4 ms·
I agree. To me, Webfinger+OpenID seems like a more sensible solution. At least in principle. The only downside is that OpenID lacks BrowserID's privacy bits.
by saljam 14y ago
I agree. To me, Webfinger+OpenID seems like a more sensible solution. At least in principle. The only downside is that OpenID lacks BrowserID's privacy bits.
http://code.google.com/p/webfinger/ http://code.google.com/p/webfinger/
- Gmo 14y ago> The only downside is that OpenID lacks BrowserID's privacy bits. Well, that's quite a major downside, don't you think ? Isn't one of the main purpose of persona/BrowserId a better respect of privacy ?
- drdaeman 14y agoI believe http://gpgauth.org/ http://gpgauth.org/ is better (except that it lacks strong community and PR from browser vendors). No need for per-site passwords (the only passwords are master password and, possibly, secret for key escrow). No need for any discovery and third parties, as you're identified by your own key, which contains a name (or nickname or whatever) — the most natural approach to identities (which has minor problem with nickname collisions, but that's about it). And, privacy-wise — no need to reveal email address if you don't want it, too. Edit/Add: WebID looks even more nice http://webid.info/ http://webid.info/, as it's actively developed by W3C WebID Community Group, while gpgAuth development is stalled and project seems dead.
- saljam 14y agoWow, I remember reading about foaf+ssl years ago. Glad to see it's still alive!