Blog URI, is it necessary?

Ben Hyde bhyde at pobox.com
Mon Jun 6 11:11:14 PDT 2005


We didn't bring this discussion to closure.  It just peter'd out.    So 
I will close it:  don't do it.

The idea was to allow the ID server to participate in the 
cannibalization process.   So if you entered livejournal.com the ID 
server might return alice.livejournal.com.  This has a lot of nice 
features (usability, privacy, functional).  But it also has a serious 
privacy flaw, as Martin pointed out.  For example if alice visits mr. 
evil anonymously he can, without her permission, attempt to 
authenticator at livejournal.com and his reward is suddenly he knows 
that this anonymous visitor is alice.  Bleck.

     - ben

----
http://enthusiasm.cozy.org   http://gibbon.cozy.org   
tel:+1-781-240-2221
  I forecast sunny weather!



More information about the yadis mailing list