<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>http://groups.google.com/group/oauth-extensions</id>
  <title type="text">OAuth Extensions Google Group</title>
  <subtitle type="text">
  A forum to discuss and develop extensions to the OAuth protocol to be published seperately or added to future versions of OAuth.
  </subtitle>
  <link href="/group/oauth-extensions/feed/atom_v1_0_msgs.xml" rel="self" title="OAuth Extensions feed"/>
  <updated>2009-04-06T16:08:36Z</updated>
  <generator uri="http://groups.google.com" version="1.99">Google Groups</generator>
  <entry>
  <author>
  <name>Eran Hammer-Lahav</name>
  <email>e...@hueniverse.com</email>
  </author>
  <updated>2009-04-06T16:08:36Z</updated>
  <id>http://groups.google.com/group/oauth-extensions/browse_thread/thread/5d18e67089b02341/1f040e0545d67617?show_docid=1f040e0545d67617</id>
  <link href="http://groups.google.com/group/oauth-extensions/browse_thread/thread/5d18e67089b02341/1f040e0545d67617?show_docid=1f040e0545d67617"/>
  <title type="text">OAuth-Extensions Group Closed</title>
  <summary type="html" xml:space="preserve">
  In order to avoid the fragmentation of the community working on OAuth &lt;br&gt; extensions, we are closing this list and leaving it as an archive &lt;br&gt; (read-only). Please post all messages to the main OAuth list: &lt;br&gt; &lt;p&gt;&lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://groups.google.com/group/oauth&quot;&gt;[link]&lt;/a&gt; &lt;br&gt; &lt;p&gt;EHL
  </summary>
  </entry>
  <entry>
  <author>
  <name>John Kemp</name>
  <email>j...@jkemp.net</email>
  </author>
  <updated>2009-04-04T23:51:38Z</updated>
  <id>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/1050147c255c3316?show_docid=1050147c255c3316</id>
  <link href="http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/1050147c255c3316?show_docid=1050147c255c3316"/>
  <title type="text">Re: [oauth-extensions] Re: last call for comments on body signing</title>
  <summary type="html" xml:space="preserve">
  Yes, I see what you&#39;re saying, but until you have read the body, you &lt;br&gt; don&#39;t know the length of the data you are reading. &lt;br&gt; You read the value of the Content-length header before you start &lt;br&gt; reading the body data. &lt;br&gt; And you could verify that it was correctly signed before you are &lt;br&gt; forced to create buffers to read the body. And if the signature isn&#39;t
  </summary>
  </entry>
  <entry>
  <author>
  <name>Ben Adida</name>
  <email>b...@adida.net</email>
  </author>
  <updated>2009-04-04T17:20:23Z</updated>
  <id>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/79d3b261573b2e18?show_docid=79d3b261573b2e18</id>
  <link href="http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/79d3b261573b2e18?show_docid=79d3b261573b2e18"/>
  <title type="text">Re: last call for comments on body signing</title>
  <summary type="html" xml:space="preserve">
  Sure, but if you&#39;re already hashing the content, you won&#39;t be able to &lt;br&gt; truly modify the effective content length without changing the body &lt;br&gt; signature, so in other words the content-length is already being &lt;br&gt; verified by virtue of the hashing of the body. &lt;br&gt; &lt;p&gt;That&#39;s not the case for content-type, which, if you try to &amp;quot;sniff&amp;quot;
  </summary>
  </entry>
  <entry>
  <author>
  <name>Krishna Sankar (ksankar)</name>
  <email>ksan...@cisco.com</email>
  </author>
  <updated>2009-04-03T22:59:30Z</updated>
  <id>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/bcbe95346e1c269a?show_docid=bcbe95346e1c269a</id>
  <link href="http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/bcbe95346e1c269a?show_docid=bcbe95346e1c269a"/>
  <title type="text">Oauth header integrity</title>
  <summary type="html" xml:space="preserve">
  My first cut at an outline draft - attached to my blog &lt;br&gt; &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://doubleclix.wordpress.com/2009/04/03/oauth-header-hash/&quot;&gt;[link]&lt;/a&gt; Naturally &lt;br&gt; leveraged Brian&#39;s body hash spec figuratively and literally. &lt;br&gt; There is lot of work to be done from formatting to processing model to &lt;br&gt; examples and running code. Also need to find a way to get a
  </summary>
  </entry>
  <entry>
  <author>
  <name>Krishna Sankar (ksankar)</name>
  <email>ksan...@cisco.com</email>
  </author>
  <updated>2009-04-03T18:20:22Z</updated>
  <id>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/d8aa3a116997a004?show_docid=d8aa3a116997a004</id>
  <link href="http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/d8aa3a116997a004?show_docid=d8aa3a116997a004"/>
  <title type="text">RE: [oauth-extensions] Re: last call for comments on body signing</title>
  <summary type="html" xml:space="preserve">
  I am working on a preliminary first cut at a header hash draft, based on the discussions. Will send out a draft by tonight. &lt;br&gt; &lt;p&gt;Cheers &lt;br&gt; &amp;lt;k/&amp;gt;
  </summary>
  </entry>
  <entry>
  <author>
  <name>John Kemp</name>
  <email>j...@jkemp.net</email>
  </author>
  <updated>2009-04-03T17:36:04Z</updated>
  <id>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/acf9612acd4a0552?show_docid=acf9612acd4a0552</id>
  <link href="http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/acf9612acd4a0552?show_docid=acf9612acd4a0552"/>
  <title type="text">Re: [oauth-extensions] Re: last call for comments on body signing</title>
  <summary type="html" xml:space="preserve">
  Ben (and now cc&#39;ing the main list since I hear &#39;extensions&#39; is going &lt;br&gt; away), &lt;br&gt; Isn&#39;t that &#39;hint&#39; often used to determine the size of a buffer used to &lt;br&gt; hold the content following the headers, or to constrain the number of &lt;br&gt; bytes read by the recipient? &lt;br&gt; Are you suggesting that the signing of these headers be included in
  </summary>
  </entry>
  <entry>
  <author>
  <name>Ben Adida</name>
  <email>b...@adida.net</email>
  </author>
  <updated>2009-04-03T17:27:55Z</updated>
  <id>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/401af334950bc5c6?show_docid=401af334950bc5c6</id>
  <link href="http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/401af334950bc5c6?show_docid=401af334950bc5c6"/>
  <title type="text">Re: last call for comments on body signing</title>
  <summary type="html" xml:space="preserve">
  Agreed that it does make it more difficult, but still it seems there&#39;s &lt;br&gt; a pretty big hole. &lt;br&gt; &lt;p&gt;Of course, but if you&#39;re trying to build a REST-compliant service, &lt;br&gt; then that&#39;s an ugly hack. &lt;br&gt; &lt;p&gt;I&#39;m certainly not suggesting signing all headers, as that would indeed &lt;br&gt; be complicated. I&#39;m only suggesting signing content-type and (as JK
  </summary>
  </entry>
  <entry>
  <author>
  <name>David Orchard</name>
  <email>orch...@pacificspirit.com</email>
  </author>
  <updated>2009-04-03T16:33:10Z</updated>
  <id>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/b45b34db94bd2437?show_docid=b45b34db94bd2437</id>
  <link href="http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/b45b34db94bd2437?show_docid=b45b34db94bd2437"/>
  <title type="text">Re: [oauth-extensions] Re: last call for comments on body signing</title>
  <summary type="html" xml:space="preserve">
  FYI, grand XML Master James Clark proposed secure HTTP Responses a &lt;br&gt; while ago. There&#39;s some blog posts before and after this one too. &lt;br&gt; &lt;p&gt;&lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://blog.jclark.com/2007/10/http-response-signing-strawman.html&quot;&gt;[link]&lt;/a&gt; &lt;br&gt; &lt;p&gt;Cheers, &lt;br&gt; Dave &lt;br&gt; &lt;p&gt;On Fri, Apr 3, 2009 at 9:24 AM, Krishna Sankar (ksankar)
  </summary>
  </entry>
  <entry>
  <author>
  <name>Krishna Sankar (ksankar)</name>
  <email>ksan...@cisco.com</email>
  </author>
  <updated>2009-04-03T16:24:21Z</updated>
  <id>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/8d3533ae57015fe7?show_docid=8d3533ae57015fe7</id>
  <link href="http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/8d3533ae57015fe7?show_docid=8d3533ae57015fe7"/>
  <title type="text">RE: [oauth-extensions] Re: last call for comments on body signing</title>
  <summary type="html" xml:space="preserve">
  Yep, content-length is hint at most. But might as well include it as it has some value. &lt;br&gt; &lt;p&gt;Cheers &lt;br&gt; &amp;lt;k/&amp;gt;
  </summary>
  </entry>
  <entry>
  <author>
  <name>Brian Eaton</name>
  <email>bea...@google.com</email>
  </author>
  <updated>2009-04-03T16:19:58Z</updated>
  <id>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/159331d6d793a191?show_docid=159331d6d793a191</id>
  <link href="http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/159331d6d793a191?show_docid=159331d6d793a191"/>
  <title type="text">Re: [oauth-extensions] Re: last call for comments on body signing</title>
  <summary type="html" xml:space="preserve">
  The addition of the body hash doesn&#39;t completely prevent that from &lt;br&gt; happening, but it sure makes it more difficult. Instead of the &lt;br&gt; attacker being able to do arbitrary manipulation of content-type and &lt;br&gt; body, they are restricted to tampering with the content-type. Also &lt;br&gt; note that if you are building a file upload API that you think might
  </summary>
  </entry>
  <entry>
  <author>
  <name>Ben Adida</name>
  <email>b...@adida.net</email>
  </author>
  <updated>2009-04-03T16:02:11Z</updated>
  <id>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/f337ebb6f29cb74b?show_docid=f337ebb6f29cb74b</id>
  <link href="http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/f337ebb6f29cb74b?show_docid=f337ebb6f29cb74b"/>
  <title type="text">Re: last call for comments on body signing</title>
  <summary type="html" xml:space="preserve">
  I can see the argument for content-encoding, so I would support that &lt;br&gt; one as it could lead to misinterpretation of the body. I think content- &lt;br&gt; length wouldn&#39;t make a difference, since it&#39;s just a hint regarding &lt;br&gt; what comes next, right? &lt;br&gt; &lt;p&gt;is already very useful. I&#39;d love to be simply compliant with it,
  </summary>
  </entry>
  <entry>
  <author>
  <name>John Kemp</name>
  <email>j...@jkemp.net</email>
  </author>
  <updated>2009-04-03T12:02:13Z</updated>
  <id>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/1758786402ab79b5?show_docid=1758786402ab79b5</id>
  <link href="http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/1758786402ab79b5?show_docid=1758786402ab79b5"/>
  <title type="text">Re: [oauth-extensions] Re: last call for comments on body signing</title>
  <summary type="html" xml:space="preserve">
  Hello Ben, &lt;br&gt; &lt;p&gt;I tend to agree. &lt;br&gt; &lt;p&gt;How about Content-Encoding and Content-Length then? &lt;br&gt; &lt;p&gt;[...] &lt;br&gt; &lt;p&gt;What spec.? ;) &lt;br&gt; &lt;p&gt;- johnk
  </summary>
  </entry>
  <entry>
  <author>
  <name>Ben Adida</name>
  <email>b...@adida.net</email>
  </author>
  <updated>2009-04-03T11:45:47Z</updated>
  <id>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/578332aed764dc2c?show_docid=578332aed764dc2c</id>
  <link href="http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/578332aed764dc2c?show_docid=578332aed764dc2c"/>
  <title type="text">Re: last call for comments on body signing</title>
  <summary type="html" xml:space="preserve">
  Hi Brian, &lt;br&gt; &lt;p&gt;My general attitude is not to design based only on known attacks, &lt;br&gt; since that only helps you fight the last war. Designing defensively &lt;br&gt; for security seems like the more prudent things to do, although of &lt;br&gt; course one has to stop somewhere. That&#39;s why I&#39;m not advocating &lt;br&gt; signing every header. But if you&#39;re going to sign the body, signing a
  </summary>
  </entry>
  <entry>
  <author>
  <name>Krishna Sankar (ksankar)</name>
  <email>ksan...@cisco.com</email>
  </author>
  <updated>2009-04-03T00:14:07Z</updated>
  <id>http://groups.google.com/group/oauth-extensions/browse_thread/thread/35992a5955216d66/4d82c72850aac4df?show_docid=4d82c72850aac4df</id>
  <link href="http://groups.google.com/group/oauth-extensions/browse_thread/thread/35992a5955216d66/4d82c72850aac4df?show_docid=4d82c72850aac4df"/>
  <title type="text">RE: [oauth-extensions] ProtectServe: centralized and formalized authorization for distributed SPs</title>
  <summary type="html" xml:space="preserve">
  Eve, &lt;br&gt; Looks interesting from a quick glance. Need to dig deeper into &lt;br&gt; the exchanges to compare with Oauth et al. &lt;br&gt; &lt;p&gt;	BTW, I think this is very relevant and should be posted to the &lt;br&gt; main oauth list. Moreover, just saw an e-mail from EHL that this mailer &lt;br&gt; would be RO from next week. &lt;br&gt; Cheers &lt;br&gt; &amp;lt;k/&amp;gt; &lt;br&gt; &lt;p&gt;/
  </summary>
  </entry>
  <entry>
  <author>
  <name>Eran Hammer-Lahav</name>
  <email>e...@hueniverse.com</email>
  </author>
  <updated>2009-04-03T00:15:17Z</updated>
  <id>http://groups.google.com/group/oauth-extensions/browse_thread/thread/587a0e45b55061ad/699219c3793762aa?show_docid=699219c3793762aa</id>
  <link href="http://groups.google.com/group/oauth-extensions/browse_thread/thread/587a0e45b55061ad/699219c3793762aa?show_docid=699219c3793762aa"/>
  <title type="text">Proposal: Close the OAuth-Extensions list</title>
  <summary type="html" xml:space="preserve">
  Over the past year activity on the extensions list slowed down. I no longer &lt;br&gt; think there is much value in maintaining two separate lists when the &lt;br&gt; audience is pretty much the same. &lt;br&gt; Unless anyone objects, I will turn the extension list to read-only on &lt;br&gt; Monday. The list will remain open for archive purposes.
  </summary>
  </entry>
</feed>
