<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Kyle Brady: A Blog - Latest Comments in idAuth Proposal, Take 2</title><link>http://kyle-brady.disqus.com/</link><description>thoughts on life, code, and things</description><language>en</language><lastBuildDate>Fri, 30 May 2008 11:42:29 -0000</lastBuildDate><item><title>Re: idAuth Proposal, Take 2</title><link>http://www.kyle-brady.com/2008/05/26/idauth-proposal-take-2/#comment-1705355</link><description>That's the right approach-- focus on the user scenarios and making the user experience right.  The engineers can then work their magic to support the requirements.&lt;br&gt;&lt;br&gt;The idAuth idea plays nicely with the "commenter's bill of right" posted over at Disqus.  To enforce these rights, a system of definitive comment ownership is needed.  &lt;br&gt;&lt;br&gt;&lt;a href="http://bigheadlabs.com/%7Edaniel/draft/acommentersrights.html" rel="nofollow"&gt;http://bigheadlabs.com/~daniel/draft/acommenter...&lt;/a&gt;&lt;br&gt;&lt;br&gt;Things are headed in the right direction!</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tom</dc:creator><pubDate>Fri, 30 May 2008 11:42:29 -0000</pubDate></item><item><title>Re: idAuth Proposal, Take 2</title><link>http://www.kyle-brady.com/2008/05/26/idauth-proposal-take-2/#comment-1705354</link><description>Hey Tom,&lt;br&gt;&lt;br&gt;Thanks!&lt;br&gt;&lt;br&gt;I understand the cookies are going to be a problem, and I'm aware that there are a few domain restriction workaround attempts, but I wanted to have somewhere to start.  How it actually works (from a technical perspective) is going to be part of the process... &lt;br&gt;&lt;br&gt;In the same vein, I want to specifically avoid a "true" auth system, at least for now, because of the high-cost of the user experience... I don't want this to be used by the tech elite.  I want this to be used by grandma.  ;-)&lt;br&gt;&lt;br&gt;--Kyle</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">bradyk</dc:creator><pubDate>Thu, 29 May 2008 21:12:54 -0000</pubDate></item><item><title>Re: idAuth Proposal, Take 2</title><link>http://www.kyle-brady.com/2008/05/26/idauth-proposal-take-2/#comment-1705353</link><description>I like the idea-- it's a step towards giving me control over all content I publish/contribute on the web, whether a blog post or a blog comment, a photo, etc.&lt;br&gt;&lt;br&gt;I'm not a member of SID, so not sure what's being discussed, but the cookie idea can be problematic since the blog comment system will be unable to read cookies set by the  aggregator (unless they are in the same domain).  This is why federated auth systems implement an intermediate redirect, passing encrypted information in the querystring and ultimately two cookies get set, one in each domain.  (Or backend web-service calls are made.)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tom</dc:creator><pubDate>Thu, 29 May 2008 19:08:40 -0000</pubDate></item></channel></rss>