<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: draft-hammer-oauth-00</title>
	<atom:link href="http://blog.mozilla.com/rob-sayre/2008/10/14/draft-hammer-oauth-00/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mozilla.com/rob-sayre/2008/10/14/draft-hammer-oauth-00/</link>
	<description>This Must Be the Place (Naive Melody)</description>
	<lastBuildDate>Thu, 10 Sep 2009 06:17:03 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Rob Sayre&#8217;s Mozilla Blog &#187; Blog Archive &#187; Security happenings</title>
		<link>http://blog.mozilla.com/rob-sayre/2008/10/14/draft-hammer-oauth-00/comment-page-1/#comment-8582</link>
		<dc:creator>Rob Sayre&#8217;s Mozilla Blog &#187; Blog Archive &#187; Security happenings</dc:creator>
		<pubDate>Fri, 31 Oct 2008 21:47:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/rob-sayre/?p=177#comment-8582</guid>
		<description>[...] Eran Hammer-Lahav left a comment chiding me for my no-doubt unoriginal point that OAuth seems to encourage phishing. I&#8217;m a little disturbed by the thinking behind the objection. Sometimes, proposals have flaws that make them unworkable, and it seems to me that OAuth might have just such a flaw with regard to phishing, at least as it is implemented today.    Posted by rsayre Filed in Uncategorized [...]</description>
		<content:encoded><![CDATA[<p>[...] Eran Hammer-Lahav left a comment chiding me for my no-doubt unoriginal point that OAuth seems to encourage phishing. I&#8217;m a little disturbed by the thinking behind the objection. Sometimes, proposals have flaws that make them unworkable, and it seems to me that OAuth might have just such a flaw with regard to phishing, at least as it is implemented today.    Posted by rsayre Filed in Uncategorized [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eran Hammer-Lahav</title>
		<link>http://blog.mozilla.com/rob-sayre/2008/10/14/draft-hammer-oauth-00/comment-page-1/#comment-8530</link>
		<dc:creator>Eran Hammer-Lahav</dc:creator>
		<pubDate>Wed, 15 Oct 2008 22:20:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/rob-sayre/?p=177#comment-8530</guid>
		<description>Without arguing with your point (which was made many times before and without any real progress on solutions), it is still an overall improvement from just giving your username and password to a third party.

In addition, if a site is so concern about redirection in this context, it can give users an &quot;API Key&quot; which they can manually type into the third party application and circumvent the OAuth token flow. It still uses the signature mechanism.

The problem with phishing is that so far, no one suggested any half-decent solution.</description>
		<content:encoded><![CDATA[<p>Without arguing with your point (which was made many times before and without any real progress on solutions), it is still an overall improvement from just giving your username and password to a third party.</p>
<p>In addition, if a site is so concern about redirection in this context, it can give users an &#8220;API Key&#8221; which they can manually type into the third party application and circumvent the OAuth token flow. It still uses the signature mechanism.</p>
<p>The problem with phishing is that so far, no one suggested any half-decent solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Mosedale</title>
		<link>http://blog.mozilla.com/rob-sayre/2008/10/14/draft-hammer-oauth-00/comment-page-1/#comment-8528</link>
		<dc:creator>Dan Mosedale</dc:creator>
		<pubDate>Wed, 15 Oct 2008 18:44:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/rob-sayre/?p=177#comment-8528</guid>
		<description>I wonder if there&#039;s anything the browser could do on the UI front when it encounters an HTTP redirect that would improve things here...</description>
		<content:encoded><![CDATA[<p>I wonder if there&#8217;s anything the browser could do on the UI front when it encounters an HTTP redirect that would improve things here&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
