The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
From: Dossy Shiobara <do...@panoptic.com>
Date: Fri, 17 Apr 2009 16:32:14 -0400
Local: Fri, Apr 17 2009 4:32 pm
Subject: Re: [oauth] Re: http://apiwiki.twitter.com/Sign-in-with- Twitter
On 4/17/09 4:20 PM, Dirk Balfanz wrote:
> Why? OAuth doesn't need it. It's not an authentication protocol. That's such a sad oversight of the initial OAuth specification. I hope we can fix this in future versions of the spec. > Once you start going down this route, you'll realize that you also I thought the signing mechanism defined by OAuth 1.0 provides > need replay-protection, etc., and before you know it you have > re-invented OpenID. replay-protection, and everything that's included in "etc." that you hint at. Currently, the OAuth callback URL is susceptible to replay attack and -- You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||