10 ms·
OpenID has been on its way out for a while. It's being replaced by OpenID Connect [1] so this is not bad news, but a good reminder in any case! [1] http://open
by teh 12y ago
OpenID has been on its way out for a while. It's being replaced by OpenID Connect [1] so this is not bad news, but a good reminder in any case!
[1]
http://openid.net/connect/ http://openid.net/connect/
- nailer 12y agoPractically, openID is being replaced by oauth. A decade ago authentication and authorisation were quite separate concepts. This has been replaced with a realisation that 'being authorised to use a particular account' (Google Account, Twitter, FB, etc) is sufficient to prove ownership of that account and therefore identity.
- Tobu 12y agoOpenID Connect is based on OAuth.
- nailer 12y agoOK. What else does OpenID Connect get me, vs asking for a limited-scope oauth?
- bvirkler 12y agoBasically, OpenID Connect is for federated authentication, and OAuth2 is for delegated authorization. I like Vitorrio's explanation: http://www.cloudidentity.com/blog/2013/01/02/oauth-2-0-and-sign-in-4/ http://www.cloudidentity.com/blog/2013/01/02/oauth-2-0-and-s...
- soapdog 12y agoEven though its community maintained these days, Mozilla Persona was a great authentication mechanism with federation support. I loved using it. A pity it failed to get traction.
- nly 12y agoThis gives me the creeps. Authorisation and identification are not the same. If you use 'Login with X' you're giving X access to all your accounts. That's not just third party attestation of your identity. It's kind of like saying a passport is what gives you access to your home country... in reality your status as a citizen is what gives you that right, the passport is merely a convenience.
- cheald 12y agoAuthorization of a null permission is effectively the same as authentication, though. I think the GP's point was that authz implies authn, even if the set of permissioned authz'd for is empty.
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- nailer 12y agoEdit: see reply below, I think I misunderstood the parent post. > If you use 'Login with X' you're giving X access to all your accounts. That's definitely not correct. You are giving X to access only whatever scopes you allowed, on a single account. Here's an example of just 'userinfo'. Click this and see what it asks for: https://accounts.google.com/AccountChooser?service=lso&continue=https%3A%2F%2Faccounts.google.com%2Fo%2Foauth2%2Fauth%3Fscope%3Dhttps%3A%2F%2Fwww.googleapis.com%2Fauth%2Fuserinfo.profile%26response_type%3Dcode%26access_type%3Doffline%26redirect_uri%3Dhttps%3A%2F%2Fdevelopers.google.com%2Foauthplayground%26approval_prompt%3Dforce%26client_id%3D407408718192.apps.googleusercontent.com%26hl%3Den%26from_login%3D1%26as%3D-6660997c12ed44e0&btmpl=authsub&hl=en https://accounts.google.com/AccountChooser?service=lso&conti... Per the screen, it only allows: " - View your full name, profile picture and profile URL" " - View any publicly available information on your Google+ profile (if you have one or create one in the future)" It can't see your photos, see your contacts, read your email, post G+ messages, or anything else you didn't authorise.
- rabbyte 12y agoThat was actually understood a decade ago as well and was part of the conversation that led to OpenID and OAuth. It was suggested close to a decade ago that they both merge efforts and they have both struggled to find their place. Development on this scale just lags a bit behind, specially when the community around it is so fragmented and opinionated.
- chris_wot 12y agoI'm a tad confused... To be authorised is great, but authentication must first happen surely? Authorisation says I can access x, but authentication says I am who I say I am! Being authorized to use a particular account is still seperate from proving who I am. I have visions of going to the Pentagon and I say "Hi, President Obama here, give me access to all your intelligence data" and the analysts saying "Certainly sir! You have top authorisation, here is all the data". :-) Actually, that would work better at a bank. "Hi, I'm Donald Trump, give me a million dollars from my loose change account, thanks!"
- keeperofdakeys 12y agoTechnically you don't authenticate using OAuth, you just have a secret token - which is proof you own the account. If you wanted to stretch your analogy, you could say a check from Donald Trump is just an authorisation. OAuth definitely does authenticate though (hence the name).
- nailer 12y agoThe auth on 'oauth' is for authorization - see https://tools.ietf.org/html/rfc6749 https://tools.ietf.org/html/rfc6749 Your first sentence is totally correct though.
- nailer 12y agoGreat question. Think of it as "Hi, I'm an individual who has an oauth access token for President Obama's userinfo.me scope. The only person who can authorise this is President Obama". Hope that helps.
- christiansmith 12y agoIn fact, unlike previous OpenID protocols, OpenID Connect is a profile of OAuth 2.0. The conflation of authorization with authentication is an accident and a mistake. They are still quite separate concepts. Authentication is about verifying identity. Authorization is about privileges afforded a given identity. Access control models usually depend on some form of upstream authentication. The third-party authorization flows provided by OAuth are not intended to establish or verify a user's identity. Their purpose is to extend a user's access to a third-party in a limited way without sharing passwords. Social Sign-in is an accident of 3-Legged OAuth and its use for this purpose is considered a very weak form of authentication. OpenID Connect takes the best ideas from preceding identity protocols and incorporates them into OAuth flows, giving the best of both worlds. More information on all of the above here: https://github.com/christiansmith/anvil-connect/wiki/References https://github.com/christiansmith/anvil-connect/wiki/Referen...
- nailer 12y agoYou've said limited scope authorisation is weak authentication, but you haven't said why in your post. Can anyone advocating OpenID connect give a single sentence explanation of why people (developers and users) would want to use it vs limited scope oauth?
- learningram 12y agoDo you have any suggested good reads about the topics ?