<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: hCard is not a provisioning engine (for private data)</title>
	<atom:link href="http://willnorris.com/2007/11/hcard-is-not-a-provisioning-engine-for-private-data/feed" rel="self" type="application/rss+xml" />
	<link>http://willnorris.com/2007/11/hcard-is-not-a-provisioning-engine-for-private-data</link>
	<description>managing identity</description>
	<pubDate>Wed, 08 Oct 2008 05:45:40 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Jason</title>
		<link>http://willnorris.com/2007/11/hcard-is-not-a-provisioning-engine-for-private-data#comment-14690</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Tue, 06 Nov 2007 23:51:52 +0000</pubDate>
		<guid isPermaLink="false">http://willnorris.com/2007/11/hcard-is-not-a-provisioning-engine-for-private-data#comment-14690</guid>
		<description>&lt;p&gt;Not to even mention that there are and will be some people who do not maintain a profile page, nor webpage of any kind, but would like to exchange attributes to RPs that request them.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Not to even mention that there are and will be some people who do not maintain a profile page, nor webpage of any kind, but would like to exchange attributes to RPs that request them.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: try { reuse; } catch (Ex) { reinvent; }</title>
		<link>http://willnorris.com/2007/11/hcard-is-not-a-provisioning-engine-for-private-data#comment-14665</link>
		<dc:creator>try { reuse; } catch (Ex) { reinvent; }</dc:creator>
		<pubDate>Tue, 06 Nov 2007 03:49:49 +0000</pubDate>
		<guid isPermaLink="false">http://willnorris.com/2007/11/hcard-is-not-a-provisioning-engine-for-private-data#comment-14665</guid>
		<description>&lt;p&gt;[...] willnorris.com managing identities   Skip to content AboutpgpProjectsWordPress YADIS/XRDS PluginWordPress OpenID PluginWordPress MicroID Pluginwp-xrdswpopenidArchives     &#171; hCard is not a provisioning engine (for private data) [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[&#8230;] willnorris.com managing identities   Skip to content AboutpgpProjectsWordPress YADIS/XRDS PluginWordPress OpenID PluginWordPress MicroID Pluginwp-xrdswpopenidArchives     &laquo; hCard is not a provisioning engine (for private data) [&#8230;]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Will Norris</title>
		<link>http://willnorris.com/2007/11/hcard-is-not-a-provisioning-engine-for-private-data#comment-14664</link>
		<dc:creator>Will Norris</dc:creator>
		<pubDate>Tue, 06 Nov 2007 02:50:55 +0000</pubDate>
		<guid isPermaLink="false">http://willnorris.com/2007/11/hcard-is-not-a-provisioning-engine-for-private-data#comment-14664</guid>
		<description>&lt;p&gt;agreed, it is much more likely that truly different personas would be represented by different OpenID URLs, but many providers support this concept today as I described it.&lt;/p&gt;

&lt;p&gt;The much more provocative use case is private data, and I really don't think shoe-horning hCard is the most appropriate or secure way of handling that.  Not only because of the technical question of how it would be done, but also because I am much more comfortable knowing that it can only occur &lt;em&gt;at the time I login&lt;/em&gt;, as is the case with SREG/AX (excepting that AX can perform subsequent updates of the data).&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>agreed, it is much more likely that truly different personas would be represented by different OpenID URLs, but many providers support this concept today as I described it.</p>
<p>The much more provocative use case is private data, and I really don&#8217;t think shoe-horning hCard is the most appropriate or secure way of handling that.  Not only because of the technical question of how it would be done, but also because I am much more comfortable knowing that it can only occur <em>at the time I login</em>, as is the case with SREG/AX (excepting that AX can perform subsequent updates of the data).</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Robinson</title>
		<link>http://willnorris.com/2007/11/hcard-is-not-a-provisioning-engine-for-private-data#comment-14663</link>
		<dc:creator>Scott Robinson</dc:creator>
		<pubDate>Tue, 06 Nov 2007 02:45:49 +0000</pubDate>
		<guid isPermaLink="false">http://willnorris.com/2007/11/hcard-is-not-a-provisioning-engine-for-private-data#comment-14663</guid>
		<description>&lt;p&gt;It seems very unlikely to me that you would use the same OpenID for exposures of identity. That's a single unique identifier that the other sites (as adversaries) can correlate with.&lt;/p&gt;

&lt;p&gt;Once you separate have separate OpenIDs, having separate hCards is a clear jump.&lt;/p&gt;

&lt;p&gt;So, no, I don't think this argument works.&lt;/p&gt;

&lt;p&gt;However, hCards are semi-public and certain that is an issue. If the hCard concept has the consumer accessing the same URL - then there must be a way to recognize the source and return customized information.&lt;/p&gt;

&lt;p&gt;And I haven't heard any talk of how that is supposed to occur.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>It seems very unlikely to me that you would use the same OpenID for exposures of identity. That&#8217;s a single unique identifier that the other sites (as adversaries) can correlate with.</p>
<p>Once you separate have separate OpenIDs, having separate hCards is a clear jump.</p>
<p>So, no, I don&#8217;t think this argument works.</p>
<p>However, hCards are semi-public and certain that is an issue. If the hCard concept has the consumer accessing the same URL - then there must be a way to recognize the source and return customized information.</p>
<p>And I haven&#8217;t heard any talk of how that is supposed to occur.</p>]]></content:encoded>
	</item>
</channel>
</rss>
