<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<rss version="2.0">
  <channel>
  <title>OAuth Extensions Google Group</title>
  <link>http://groups.google.com/group/oauth-extensions</link>
  <description>A forum to discuss and develop extensions to the OAuth protocol to be published seperately or added to future versions of OAuth.</description>
  <language>en</language>
  <item>
  <title>OAuth-Extensions Group Closed</title>
  <link>http://groups.google.com/group/oauth-extensions/browse_thread/thread/5d18e67089b02341/1f040e0545d67617?show_docid=1f040e0545d67617</link>
  <description>
  In order to avoid the fragmentation of the community working on OAuth &lt;br&gt; extensions, we are closing this list and leaving it as an archive &lt;br&gt; (read-only). Please post all messages to the main OAuth list: &lt;br&gt; &lt;p&gt;&lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://groups.google.com/group/oauth&quot;&gt;[link]&lt;/a&gt; &lt;br&gt; &lt;p&gt;EHL
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/oauth-extensions/browse_thread/thread/5d18e67089b02341/1f040e0545d67617?show_docid=1f040e0545d67617</guid>
  <author>
  e...@hueniverse.com
  (Eran Hammer-Lahav)
  </author>
  <pubDate>Mon, 06 Apr 2009 16:08:36 UT
</pubDate>
  </item>
  <item>
  <title>Re: [oauth-extensions] Re: last call for comments on body signing</title>
  <link>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/1050147c255c3316?show_docid=1050147c255c3316</link>
  <description>
  Yes, I see what you&#39;re saying, but until you have read the body, you &lt;br&gt; don&#39;t know the length of the data you are reading. &lt;br&gt; You read the value of the Content-length header before you start &lt;br&gt; reading the body data. &lt;br&gt; And you could verify that it was correctly signed before you are &lt;br&gt; forced to create buffers to read the body. And if the signature isn&#39;t
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/1050147c255c3316?show_docid=1050147c255c3316</guid>
  <author>
  j...@jkemp.net
  (John Kemp)
  </author>
  <pubDate>Sat, 04 Apr 2009 23:51:38 UT
</pubDate>
  </item>
  <item>
  <title>Re: last call for comments on body signing</title>
  <link>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/79d3b261573b2e18?show_docid=79d3b261573b2e18</link>
  <description>
  Sure, but if you&#39;re already hashing the content, you won&#39;t be able to &lt;br&gt; truly modify the effective content length without changing the body &lt;br&gt; signature, so in other words the content-length is already being &lt;br&gt; verified by virtue of the hashing of the body. &lt;br&gt; &lt;p&gt;That&#39;s not the case for content-type, which, if you try to &amp;quot;sniff&amp;quot;
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/79d3b261573b2e18?show_docid=79d3b261573b2e18</guid>
  <author>
  b...@adida.net
  (Ben Adida)
  </author>
  <pubDate>Sat, 04 Apr 2009 17:20:23 UT
</pubDate>
  </item>
  <item>
  <title>Oauth header integrity</title>
  <link>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/bcbe95346e1c269a?show_docid=bcbe95346e1c269a</link>
  <description>
  My first cut at an outline draft - attached to my blog &lt;br&gt; &lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://doubleclix.wordpress.com/2009/04/03/oauth-header-hash/&quot;&gt;[link]&lt;/a&gt; Naturally &lt;br&gt; leveraged Brian&#39;s body hash spec figuratively and literally. &lt;br&gt; There is lot of work to be done from formatting to processing model to &lt;br&gt; examples and running code. Also need to find a way to get a
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/bcbe95346e1c269a?show_docid=bcbe95346e1c269a</guid>
  <author>
  ksan...@cisco.com
  (Krishna Sankar (ksankar))
  </author>
  <pubDate>Fri, 03 Apr 2009 22:59:30 UT
</pubDate>
  </item>
  <item>
  <title>RE: [oauth-extensions] Re: last call for comments on body signing</title>
  <link>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/d8aa3a116997a004?show_docid=d8aa3a116997a004</link>
  <description>
  I am working on a preliminary first cut at a header hash draft, based on the discussions. Will send out a draft by tonight. &lt;br&gt; &lt;p&gt;Cheers &lt;br&gt; &amp;lt;k/&amp;gt;
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/d8aa3a116997a004?show_docid=d8aa3a116997a004</guid>
  <author>
  ksan...@cisco.com
  (Krishna Sankar (ksankar))
  </author>
  <pubDate>Fri, 03 Apr 2009 18:20:22 UT
</pubDate>
  </item>
  <item>
  <title>Re: [oauth-extensions] Re: last call for comments on body signing</title>
  <link>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/acf9612acd4a0552?show_docid=acf9612acd4a0552</link>
  <description>
  Ben (and now cc&#39;ing the main list since I hear &#39;extensions&#39; is going &lt;br&gt; away), &lt;br&gt; Isn&#39;t that &#39;hint&#39; often used to determine the size of a buffer used to &lt;br&gt; hold the content following the headers, or to constrain the number of &lt;br&gt; bytes read by the recipient? &lt;br&gt; Are you suggesting that the signing of these headers be included in
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/acf9612acd4a0552?show_docid=acf9612acd4a0552</guid>
  <author>
  j...@jkemp.net
  (John Kemp)
  </author>
  <pubDate>Fri, 03 Apr 2009 17:36:04 UT
</pubDate>
  </item>
  <item>
  <title>Re: last call for comments on body signing</title>
  <link>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/401af334950bc5c6?show_docid=401af334950bc5c6</link>
  <description>
  Agreed that it does make it more difficult, but still it seems there&#39;s &lt;br&gt; a pretty big hole. &lt;br&gt; &lt;p&gt;Of course, but if you&#39;re trying to build a REST-compliant service, &lt;br&gt; then that&#39;s an ugly hack. &lt;br&gt; &lt;p&gt;I&#39;m certainly not suggesting signing all headers, as that would indeed &lt;br&gt; be complicated. I&#39;m only suggesting signing content-type and (as JK
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/401af334950bc5c6?show_docid=401af334950bc5c6</guid>
  <author>
  b...@adida.net
  (Ben Adida)
  </author>
  <pubDate>Fri, 03 Apr 2009 17:27:55 UT
</pubDate>
  </item>
  <item>
  <title>Re: [oauth-extensions] Re: last call for comments on body signing</title>
  <link>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/b45b34db94bd2437?show_docid=b45b34db94bd2437</link>
  <description>
  FYI, grand XML Master James Clark proposed secure HTTP Responses a &lt;br&gt; while ago. There&#39;s some blog posts before and after this one too. &lt;br&gt; &lt;p&gt;&lt;a target=&quot;_blank&quot; rel=nofollow href=&quot;http://blog.jclark.com/2007/10/http-response-signing-strawman.html&quot;&gt;[link]&lt;/a&gt; &lt;br&gt; &lt;p&gt;Cheers, &lt;br&gt; Dave &lt;br&gt; &lt;p&gt;On Fri, Apr 3, 2009 at 9:24 AM, Krishna Sankar (ksankar)
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/b45b34db94bd2437?show_docid=b45b34db94bd2437</guid>
  <author>
  orch...@pacificspirit.com
  (David Orchard)
  </author>
  <pubDate>Fri, 03 Apr 2009 16:33:10 UT
</pubDate>
  </item>
  <item>
  <title>RE: [oauth-extensions] Re: last call for comments on body signing</title>
  <link>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/8d3533ae57015fe7?show_docid=8d3533ae57015fe7</link>
  <description>
  Yep, content-length is hint at most. But might as well include it as it has some value. &lt;br&gt; &lt;p&gt;Cheers &lt;br&gt; &amp;lt;k/&amp;gt;
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/8d3533ae57015fe7?show_docid=8d3533ae57015fe7</guid>
  <author>
  ksan...@cisco.com
  (Krishna Sankar (ksankar))
  </author>
  <pubDate>Fri, 03 Apr 2009 16:24:21 UT
</pubDate>
  </item>
  <item>
  <title>Re: [oauth-extensions] Re: last call for comments on body signing</title>
  <link>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/159331d6d793a191?show_docid=159331d6d793a191</link>
  <description>
  The addition of the body hash doesn&#39;t completely prevent that from &lt;br&gt; happening, but it sure makes it more difficult. Instead of the &lt;br&gt; attacker being able to do arbitrary manipulation of content-type and &lt;br&gt; body, they are restricted to tampering with the content-type. Also &lt;br&gt; note that if you are building a file upload API that you think might
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/159331d6d793a191?show_docid=159331d6d793a191</guid>
  <author>
  bea...@google.com
  (Brian Eaton)
  </author>
  <pubDate>Fri, 03 Apr 2009 16:19:58 UT
</pubDate>
  </item>
  <item>
  <title>Re: last call for comments on body signing</title>
  <link>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/f337ebb6f29cb74b?show_docid=f337ebb6f29cb74b</link>
  <description>
  I can see the argument for content-encoding, so I would support that &lt;br&gt; one as it could lead to misinterpretation of the body. I think content- &lt;br&gt; length wouldn&#39;t make a difference, since it&#39;s just a hint regarding &lt;br&gt; what comes next, right? &lt;br&gt; &lt;p&gt;is already very useful. I&#39;d love to be simply compliant with it,
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/f337ebb6f29cb74b?show_docid=f337ebb6f29cb74b</guid>
  <author>
  b...@adida.net
  (Ben Adida)
  </author>
  <pubDate>Fri, 03 Apr 2009 16:02:11 UT
</pubDate>
  </item>
  <item>
  <title>Re: [oauth-extensions] Re: last call for comments on body signing</title>
  <link>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/1758786402ab79b5?show_docid=1758786402ab79b5</link>
  <description>
  Hello Ben, &lt;br&gt; &lt;p&gt;I tend to agree. &lt;br&gt; &lt;p&gt;How about Content-Encoding and Content-Length then? &lt;br&gt; &lt;p&gt;[...] &lt;br&gt; &lt;p&gt;What spec.? ;) &lt;br&gt; &lt;p&gt;- johnk
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/1758786402ab79b5?show_docid=1758786402ab79b5</guid>
  <author>
  j...@jkemp.net
  (John Kemp)
  </author>
  <pubDate>Fri, 03 Apr 2009 12:02:13 UT
</pubDate>
  </item>
  <item>
  <title>Re: last call for comments on body signing</title>
  <link>http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/578332aed764dc2c?show_docid=578332aed764dc2c</link>
  <description>
  Hi Brian, &lt;br&gt; &lt;p&gt;My general attitude is not to design based only on known attacks, &lt;br&gt; since that only helps you fight the last war. Designing defensively &lt;br&gt; for security seems like the more prudent things to do, although of &lt;br&gt; course one has to stop somewhere. That&#39;s why I&#39;m not advocating &lt;br&gt; signing every header. But if you&#39;re going to sign the body, signing a
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/oauth-extensions/browse_thread/thread/113f52b3ccace4d7/578332aed764dc2c?show_docid=578332aed764dc2c</guid>
  <author>
  b...@adida.net
  (Ben Adida)
  </author>
  <pubDate>Fri, 03 Apr 2009 11:45:47 UT
</pubDate>
  </item>
  <item>
  <title>RE: [oauth-extensions] ProtectServe: centralized and formalized authorization for distributed SPs</title>
  <link>http://groups.google.com/group/oauth-extensions/browse_thread/thread/35992a5955216d66/4d82c72850aac4df?show_docid=4d82c72850aac4df</link>
  <description>
  Eve, &lt;br&gt; Looks interesting from a quick glance. Need to dig deeper into &lt;br&gt; the exchanges to compare with Oauth et al. &lt;br&gt; &lt;p&gt;	BTW, I think this is very relevant and should be posted to the &lt;br&gt; main oauth list. Moreover, just saw an e-mail from EHL that this mailer &lt;br&gt; would be RO from next week. &lt;br&gt; Cheers &lt;br&gt; &amp;lt;k/&amp;gt; &lt;br&gt; &lt;p&gt;/
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/oauth-extensions/browse_thread/thread/35992a5955216d66/4d82c72850aac4df?show_docid=4d82c72850aac4df</guid>
  <author>
  ksan...@cisco.com
  (Krishna Sankar (ksankar))
  </author>
  <pubDate>Fri, 03 Apr 2009 00:14:07 UT
</pubDate>
  </item>
  <item>
  <title>Proposal: Close the OAuth-Extensions list</title>
  <link>http://groups.google.com/group/oauth-extensions/browse_thread/thread/587a0e45b55061ad/699219c3793762aa?show_docid=699219c3793762aa</link>
  <description>
  Over the past year activity on the extensions list slowed down. I no longer &lt;br&gt; think there is much value in maintaining two separate lists when the &lt;br&gt; audience is pretty much the same. &lt;br&gt; Unless anyone objects, I will turn the extension list to read-only on &lt;br&gt; Monday. The list will remain open for archive purposes.
  </description>
  <guid isPermaLink="true">http://groups.google.com/group/oauth-extensions/browse_thread/thread/587a0e45b55061ad/699219c3793762aa?show_docid=699219c3793762aa</guid>
  <author>
  e...@hueniverse.com
  (Eran Hammer-Lahav)
  </author>
  <pubDate>Fri, 03 Apr 2009 00:15:17 UT
</pubDate>
  </item>
  </channel>
</rss>
