<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule"
	>
<channel>
	<title>Comments on: Directed Identity vs Identifier Select</title>
	<atom:link href="http://willnorris.com/2009/07/openid-directed-identity-identifier-select/feed" rel="self" type="application/rss+xml" />
	<link>http://willnorris.com/2009/07/openid-directed-identity-identifier-select</link>
	<description>there&#039;s more to life than this</description>
	<lastBuildDate>Sun, 31 Jul 2011 08:06:56 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4-beta3-20574</generator>
	<item>
		<title>By: Ronald Widha &#187; Blog Archive &#187; Why Facebook linked accounts doesn&#8217;t work with my OpenID provider</title>
		<link>http://willnorris.com/2009/07/openid-directed-identity-identifier-select#comment-48213</link>
		<dc:creator>Ronald Widha &#187; Blog Archive &#187; Why Facebook linked accounts doesn&#8217;t work with my OpenID provider</dc:creator>
		<pubDate>Fri, 08 Oct 2010 19:09:22 +0000</pubDate>
		<guid isPermaLink="false">http://willnorris.com/?p=797#comment-48213</guid>
		<description>&lt;p&gt;[...] If you’re interested to learn what identifier select, check out Directed Identity vs Identifier Select. [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[&#8230;] If you’re interested to learn what identifier select, check out Directed Identity vs Identifier Select. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Best Practices with Directed Identity &#8212; Will Norris</title>
		<link>http://willnorris.com/2009/07/openid-directed-identity-identifier-select#comment-32834</link>
		<dc:creator>Best Practices with Directed Identity &#8212; Will Norris</dc:creator>
		<pubDate>Mon, 03 Aug 2009 03:48:35 +0000</pubDate>
		<guid isPermaLink="false">http://willnorris.com/?p=797#comment-32834</guid>
		<description>&lt;p&gt;[...] Will Norris Thoughts on Identity, OpenID, WordPress, and Life   Skip to content BlogAboutProjectsArchives       &#171; Directed Identity vs Identifier Select [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[&#8230;] Will Norris Thoughts on Identity, OpenID, WordPress, and Life   Skip to content BlogAboutProjectsArchives       &laquo; Directed Identity vs Identifier Select [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aswath Rao</title>
		<link>http://willnorris.com/2009/07/openid-directed-identity-identifier-select#comment-32809</link>
		<dc:creator>Aswath Rao</dc:creator>
		<pubDate>Sun, 02 Aug 2009 01:41:17 +0000</pubDate>
		<guid isPermaLink="false">http://willnorris.com/?p=797#comment-32809</guid>
		<description>&lt;p&gt;@Will, yes it would be ironic if I had meant :identifier select&quot;, but stated &quot;directed identity. But I did not as the followup comment by @John suggests. You should give more credit to yourself that your lengthy explanation will make its point.&lt;/p&gt;

&lt;p&gt;@John, I am afraid that you are right in your prediction regarding large OPs. Well meaning efforts to improve UX with &quot;NASCAR style buttons&quot; favoring large OPs stacks the deck against some of the fundamental aspects of OpenID that attracted me in the first place.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@Will, yes it would be ironic if I had meant :identifier select&#8221;, but stated &#8220;directed identity. But I did not as the followup comment by @John suggests. You should give more credit to yourself that your lengthy explanation will make its point.</p>

<p>@John, I am afraid that you are right in your prediction regarding large OPs. Well meaning efforts to improve UX with &#8220;NASCAR style buttons&#8221; favoring large OPs stacks the deck against some of the fundamental aspects of OpenID that attracted me in the first place.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Bradley</title>
		<link>http://willnorris.com/2009/07/openid-directed-identity-identifier-select#comment-32805</link>
		<dc:creator>John Bradley</dc:creator>
		<pubDate>Sat, 01 Aug 2009 20:08:35 +0000</pubDate>
		<guid isPermaLink="false">http://willnorris.com/?p=797#comment-32805</guid>
		<description>&lt;p&gt;Delegation only half supports multiple personas.&lt;/p&gt;

&lt;p&gt;It makes it slightly harder for people to correlate but it doesn&#039;t stop correlation.   That was never part of the delegation use case.&lt;/p&gt;

&lt;p&gt;To avoid correlation you need totally separate openIDs or better pairwise identifiers as Will has described.&lt;/p&gt;

&lt;p&gt;Delegation supports some measure of OP independence if you control your URI.   It also allows for a measure of OP redundancy/fault tolerance at RP&#039;s that properly support XRDS.&lt;/p&gt;

&lt;p&gt;I suspect delegation will become a smaller percentage of logins as the large OPs start taking more of the market.   I would be happy to be wrong about that.&lt;/p&gt;

&lt;p&gt;John B.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Delegation only half supports multiple personas.</p>

<p>It makes it slightly harder for people to correlate but it doesn&#8217;t stop correlation.   That was never part of the delegation use case.</p>

<p>To avoid correlation you need totally separate openIDs or better pairwise identifiers as Will has described.</p>

<p>Delegation supports some measure of OP independence if you control your URI.   It also allows for a measure of OP redundancy/fault tolerance at RP&#8217;s that properly support XRDS.</p>

<p>I suspect delegation will become a smaller percentage of logins as the large OPs start taking more of the market.   I would be happy to be wrong about that.</p>

<p>John B.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will Norris</title>
		<link>http://willnorris.com/2009/07/openid-directed-identity-identifier-select#comment-32804</link>
		<dc:creator>Will Norris</dc:creator>
		<pubDate>Sat, 01 Aug 2009 19:51:59 +0000</pubDate>
		<guid isPermaLink="false">http://willnorris.com/?p=797#comment-32804</guid>
		<description>&lt;p&gt;@Aswath: I&#039;m not sure I entirely follow your point.  First of all, I&#039;m pretty sure you mean &quot;identifier select&quot; when you are saying &quot;directed identity&quot; (ironic, given the whole point of this post -- to clarify the difference).  MyVidoop has never implemented directed identity. It does however support &quot;identifier select&quot;, enabling users to just enter &quot;myvidoop.com&quot; in an OpenID field rather than their full OpenID URL.&lt;/p&gt;

&lt;p&gt;You mention using delegation to address your desire for multiple personas.  Sure, that can certainly work... you could maintain multiple OpenIDs that each delegate to an OpenID provider, perhaps different ones.  Delegation is outside the scope of this article however, since my goal was to differentiate between &quot;directed identity&quot; and &quot;identifier select&quot;.  It is worth noting, however, that delegation is not possible with identifier select... perhaps a good topic for another post.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@Aswath: I&#8217;m not sure I entirely follow your point.  First of all, I&#8217;m pretty sure you mean &#8220;identifier select&#8221; when you are saying &#8220;directed identity&#8221; (ironic, given the whole point of this post &#8212; to clarify the difference).  MyVidoop has never implemented directed identity. It does however support &#8220;identifier select&#8221;, enabling users to just enter &#8220;myvidoop.com&#8221; in an OpenID field rather than their full OpenID URL.</p>

<p>You mention using delegation to address your desire for multiple personas.  Sure, that can certainly work&#8230; you could maintain multiple OpenIDs that each delegate to an OpenID provider, perhaps different ones.  Delegation is outside the scope of this article however, since my goal was to differentiate between &#8220;directed identity&#8221; and &#8220;identifier select&#8221;.  It is worth noting, however, that delegation is not possible with identifier select&#8230; perhaps a good topic for another post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aswath Rao</title>
		<link>http://willnorris.com/2009/07/openid-directed-identity-identifier-select#comment-32801</link>
		<dc:creator>Aswath Rao</dc:creator>
		<pubDate>Sat, 01 Aug 2009 14:58:55 +0000</pubDate>
		<guid isPermaLink="false">http://willnorris.com/?p=797#comment-32801</guid>
		<description>&lt;p&gt;Directed Identity is useful in cases where I would like to maintain different persona. But I am still bound to a single OP. As we saw from the case of myVidoop, that is not safe. That is why I prefer delegation. Once I do that, I can create different OpenIDs easily on my own, without the need of directed identity.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Directed Identity is useful in cases where I would like to maintain different persona. But I am still bound to a single OP. As we saw from the case of myVidoop, that is not safe. That is why I prefer delegation. Once I do that, I can create different OpenIDs easily on my own, without the need of directed identity.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will Norris</title>
		<link>http://willnorris.com/2009/07/openid-directed-identity-identifier-select#comment-32790</link>
		<dc:creator>Will Norris</dc:creator>
		<pubDate>Fri, 31 Jul 2009 17:15:28 +0000</pubDate>
		<guid isPermaLink="false">http://willnorris.com/?p=797#comment-32790</guid>
		<description>&lt;p&gt;test comment with Yahoo!&lt;/p&gt;

&lt;p&gt;OpenID should be working now... seems the good folks at Joyent decided it would be a good idea to remove curl&#039;s ca cert bundle all together.  I had actually noticed this a few weeks ago, just forgot to fix it with the WordPress plugin.  Should hopefully be okay now.&lt;/p&gt;

&lt;p&gt;&lt;b&gt;edit:&lt;/b&gt; well, it worked with MyOpenID... guess there&#039;s still something wrong with Yahoo!.  I&#039;ll get it sorted out.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>test comment with Yahoo!</p>

<p>OpenID should be working now&#8230; seems the good folks at Joyent decided it would be a good idea to remove curl&#8217;s ca cert bundle all together.  I had actually noticed this a few weeks ago, just forgot to fix it with the WordPress plugin.  Should hopefully be okay now.</p>

<p><b>edit:</b> well, it worked with MyOpenID&#8230; guess there&#8217;s still something wrong with Yahoo!.  I&#8217;ll get it sorted out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Bradley</title>
		<link>http://willnorris.com/2009/07/openid-directed-identity-identifier-select#comment-32787</link>
		<dc:creator>John Bradley</dc:creator>
		<pubDate>Fri, 31 Jul 2009 16:42:41 +0000</pubDate>
		<guid isPermaLink="false">http://willnorris.com/?p=797#comment-32787</guid>
		<description>&lt;p&gt;I cant find an openID that is working on your blog.  Yahoo , =jbradley, and http://thread-safe.com.&lt;/p&gt;

&lt;p&gt;I expect many of the large OPs to be supporting Pairwise identifiers in the September timeframe.&lt;/p&gt;

&lt;p&gt;Good post.&lt;/p&gt;

&lt;p&gt;John B.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I cant find an openID that is working on your blog.  Yahoo , =jbradley, and <a href="http://thread-safe.com" rel="nofollow">http://thread-safe.com</a>.</p>

<p>I expect many of the large OPs to be supporting Pairwise identifiers in the September timeframe.</p>

<p>Good post.</p>

<p>John B.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew Arnott</title>
		<link>http://willnorris.com/2009/07/openid-directed-identity-identifier-select#comment-32785</link>
		<dc:creator>Andrew Arnott</dc:creator>
		<pubDate>Fri, 31 Jul 2009 15:43:18 +0000</pubDate>
		<guid isPermaLink="false">http://willnorris.com/?p=797#comment-32785</guid>
		<description>&lt;p&gt;Oh, and by the way, your OpenID RP for comment posting is broken. ;)  Try posting a comment with http://blog.nerdbank.net/ yourself, you&#039;ll see an error from myopenid.com because the request is incorrect. (no, it&#039;s not a bug in my XRDS doc).&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Oh, and by the way, your OpenID RP for comment posting is broken. ;)  Try posting a comment with <a href="http://blog.nerdbank.net/" rel="nofollow">http://blog.nerdbank.net/</a> yourself, you&#8217;ll see an error from myopenid.com because the request is incorrect. (no, it&#8217;s not a bug in my XRDS doc).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew Arnott</title>
		<link>http://willnorris.com/2009/07/openid-directed-identity-identifier-select#comment-32784</link>
		<dc:creator>Andrew Arnott</dc:creator>
		<pubDate>Fri, 31 Jul 2009 15:42:24 +0000</pubDate>
		<guid isPermaLink="false">http://willnorris.com/?p=797#comment-32784</guid>
		<description>&lt;p&gt;Great post.  Thanks for clarifying these two points.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Great post.  Thanks for clarifying these two points.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

