<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: More Secure OpenID</title>
	<atom:link href="http://www.mandladventures.com/2008/01/03/more-secure-openid/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mandladventures.com/2008/01/03/more-secure-openid/</link>
	<description>Leading you on the technical adventure</description>
	<pubDate>Tue, 06 Jan 2009 10:11:20 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: steve pepple</title>
		<link>http://www.mandladventures.com/2008/01/03/more-secure-openid/comment-page-1/#comment-24352</link>
		<dc:creator>steve pepple</dc:creator>
		<pubDate>Wed, 13 Feb 2008 19:29:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.mandladventures.com/2008/01/03/more-secure-openid/#comment-24352</guid>
		<description>The team I work with is developing a beta implementation of strong, multi-factor authentication for OpenID, 
&lt;a href="http://openid.trustbearer.com" rel="nofollow"&gt;TrustBearer OpenID&lt;/a&gt;. 

We've found that this infinitely decreases the possibility of someone fraudulently accessing another persons' account. We've found some compelling ways to thwart phishing here, as well. We use a web browser add-on to manage the authentication process, and we can actually check the validity of sites here. A user's private data also remain private during the exchange of keys during authetication.

We've been concentrating on simple user experience at this point, 
and we are interested to learn what sort of features user will look 
for in this type of implementation.

With our OpenID, you basically just set-up a strong authentication device 
and then link the device to your OpenID URL.</description>
		<content:encoded><![CDATA[<p>The team I work with is developing a beta implementation of strong, multi-factor authentication for OpenID,<br />
<a href="http://openid.trustbearer.com" rel="nofollow">TrustBearer OpenID</a>. </p>
<p>We&#8217;ve found that this infinitely decreases the possibility of someone fraudulently accessing another persons&#8217; account. We&#8217;ve found some compelling ways to thwart phishing here, as well. We use a web browser add-on to manage the authentication process, and we can actually check the validity of sites here. A user&#8217;s private data also remain private during the exchange of keys during authetication.</p>
<p>We&#8217;ve been concentrating on simple user experience at this point,<br />
and we are interested to learn what sort of features user will look<br />
for in this type of implementation.</p>
<p>With our OpenID, you basically just set-up a strong authentication device<br />
and then link the device to your OpenID URL.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.mandladventures.com/2008/01/03/more-secure-openid/comment-page-1/#comment-22067</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Sat, 19 Jan 2008 04:49:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.mandladventures.com/2008/01/03/more-secure-openid/#comment-22067</guid>
		<description>Thanks for the links Luke. Hadn't seen that particular solution before.</description>
		<content:encoded><![CDATA[<p>Thanks for the links Luke. Hadn&#8217;t seen that particular solution before.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luke</title>
		<link>http://www.mandladventures.com/2008/01/03/more-secure-openid/comment-page-1/#comment-21139</link>
		<dc:creator>Luke</dc:creator>
		<pubDate>Sun, 06 Jan 2008 23:38:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.mandladventures.com/2008/01/03/more-secure-openid/#comment-21139</guid>
		<description>Matt,

Relating to security and OpenID, the following thoughts might interest you:

http://blog.vidoop.com/archives/26

http://blog.vidoop.com/archives/33

-Luke</description>
		<content:encoded><![CDATA[<p>Matt,</p>
<p>Relating to security and OpenID, the following thoughts might interest you:</p>
<p><a href="http://blog.vidoop.com/archives/26" rel="nofollow">http://blog.vidoop.com/archives/26</a></p>
<p><a href="http://blog.vidoop.com/archives/33" rel="nofollow">http://blog.vidoop.com/archives/33</a></p>
<p>-Luke</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.mandladventures.com/2008/01/03/more-secure-openid/comment-page-1/#comment-21058</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Sat, 05 Jan 2008 18:36:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.mandladventures.com/2008/01/03/more-secure-openid/#comment-21058</guid>
		<description>Thanks for the comment Aswath. What you described is a good and easy way to avoid OpenID phishing attempts. Thanks for sharing your knowledge.</description>
		<content:encoded><![CDATA[<p>Thanks for the comment Aswath. What you described is a good and easy way to avoid OpenID phishing attempts. Thanks for sharing your knowledge.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aswath</title>
		<link>http://www.mandladventures.com/2008/01/03/more-secure-openid/comment-page-1/#comment-21056</link>
		<dc:creator>Aswath</dc:creator>
		<pubDate>Sat, 05 Jan 2008 16:54:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.mandladventures.com/2008/01/03/more-secure-openid/#comment-21056</guid>
		<description>One way to avoid phishing attempts is to use the tab feature available in many browsers. Before using OpenID in a site, open a new tab, log into your OpenID provider and leave the tab open. Then you can use OpenID from any other tab in the same window. A conforming site will not redirect you to your provider's login screen. This eliminates any phishing opportunity.</description>
		<content:encoded><![CDATA[<p>One way to avoid phishing attempts is to use the tab feature available in many browsers. Before using OpenID in a site, open a new tab, log into your OpenID provider and leave the tab open. Then you can use OpenID from any other tab in the same window. A conforming site will not redirect you to your provider&#8217;s login screen. This eliminates any phishing opportunity.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
