Slashdot Mirror


User: DeFender1031

DeFender1031's activity in the archive.

Stories
0
Comments
8
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 8

  1. Re:Native apps == insecure on A Truckload of OAuth Issues That Would Make Any Author Quit · · Score: 1

    Exactly. And the people commenting that "you should never have a hacked browser" don't get that it's referring to native apps which embed a browser to mislead you rather than, say, a spyware-infested version of firefox. Of course you shouldn't have the latter, but for the former, anyone can make an app that imitates anything.

  2. Re:totally secure == powered off on A Truckload of OAuth Issues That Would Make Any Author Quit · · Score: 1

    True that's exactly what it is but with a lot of cruft surrounding it as well. It requires a web browser to facilitate the connection, rather than the user just copying a password to wherever it's needed, it requires that the third-party application which wants to authenticate needs its own domain and its own server, instead of just being able to be a standalone application which can authenticate directly. Because of this, it's just a mess of a system. What the author is suggesting is to leave the part of it that's based on a solid security foundation intact, (the part that says "separate keys for each application with limited access") but remove all of the insanity around it that adds no extra security and just serves to confuse the issue and limit its usability.

  3. Re:Not complex; not broken; not meant for enterpri on A Truckload of OAuth Issues That Would Make Any Author Quit · · Score: 1

    If people were only using OAuth for web-to-web communication, I don't think those issues would have been raised. But many of the big players have their "API"s based on it. Take a look at this thread on citrix's development site for example. Here, there's a service which is hardly web-based, pretty much the only thing web-based about it is that you join meetings by browsing to a URL, and yet the only authentication model they provide for their "API" is OAuth. This is wrong. It's not what OAuth was designed for. And yet it's what's being used. If people would stick to its intended purpose when using it, there would be no problem, but this is hardly the case.

  4. Re:totally secure == powered off on A Truckload of OAuth Issues That Would Make Any Author Quit · · Score: 2

    Again, you miss the point. The point isn't separate accounts. The point is, you have a user account, say "JoeCool", and a password, say "12345". Your system allows Joe, when logged in under that password, to create a secondary password, 67890 which, when logged in with, only allows limited access. Joe can then give "67890" as a password a third-party application, which will then have only limited access. If the application misbehaves, Joe can remove the "67890" password, thus locking out the malicious application while keeping his primary password secure, along with any other secondary passwords he's generated for other applications. That's the system being described and that's a system which would avoid a heck of a lot of headache.

    And I'd appreciate not being called names by someone who hasn't even taken the time to understand what's being said.

  5. Re:totally secure == powered off on A Truckload of OAuth Issues That Would Make Any Author Quit · · Score: 3

    You miss the point. He says to have the user create separate passwords from the primary one, with restricted permissions, and give a different managed password to each application. That way, if the application misbehaves, the user themselves can remove that password without having to affect anything else.

  6. Re:They make products for this already on Moodle 1.9 For Second Language Teaching · · Score: 1

    Forgot to mention, my teacher uses live meeting... apparently groopex integrates live meeting as well as webex.

  7. Re:They make products for this already on Moodle 1.9 For Second Language Teaching · · Score: 1

    I learned hebrew from a teacher who uses a groopex integrated moodle site, and i found the live classes far better than simple downloads of static files that i'd tried in the past. I'm surprised how few people use these real-time tools.

  8. A complete set on Gates and Jobs to Share A Stage · · Score: 3, Funny

    Where's Linus and Stallman? Throw them in there for Super Smash CEOs Brawl!