Re: Webapp OpenID Login Filter
Andrew Jaquith <[email protected]> Mon, 27 Aug 2007 01:01:33 -0400
| Newsgroups | gmane.comp.java.jspwiki.user |
|---|---|
| Message-ID | <[email protected]> |
Jack -- I agree that the MITM issues are over-stated, considering that OpenID isn't used for high-value transactions. Fortunately the Powers That Be in the OpenID community are well aware of them and are trying to fix 'em. That means there will be some flux in the spec -- hence my question about which version you supported. And yes, I suppose the 'sent from my iPhone' thing is a little showy. But I am lazy, and have not changed the default footer. Andrew (Cough cough: sent from my MacBook Pro...) On Aug 26, 2007, at 11:10 AM, Jack wrote: > Andrew Jaquith wrote: >> Jack - thanks for the excellent initiative. As the resident security >> guy for JSPWiki and a part-time member of the Identity Gang, I have >> been looking at OpenID for a while. It has some issues (notably a >> susceptibility to man-in-the middle attacks) but overall the benefits >> strongly outweigh the risks. >> OpenID us very interesting for us. I will take a careful look at what >> you've done (likely in the next month or so); perhaps we can include >> this in JSPWiki 3. >> Nice work. What version of OpenID does your library support, by the >> way? > > Hey, thanks for your interest - I'm flattered to have got a reply from > you (I know who you are in JSPWiki). > > BTW: it's not really a library - it's a ready-to-go servlet + filter > combo. A library would have an API. > > As far as incorporating it in JSPWiki 3.0: there's nothing to be done. > You could drop it into any web-app, as long as that web-app isn't > committed to an incompatible authentication system. If you wanted to > just package it, then that would be a matter of including the jar, a > login form, and some commented-out sections in web.xml. > > This code supports OpenID version 2.0, which implies support for > OpenID > 1.1 - it's a requirement of the 2.0 spec. OpenID 1.1 is really just > the > same as OpenID "1.0", except that there's no such thing - the first > version of OpenID didn't have a version number. The difference between > versions 1.0 and 1.1 is therefore that version 1.1 knows what > version it > is (i.e. it's possible to signify compliance with 1.1, but not with > 1.0). > > I'm no evangelist; I don't have a mission to sell OpenID, or anything > like that. This is something that I was writing for another app, > and it > turned out to be detachable, so I have detached it. > > The man-in-the-middle problem is getting a lot of airtime. I think the > MITM issue would be an issue, if OpenID were useable for stuff like > financial transactions. But all that OpenID can say about someone is > that they are the same user as user X (who shares the same userID). > Any > of the registration assertions about an OpenID user are effectively > self-certified, and therefore are only useful if you know who the user > is through some other channel, and trust their claims. I guess that in > principle, a bank could rely on OpenID provided by a third party; but > consider (for example) that Indian OpenID provider, which will > authenticate any OpenID userid without requiring credentials. > > I'm still trying to figure out what the strengths and weakenesses of > OpenID are. I think most of the dissing commentators are going for the > low-hanging fruit (MITM, Phishing), and missing the big problems > (who is > this dude, actually - like, who really is mrdemeanour.myopenid.com; > and > why should I trust provider X). > > MITM can crop up wherever a password (or other sensitive info) has > to be > typed into a webpage. It can be defeated only by the user ascertaining > that the party they are sending their data to is who it's supposed to > be. There are ways to make that more intuitive (like browser plugins), > but in the end it comes down to users paying attention. It's certainly > not a problem that OpenID has created; but it's also true that OpenID > doesn't solve it. > > >> Andrew >> Sent from my iPhone > > Oh, bragging are we? AFAIAA, those things aren't even available > here yet :-) > > -- > Jack. > _______________________________________________ > This is the Jspwiki-users mailing list, in which we discuss the > stable release (even-numbered, 2.4.x, 2.6.x), and user-issues. For > development discussion, please join jspwiki-dev. > http://ecyrd.com/cgi-bin/mailman/listinfo/jspwiki-users > http://www.jspwiki.org/JSPWikiMailingList