Core Identity Issuers (Part II)
Continuing from the previous post (Part I of the Core Identity series), the goal of a Core Identity Issuer (CoreID Issuer) is to collate sufficient data – aggregate data and non-PII data — from members...
View ArticleUMA Presentation from IIW#16
Eve Maler kindly prepared an excellent set of slides for me to present at IIW#16 in Mountain View, CA late April: UMA_for_IIW16_2013-05 After discussions during the presentation, I believe one of the...
View ArticleLimitations of the OAuth 2.0 definition of “Client”
I believe the OAuth 2.0 definition of the “client” is too restrictive, and by doing so it has effectively closed-off any possibility of OAuth 2.0 entertaining true third party access on the Internet....
View ArticleEran bails out of the OAuth2.0 Spec
So the news this week was that Eran has decided that OAuth2.0 is a bad specification and wants nothing to do with it. Its kinda a bit too late to complain about OAuth2.0. Its out there, its being...
View ArticleUMA, OpenID-Connect & OAuth2.0
Eve Maler has devised a very useful diagram (for our Google techTalk presentation), comparing the features and intended purposes of OAuth2.0, OpenID-Connect and UMA. Interestingly, the diagram also...
View Article