Skip to content

{ Category Archives } Identity and Privacy

Sun’s OpenID IdP: Summary

I’ve now fin­ished my cur­rent batch of post­ings about Sun’s OpenID IdP. Here’s a list­ing of the rel­ev­ant post­ings that the team has made. I’ll add new post­ings to this list as they’re pub­lished, or as I find them. Pur­pose and Policies my Sun’s OpenID IdP: Intro­duc­tion my Sun’s OpenID IdP: Busi­ness Pur­pose my Sun’s OpenID […]

Tagged ,

Sun’s OpenID IdP: Trust

Part of a series on Sun’s OpenID@Work ini­ti­at­ive; see the intro­duc­tion for more con­text. Trust is always an issue on the web. People don’t usu­ally even think about it, but they trust the DNS server to point their browser at the right web site when they click on a link, they trust the web server […]

Tagged ,

Sun’s OpenID IdP: Real vs Fake

Part of a series on Sun’s OpenID@Work ini­ti­at­ive; see the intro­duc­tion for more con­text. Prob­ably the biggest dis­cus­sion we had in the entire policy dis­cus­sion was whether to let Sun employ­ees use fake or fic­ti­tious names, or whether to force the use of real names in what the OpenID simple regis­tra­tion exten­sion calls the fullname. […]

Tagged ,

Sun’s OpenID IdP: Data Governance

Part of a series on Sun’s OpenID@Work ini­ti­at­ive; see the intro­duc­tion for more con­text. Data gov­ernance is the term used for know­ing what hap­pens to the data that is stored, par­tic­u­larly when that data has any PII (per­son­ally iden­ti­fi­able inform­a­tion), which the OpenID IdP does. Using OpenID isn’t the reason we keep this inform­a­tion; any […]

Tagged ,

Facebook Apps and Profiles

So I’m not really into the Face­book thing, but occa­sion­ally I hop on and see what people are up to. I’ve noticed a few of my friends have some inter­est­ing look­ing apps on their pro­file pages, and figured I might try some of them out. Except for, every single one I’ve looked at so far […]

Sun’s OpenID IdP: Business Purpose

Part of a series on Sun’s OpenID@Work ini­ti­at­ive; see the intro­duc­tion for more con­text. One of the inter­est­ing things about secur­ity is that you can never make any­thing 100% secure. You need to fig­ure out what the risks are, how likely they are to occur, and what the dam­age will be if some­thing bad does […]

Tagged ,