/comment-page-1/#comment-168115</link>
		<dc:creator>cakebaker</dc:creator>
		<pubDate>Sat, 17 Jul 2010 15:29:16 +0000</pubDate>
		<guid isPermaLink="false">http://cakebaker.42dh.com/?p=592#comment-168115</guid>
		<description>@zibin: Well, I think it makes sense to have different specs for different things. However, it seems like the relationship of those two specs will change in the future. According to the &lt;a href=&quot;http://openidconnect.com/&quot; rel=&quot;nofollow&quot;&gt;OpenID Connect&lt;/a&gt; (&quot;OpenID 3.0&quot;) proposal, OpenID Connect will be built on OAuth 2.0. So OpenID gets kind of &quot;merged&quot; with OAuth, but OAuth will still exist on its own.

Hope that makes sense ;-)</description>
		<content:encoded><![CDATA[<p>@zibin: Well, I think it makes sense to have different specs for different things. However, it seems like the relationship of those two specs will change in the future. According to the <a href="http://openidconnect.com/" rel="nofollow">OpenID Connect</a> (&#8220;OpenID 3.0&#8243;) proposal, OpenID Connect will be built on OAuth 2.0. So OpenID gets kind of &#8220;merged&#8221; with OAuth, but OAuth will still exist on its own.</p>
<p>Hope that makes sense ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zibin</title>
		<link>http://cakebaker.42dh.com/2008/04/01/openid-versus-oauth-from-the-users-perspective/comment-page-1/#comment-167921</link>
		<dc:creator>zibin</dc:creator>
		<pubDate>Thu, 15 Jul 2010 05:06:28 +0000</pubDate>
		<guid isPermaLink="false">http://cakebaker.42dh.com/?p=592#comment-167921</guid>
		<description>Despite the distinction, is it not better to merge the two into one?</description>
		<content:encoded><![CDATA[<p>Despite the distinction, is it not better to merge the two into one?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cakebaker</title>
		<link>http://cakebaker.42dh.com/2008/04/01/openid-versus-oauth-from-the-users-perspective/comment-page-1/#comment-143880</link>
		<dc:creator>cakebaker</dc:creator>
		<pubDate>Wed, 13 Jan 2010 15:57:09 +0000</pubDate>
		<guid isPermaLink="false">http://cakebaker.42dh.com/?p=592#comment-143880</guid>
		<description>@Erik: Thanks for the link to that video, and good luck on your journey with OpenID and OAuth :)</description>
		<content:encoded><![CDATA[<p>@Erik: Thanks for the link to that video, and good luck on your journey with OpenID and OAuth :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Erik</title>
		<link>http://cakebaker.42dh.com/2008/04/01/openid-versus-oauth-from-the-users-perspective/comment-page-1/#comment-143767</link>
		<dc:creator>Erik</dc:creator>
		<pubDate>Mon, 11 Jan 2010 19:52:37 +0000</pubDate>
		<guid isPermaLink="false">http://cakebaker.42dh.com/?p=592#comment-143767</guid>
		<description>@cakebaker: yes it definitely does help and I thank you for your response.

My struggle to put all of this together into a cohesive whole continues and may well forever but I&#039;m very excited about the prospects this sort of effort will offer. I found a YouTube video  http://www.youtube.com/watch?v=6SYnlH5FXz0 which is exceptional in filling in the missing pieces, at least conceptually.

I feel strong enough about the righteousness of the OpenID and OAuth concepts that I&#039;ll be committing to using them exclusively in all of my future projects even if it&#039;s a bumpy, partially paved road. I suppose if it wasn&#039;t, it wouldn&#039;t be interesting.

Keep up the great work!</description>
		<content:encoded><![CDATA[<p>@cakebaker: yes it definitely does help and I thank you for your response.</p>
<p>My struggle to put all of this together into a cohesive whole continues and may well forever but I&#8217;m very excited about the prospects this sort of effort will offer. I found a YouTube video  <a href="http://www.youtube.com/watch?v=6SYnlH5FXz0" rel="nofollow">http://www.youtube.com/watch?v=6SYnlH5FXz0</a> which is exceptional in filling in the missing pieces, at least conceptually.</p>
<p>I feel strong enough about the righteousness of the OpenID and OAuth concepts that I&#8217;ll be committing to using them exclusively in all of my future projects even if it&#8217;s a bumpy, partially paved road. I suppose if it wasn&#8217;t, it wouldn&#8217;t be interesting.</p>
<p>Keep up the great work!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cakebaker</title>
		<link>http://cakebaker.42dh.com/2008/04/01/openid-versus-oauth-from-the-users-perspective/comment-page-1/#comment-143756</link>
		<dc:creator>cakebaker</dc:creator>
		<pubDate>Mon, 11 Jan 2010 16:22:49 +0000</pubDate>
		<guid isPermaLink="false">http://cakebaker.42dh.com/?p=592#comment-143756</guid>
		<description>@Erik: Thanks for your comment!

Yes, the described scenario is correct. And I agree with you, the user experience is not that great in such a use case...

OAuth Wrap could, theoretically, simplify this process if the two services (Picasa, Flickr) trust each other&#039;s Authorization Servers (or use the same Authorization Server). In that case the scenario would look like:
1. - 3. Same as above
4. Settings page redirects the user to the Authorization Server and the user authorizes access
5. Same as above.
6. No such step ;-)

But as always with new protocols: it will take quite some time until it gets implemented...

I hope this answers your question.</description>
		<content:encoded><![CDATA[<p>@Erik: Thanks for your comment!</p>
<p>Yes, the described scenario is correct. And I agree with you, the user experience is not that great in such a use case&#8230;</p>
<p>OAuth Wrap could, theoretically, simplify this process if the two services (Picasa, Flickr) trust each other&#8217;s Authorization Servers (or use the same Authorization Server). In that case the scenario would look like:<br />
1. &#8211; 3. Same as above<br />
4. Settings page redirects the user to the Authorization Server and the user authorizes access<br />
5. Same as above.<br />
6. No such step ;-)</p>
<p>But as always with new protocols: it will take quite some time until it gets implemented&#8230;</p>
<p>I hope this answers your question.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

