<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Blog posting delegation and third-party auth</title>
	<atom:link href="http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth/feed" rel="self" type="application/rss+xml" />
	<link>http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth</link>
	<description>It's all spinning wheels and self-doubt until the first pot of coffee.</description>
	<pubDate>Sat, 30 Aug 2008 00:08:51 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7-hemorrhage</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Geekularity &#187; Can OpenID be used for API Authentication?</title>
		<link>http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-126585</link>
		<dc:creator>Geekularity &#187; Can OpenID be used for API Authentication?</dc:creator>
		<pubDate>Mon, 09 Apr 2007 19:19:47 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-126585</guid>
		<description>&lt;p&gt;[...] Orchard has an open discussion about using OpenID in a blog comment [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] Orchard has an open discussion about using OpenID in a blog comment [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ian McKellar</title>
		<link>http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-100028</link>
		<dc:creator>Ian McKellar</dc:creator>
		<pubDate>Mon, 12 Mar 2007 19:26:16 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-100028</guid>
		<description>&lt;p&gt;@l.m.orchard: in my experience the problems are with the formatting of the content (do blank lines turn into paragraphs, etc) and fragile post IDs (the upgraded wordpress and spammed all my friends on livejournal or planet problem). I'm not sure how to fix either of these problems but I think they're both problems Atom is attempting to solve...&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@l.m.orchard: in my experience the problems are with the formatting of the content (do blank lines turn into paragraphs, etc) and fragile post IDs (the upgraded wordpress and spammed all my friends on livejournal or planet problem). I'm not sure how to fix either of these problems but I think they're both problems Atom is attempting to solve...</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: l.m.orchard</title>
		<link>http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-100009</link>
		<dc:creator>l.m.orchard</dc:creator>
		<pubDate>Mon, 12 Mar 2007 19:01:45 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-100009</guid>
		<description>&lt;p&gt;@ian: Hmm, yeah, that does sound like the least complicated way to get outside content pulled into a blog without releasing the blog's login details.  I know I've seen / used some WordPress plugins that do  basically that, though I've not been happy with any of them yet.  I should re-look into why that's been the case&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@ian: Hmm, yeah, that does sound like the least complicated way to get outside content pulled into a blog without releasing the blog's login details.  I know I've seen / used some WordPress plugins that do  basically that, though I've not been happy with any of them yet.  I should re-look into why that's been the case</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ian McKellar</title>
		<link>http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-99999</link>
		<dc:creator>Ian McKellar</dc:creator>
		<pubDate>Mon, 12 Mar 2007 18:44:46 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-99999</guid>
		<description>&lt;p&gt;@l.m.orchard: you don't need to just aggregate you can also import posts into your own store. We could come up with a cleverly confusing buzzword acronym like Atom Pull Publishing. You just periodically poll a feed and import the items. Actually, this is kind of what Google Reader is doing. They've even got a namespace in their atom for expressing the original id and the source feed. Perhaps I should write a drupal module.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@l.m.orchard: you don't need to just aggregate you can also import posts into your own store. We could come up with a cleverly confusing buzzword acronym like Atom Pull Publishing. You just periodically poll a feed and import the items. Actually, this is kind of what Google Reader is doing. They've even got a namespace in their atom for expressing the original id and the source feed. Perhaps I should write a drupal module.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: l.m.orchard</title>
		<link>http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-99966</link>
		<dc:creator>l.m.orchard</dc:creator>
		<pubDate>Mon, 12 Mar 2007 17:58:35 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-99966</guid>
		<description>&lt;p&gt;@ian: Hmm, yeah, that probably does end up being the least onerous solution - just offer an aggregated feed of one's output.  I do like the idea of auto-posting to a blog, though, for the sake of something sorta like daily backups to a system I control.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@ian: Hmm, yeah, that probably does end up being the least onerous solution - just offer an aggregated feed of one's output.  I do like the idea of auto-posting to a blog, though, for the sake of something sorta like daily backups to a system I control.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ian McKellar</title>
		<link>http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-99958</link>
		<dc:creator>Ian McKellar</dc:creator>
		<pubDate>Mon, 12 Mar 2007 17:43:49 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-99958</guid>
		<description>&lt;p&gt;It seems to me that the ideal solution to this is to have your blog pull new posts from an RSS/Atom feed that's hosted by the service that is generating your content. Feedburner already has a half-assed implementation of this where they'll pull your delicious bookmarks and flickr photos into your burned feed.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>It seems to me that the ideal solution to this is to have your blog pull new posts from an RSS/Atom feed that's hosted by the service that is generating your content. Feedburner already has a half-assed implementation of this where they'll pull your delicious bookmarks and flickr photos into your burned feed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: l.m.orchard</title>
		<link>http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-95247</link>
		<dc:creator>l.m.orchard</dc:creator>
		<pubDate>Tue, 06 Mar 2007 18:04:57 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-95247</guid>
		<description>&lt;p&gt;Yeah, I figured making multiple accounts is a way to go when you've got your own install of something like WordPress.  It kind of gets stymied, though, if you want the same thing for a hosted service like WordPress.com, Vox, TypePad, or LiveJournal where one account = one blog.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Yeah, I figured making multiple accounts is a way to go when you've got your own install of something like WordPress.  It kind of gets stymied, though, if you want the same thing for a hosted service like WordPress.com, Vox, TypePad, or LiveJournal where one account = one blog.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: George Hotelling</title>
		<link>http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-95241</link>
		<dc:creator>George Hotelling</dc:creator>
		<pubDate>Tue, 06 Mar 2007 17:51:55 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-95241</guid>
		<description>&lt;p&gt;At first I had this great idea to build a blog posting proxy service that could grant access to your blog to different services by giving them different usernames and passwords and you could revoke them at any time and it would be great and everyone would be posting to everyone's blog all the time.&lt;/p&gt;

&lt;p&gt;Then I realized I had put on &lt;a href="http://worsethanfailure.com/Articles/The_Complicator's_Gloves.aspx" rel="nofollow"&gt;complicator gloves&lt;/a&gt; and that it would be way easier to just add new users to my blog without a proxy service.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>At first I had this great idea to build a blog posting proxy service that could grant access to your blog to different services by giving them different usernames and passwords and you could revoke them at any time and it would be great and everyone would be posting to everyone's blog all the time.</p>
<p>Then I realized I had put on <a href="http://worsethanfailure.com/Articles/The_Complicator's_Gloves.aspx" rel="nofollow">complicator gloves</a> and that it would be way easier to just add new users to my blog without a proxy service.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kim Cameron&#8217;s Identity Weblog &#187; Blog posting delegation and third-party auth</title>
		<link>http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-94847</link>
		<dc:creator>Kim Cameron&#8217;s Identity Weblog &#187; Blog posting delegation and third-party auth</dc:creator>
		<pubDate>Tue, 06 Mar 2007 02:22:29 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-94847</guid>
		<description>&lt;p&gt;[...] at 0xDECAFBAD (&#8230;t’s all spinning wheels and self-doubt until the first pot of coffee) expands on the idea [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] at 0xDECAFBAD (&#8230;t’s all spinning wheels and self-doubt until the first pot of coffee) expands on the idea [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: l.m.orchard</title>
		<link>http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-94764</link>
		<dc:creator>l.m.orchard</dc:creator>
		<pubDate>Mon, 05 Mar 2007 22:48:24 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-94764</guid>
		<description>&lt;p&gt;Not really, unless I don't entirely understand OpenID.  &lt;/p&gt;

&lt;p&gt;OpenID offers way to authenticate &lt;em&gt;yourself&lt;/em&gt;.  However, what I want is an easy way to delegate your access to 3rd party apps, without those apps being able to authenticate as you or performs actions outside of the permissions you approve.  I don't really want Flickr Uploader, Ecto, MarsEdit to be able to use OpenID to login as me with carte blanche.&lt;/p&gt;

&lt;p&gt;With a token-based system like Flickr has, I can approve delegation to various apps and revoke their access at any time - without ever releasing my login details.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Not really, unless I don't entirely understand OpenID.  </p>
<p>OpenID offers way to authenticate <em>yourself</em>.  However, what I want is an easy way to delegate your access to 3rd party apps, without those apps being able to authenticate as you or performs actions outside of the permissions you approve.  I don't really want Flickr Uploader, Ecto, MarsEdit to be able to use OpenID to login as me with carte blanche.</p>
<p>With a token-based system like Flickr has, I can approve delegation to various apps and revoke their access at any time - without ever releasing my login details.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fluffy</title>
		<link>http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-94759</link>
		<dc:creator>fluffy</dc:creator>
		<pubDate>Mon, 05 Mar 2007 22:40:26 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/2007/03/05/blog-posting-delegation-and-third-party-auth#comment-94759</guid>
		<description>&lt;p&gt;Wouldn't openID be a better candidate for this?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Wouldn't openID be a better candidate for this?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
