« OpenID and "High Security" | Main | OpenID IPR: Please Comment! »

March 20, 2007

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83455eeb869e200d8342fa76d53ef

Listed below are links to weblogs that reference OpenID for Desktop Clients:

Comments

bmuller

Just understand that your idea still requires that the user *absolutely* trusts the client software with a username and password. Just because the client appears to be opening a regular browser window does not mean that it's not opening a second, hacked installation (modified upon the software client install).

Mark Murphy

Here are a couple other variations on your theme:

-- Embed a Web browser in the desktop app itself, such as Gecko. That makes the OpenID work happen fully within the application rather than through an external browser. Monitoring browser progress through events might even eliminate the need to do the localhost:9876 socket.

-- When the user launches the "program", the icon or whatever spawns both a Web browser (visible) and your application (not yet visible, but with your localhost:9876 socket). The browser opens onto a traditional OpenID login page, and login proceeds like it would if they were logging into a local site. If you make your OpenID process be specific to your desktop app, the server can just "know" to redir to localhost:9876 upon completion, which triggers popping up the first application window and, perhaps, closing the browser.

Basically, I agree with bmuller that having login split between an app and a browser might be a bit disconcerting for users.

Timothy

I've been thinking about a simular solution. (As you can see on my blog). I make the client act as a browser, instead of using a browser, but then some really good html form parsing code needs to be written.

But there are a few security implications, also noted in my blog.

Chris Messina

BTW, you should check out OAuth since this idea was core to the problem we set out to solve.

http://oauth.net

Gabe Wachob

Yes, OAuth is the answer here now! Everyone should go check out oauth.net for this problem now...

Munish

Can you please provide me the code for this?

LillyMckenzie

Following my own investigation, billions of persons all over the world receive the home loans at good creditors. Hence, there is a good possibility to get a short term loan in every country.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Gabe's Stuff

Gabe Wachob's Tumblelog

September 2009

Sun Mon Tue Wed Thu Fri Sat
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30      

Google Friend Connect