Our software is compatible, baby.
Home
Go Back   Chief Delphi > ChiefDelphi.com Website > CD Forum Support
CD-Media   CD-Spy  
portal register members calendar search Today's Posts Mark Forums Read FAQ rules

 
Reply
 
Thread Tools Rating: Thread Rating: 2 votes, 5.00 average. Display Modes
  #1   Spotlight this post!  
Unread 06-06-2008, 02:45
Nibbles Nibbles is offline
Interstellar Hitchhiker
AKA: Austin Wright
FRC #0498 (Cobra Commanders)
Team Role: Alumni
 
Join Date: Jan 2008
Rookie Year: 2003
Location: Arizona
Posts: 103
Nibbles is just really niceNibbles is just really niceNibbles is just really niceNibbles is just really niceNibbles is just really nice
Re: OpenID

Let me ask, What would the purpose of OpenID here?
I use OpenID in quite a few different applications, it is very clearly targeted towards the sites that just need quick and simple authentication without the hassle of registering users. For those sorts of small sites where you just need to prove you are the same person that you were last time, like blog comments or many Wikis, it is perfect.
There is nothing wrong with using it on a large site like this, but it would be awkward I think, you still have to have a username associated with your post, which means you have your password too. If the OpenID provider goes down, your entire account is inaccessible if you have no other way to log in.
It might be a good way to log in needing to remember one less password, or more securely with two-factor authentication if you are paranoid like that, so it isn't a bad thing either. The makers of OpenID might disagree, but for a large community like this I do not believe you should be able to post with nothing more then your OpenID URL, some form of extra registration should be required (I don't think anyone meant that though?).

As for CAPTCHAs, what prevents you from requiring a CAPTCHA before the new user is created in the database?

How OpenID might be integrated into a BB like this would be that you can log in with the OpenID. If the OpenID exists in the database, it retrieves the corresponding user ID and logs you in. If the user does not exist, it brings you to an account creation page with your name, email, etc already filled out, verify you are human, and create the account and UID. The OpenID is mapped to your UID automatically. Now you can login with whatever provider you feel safe with, anywhere from Anonymous OpenID to with your private key/client SSL cert (what I use) to biometric two-factor authentication.

With OpenID is is important to allow multiple URLs to link to the same account if there is anything more then a blog comment, unlike individually registered accounts, you are stuck if your OpenID provider goes down your account does not (and vice versa). All OpenID enabled sites need a way to link a new URL to your account without logging in, similar to a "forgot your password?" link.
__________________
Help standardize match data! Use the XML interchange format. (Specification page)
AAA_awright on Freenode IRC chat. (Join us at ##FRC on chat.freenode.net, or in your browser)
Reply With Quote
Reply


Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 03:14.

The Chief Delphi Forums are sponsored by Innovation First International, Inc.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2017, Jelsoft Enterprises Ltd.
Copyright © Chief Delphi