<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Trust your OpenID Provider?</title>
	<atom:link href="http://www.notsorelevant.com/2007-04-04/trust-your-openid-provider/feed/" rel="self" type="application/rss+xml" />
	<link>http://notsorelevant.com/2007-04-04/trust-your-openid-provider/</link>
	<description>no expert in technology</description>
	<pubDate>Sun, 12 Oct 2008 19:59:11 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Discussion on People Search Engines in Germany at Not So Relevant</title>
		<link>http://notsorelevant.com/2007-04-04/trust-your-openid-provider/#comment-5331</link>
		<dc:creator>Discussion on People Search Engines in Germany at Not So Relevant</dc:creator>
		<pubDate>Sun, 12 Aug 2007 09:45:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsorelevant.com/2007-04-04/trust-your-openid-provider/#comment-5331</guid>
		<description>[...] personal data and use it for commercial purposes, e.g. a German guy started an initiative called OpenID - Nein Danke (OpenID - No Thanks) a few months ago because OpenID providers had the opportunity to create [...]</description>
		<content:encoded><![CDATA[<p>[...] personal data and use it for commercial purposes, e.g. a German guy started an initiative called OpenID - Nein Danke (OpenID - No Thanks) a few months ago because OpenID providers had the opportunity to create [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Setting up your own OpenID Server at Not So Relevant</title>
		<link>http://notsorelevant.com/2007-04-04/trust-your-openid-provider/#comment-4470</link>
		<dc:creator>Setting up your own OpenID Server at Not So Relevant</dc:creator>
		<pubDate>Wed, 02 May 2007 22:04:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsorelevant.com/2007-04-04/trust-your-openid-provider/#comment-4470</guid>
		<description>[...] are some people who consider OpenID providers a risk to privacy because providers are able to monitor all the sites [...]</description>
		<content:encoded><![CDATA[<p>[...] are some people who consider OpenID providers a risk to privacy because providers are able to monitor all the sites [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Carsten PÃ¶tter</title>
		<link>http://notsorelevant.com/2007-04-04/trust-your-openid-provider/#comment-4154</link>
		<dc:creator>Carsten PÃ¶tter</dc:creator>
		<pubDate>Mon, 09 Apr 2007 21:17:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsorelevant.com/2007-04-04/trust-your-openid-provider/#comment-4154</guid>
		<description>I am sure there will be competition between IdP's. Some IdP's even have similar solutions to phishing as PassPack has.

While OpenID is still not perfect I'm confident that all major problems will be solved someday because the OpenID community is aware of them and doesn't deny them; some of them are even mentioned in the specs.</description>
		<content:encoded><![CDATA[<p>I am sure there will be competition between IdP&#8217;s. Some IdP&#8217;s even have similar solutions to phishing as PassPack has.</p>
<p>While OpenID is still not perfect I&#8217;m confident that all major problems will be solved someday because the OpenID community is aware of them and doesn&#8217;t deny them; some of them are even mentioned in the specs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tara (PassPack)</title>
		<link>http://notsorelevant.com/2007-04-04/trust-your-openid-provider/#comment-4148</link>
		<dc:creator>Tara (PassPack)</dc:creator>
		<pubDate>Mon, 09 Apr 2007 18:20:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsorelevant.com/2007-04-04/trust-your-openid-provider/#comment-4148</guid>
		<description>Cartes, 
You're abolsutely right.

Right now a bunch of services are popping up around OpenID, which is great news. But it's up to these services to build security layers on top of OpenID. OpenID alone isn't enough.

So yes, there will be (fierce) competition between IdPâ€™s. At least I hope so. Because OpenID has major security issues, phishing being the biggest, and it's up to the IdP's to solve those issues.

It'll be fun to watch how things start to shape up in the coming months.

Cheers,
Tara</description>
		<content:encoded><![CDATA[<p>Cartes,<br />
You&#8217;re abolsutely right.</p>
<p>Right now a bunch of services are popping up around OpenID, which is great news. But it&#8217;s up to these services to build security layers on top of OpenID. OpenID alone isn&#8217;t enough.</p>
<p>So yes, there will be (fierce) competition between IdPâ€™s. At least I hope so. Because OpenID has major security issues, phishing being the biggest, and it&#8217;s up to the IdP&#8217;s to solve those issues.</p>
<p>It&#8217;ll be fun to watch how things start to shape up in the coming months.</p>
<p>Cheers,<br />
Tara</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Boris Erdmann</title>
		<link>http://notsorelevant.com/2007-04-04/trust-your-openid-provider/#comment-4140</link>
		<dc:creator>Boris Erdmann</dc:creator>
		<pubDate>Sun, 08 Apr 2007 18:19:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsorelevant.com/2007-04-04/trust-your-openid-provider/#comment-4140</guid>
		<description>Thanks for listing us at magnolia :-)

Maybe you didn't know about us because we started the service
only recently on April 4th, 2007.

Cheers
   Boris</description>
		<content:encoded><![CDATA[<p>Thanks for listing us at magnolia <img src='http://notsorelevant.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /><br />
Maybe you didn&#8217;t know about us because we started the service<br />
only recently on April 4th, 2007.</p>
<p>Cheers<br />
   Boris</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Carsten PÃ¶tter</title>
		<link>http://notsorelevant.com/2007-04-04/trust-your-openid-provider/#comment-4133</link>
		<dc:creator>Carsten PÃ¶tter</dc:creator>
		<pubDate>Sat, 07 Apr 2007 18:21:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsorelevant.com/2007-04-04/trust-your-openid-provider/#comment-4133</guid>
		<description>Boris, first I just edited the link you provided for your comment on deltalima2's blog. Hope, that's ok.

Although big companies like AOL are adopting it, OpenID is still pretty unknown to most people. Also development of the specs is still in progress. So I am sure that there will be some more improvements on the security site of things (e.g. phishing) in the future. I actually think that users will register with those providers who will provide the best service in terms of security. There will be competition between IdP's.

I didn't know about Xlogon before. Good to know that there is another provider in Germany. :)

Carsten</description>
		<content:encoded><![CDATA[<p>Boris, first I just edited the link you provided for your comment on deltalima2&#8217;s blog. Hope, that&#8217;s ok.</p>
<p>Although big companies like AOL are adopting it, OpenID is still pretty unknown to most people. Also development of the specs is still in progress. So I am sure that there will be some more improvements on the security site of things (e.g. phishing) in the future. I actually think that users will register with those providers who will provide the best service in terms of security. There will be competition between IdP&#8217;s.</p>
<p>I didn&#8217;t know about Xlogon before. Good to know that there is another provider in Germany. <img src='http://notsorelevant.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
Carsten</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Boris Erdmann</title>
		<link>http://notsorelevant.com/2007-04-04/trust-your-openid-provider/#comment-4132</link>
		<dc:creator>Boris Erdmann</dc:creator>
		<pubDate>Sat, 07 Apr 2007 16:55:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsorelevant.com/2007-04-04/trust-your-openid-provider/#comment-4132</guid>
		<description>As we ourselves just started an OpenID Provider in Germany (because at tht time we decided to do so, could not find a provider for our customers who would legally protect them), I am fairly familiar with the implementation details.

And yes, as a provider you just have to have "knowledge" at least about which identity (URL) has a relationship with which consumer site. Without this you lose any of the benefits. In fact you would render the  whole thing unusable.

But on the other hand, that's it. And of course a matter trust.
You don't have to provide any other data.

So, go and look for providers, that just don't track anything. (We ourselves are not even technically prepared to. And since we don't collect that data, we just cannot evaluate them.) Look into their Terms and if that promise is written down there. In Germany customers are protected by such terms, the German TMG and DDSG.

Maybe you'll even find some, who implemented some other features to make users a little bit less visible.

In the meantime I can only second you in saying, that google will most probably know more about you at any time than your IdP ever will.

I just commented on that at
&lt;a href="http://www.deltalima2.de/internet-openid-die-zentrale-identitat-auf-dezentralen-servern-43.html"&gt;deltalima2&lt;/a&gt;

Boris</description>
		<content:encoded><![CDATA[<p>As we ourselves just started an OpenID Provider in Germany (because at tht time we decided to do so, could not find a provider for our customers who would legally protect them), I am fairly familiar with the implementation details.</p>
<p>And yes, as a provider you just have to have &#8220;knowledge&#8221; at least about which identity (URL) has a relationship with which consumer site. Without this you lose any of the benefits. In fact you would render the  whole thing unusable.</p>
<p>But on the other hand, that&#8217;s it. And of course a matter trust.<br />
You don&#8217;t have to provide any other data.</p>
<p>So, go and look for providers, that just don&#8217;t track anything. (We ourselves are not even technically prepared to. And since we don&#8217;t collect that data, we just cannot evaluate them.) Look into their Terms and if that promise is written down there. In Germany customers are protected by such terms, the German TMG and DDSG.</p>
<p>Maybe you&#8217;ll even find some, who implemented some other features to make users a little bit less visible.</p>
<p>In the meantime I can only second you in saying, that google will most probably know more about you at any time than your IdP ever will.</p>
<p>I just commented on that at<br />
<a href="http://www.deltalima2.de/internet-openid-die-zentrale-identitat-auf-dezentralen-servern-43.html">deltalima2</a></p>
<p>Boris</p>
]]></content:encoded>
	</item>
</channel>
</rss>
