Gmail Calendar Documents Reader Web more »
Recently Visited Groups | Help | Sign in
Google Groups Home
oAuth and desktop apps
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  12 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Aral Balkan  
View profile  
 More options Feb 17, 1:17 pm
From: Aral Balkan <aralbal...@gmail.com>
Date: Tue, 17 Feb 2009 10:17:15 -0800 (PST)
Local: Tues, Feb 17 2009 1:17 pm
Subject: oAuth and desktop apps
Hey @al3x et. al.,

What's the official stance towards oAuth and desktop apps: will all
apps, *including desktop apps*  be required to implement oAuth?

I'm asking 'cos of the old usability chestnut.

And, at which point do you actually begin to trust an app that you've
installed onto your system with all sorts of other rights like
deleting files off of your machine or sending info from your machine
to the Net. At which point does user beware come into it?

The real benefit of oAuth, as I see it; being able to revoke access,
is as simple as uninstalling the app. Then again, of course, the app
could send your details to a site. But, again, this is a desktop app
you've installed -- if it's that malicious, it could be doing all
sorts of trojany things that are far worse.

Thoughts?

Thanks,
Aral


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Alex Payne  
View profile  
(1 user)  More options Feb 17, 3:46 pm
From: Alex Payne <a...@twitter.com>
Date: Tue, 17 Feb 2009 12:46:25 -0800
Local: Tues, Feb 17 2009 3:46 pm
Subject: Re: oAuth and desktop apps
Eventually, once we've got user experience solutions that work for the
80% case, we'll be moving off of Basic Auth entirely. But not before
desktop app developers are happy. It's going to take some
experimenting, but I'm sure that we can find some good solutions
between the smart folks in this community and those in the greater
OAuth/web standards community.

OAuth doesn't prevent evil folks from shipping Twitter apps that might
be trojans, but it does allow us here at the Mother Ship to revoke
their ability to talk to the Twitter API. That means less spam/"SEO"
tools, and a short time-to-live for applications that are discovered
to be malicious.

--
Alex Payne - API Lead, Twitter, Inc.
http://twitter.com/al3x

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Aral Balkan  
View profile  
 More options Feb 17, 4:51 pm
From: Aral Balkan <aralbal...@gmail.com>
Date: Tue, 17 Feb 2009 13:51:23 -0800 (PST)
Local: Tues, Feb 17 2009 4:51 pm
Subject: Re: oAuth and desktop apps
Hey Alex,

Another thing I was thinking about was specifically for AIR-based apps
(and I guess, to a larger degree, any desktop app) with regards to the
consumer secret.

If that's included in the desktop app, especially in a SWF for AIR
apps, it's basically open to the world. So another app could use the
consumer secret.

Based on your response, I'm assuming that any new desktop client
should implement oAuth as the only means of auth since the switch will
definitely happen at some point.

Thanks,
Aral

On Feb 17, 8:46 pm, Alex Payne <a...@twitter.com> wrote:

> Eventually, once we've got user experience solutions that work for the
> 80% case, we'll be moving off of Basic Auth entirely. But not before
> desktop app developers are happy. It's going to take some
> experimenting, but I'm sure that we can find some good solutions
> between the smart folks in this community and those in the greater
> OAuth/web standards community.

> OAuth doesn't prevent evil folks from shipping Twitter apps that might
> be trojans, but it does allow us here at the Mother Ship to revoke
> their ability to talk to the Twitter API. That means less spam/"SEO"
> tools, and a short time-to-live for applications that are discovered
> to be malicious.

<snip>

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Alex Payne  
View profile  
 More options Feb 17, 5:02 pm
From: Alex Payne <a...@twitter.com>
Date: Tue, 17 Feb 2009 14:02:08 -0800
Local: Tues, Feb 17 2009 5:02 pm
Subject: Re: oAuth and desktop apps
Yes, we need a solution for shipping desktop and open source apps. But
indeed, new apps should definitely look towards OAuth.

--
Alex Payne - API Lead, Twitter, Inc.
http://twitter.com/al3x

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Aral Balkan  
View profile  
 More options Feb 17, 5:29 pm
From: Aral Balkan <aralbal...@gmail.com>
Date: Tue, 17 Feb 2009 14:29:30 -0800 (PST)
Local: Tues, Feb 17 2009 5:29 pm
Subject: Re: oAuth and desktop apps
Would be happy to take part in a brainstorm on that and contribute
however possible.

The UX for setting up multiple accounts on a desktop app where there's
a jarring context change from desktop to browser for each (inc.
possibly logging out/in to different accounts on Twitter) just scares
me.

Aral

On Feb 17, 10:02 pm, Alex Payne <a...@twitter.com> wrote:

> Yes, we need a solution for shipping desktop and open source apps. But
> indeed, new apps should definitely look towards OAuth.

<snip>

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
atebits  
View profile  
 More options Feb 17, 6:03 pm
From: atebits <loren.brich...@gmail.com>
Date: Tue, 17 Feb 2009 15:03:55 -0800 (PST)
Local: Tues, Feb 17 2009 6:03 pm
Subject: Re: oAuth and desktop apps
Ditto here.  How should we get this ball rolling?


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Alex Payne  
View profile  
 More options Feb 17, 6:58 pm
From: Alex Payne <a...@twitter.com>
Date: Tue, 17 Feb 2009 15:58:52 -0800
Local: Tues, Feb 17 2009 6:58 pm
Subject: Re: oAuth and desktop apps
Start a Google Doc or a wiki, maybe?

On Tue, Feb 17, 2009 at 15:03, atebits <loren.brich...@gmail.com> wrote:

> Ditto here.  How should we get this ball rolling?

>> Would be happy to take part in a brainstorm on that and contribute
>> however possible.

--
Alex Payne - API Lead, Twitter, Inc.
http://twitter.com/al3x

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Aral Balkan  
View profile  
 More options Feb 18, 4:39 am
From: Aral Balkan <aralbal...@gmail.com>
Date: Wed, 18 Feb 2009 01:39:02 -0800 (PST)
Local: Wed, Feb 18 2009 4:39 am
Subject: Re: oAuth and desktop apps
Set up an initial page on the Twitter Fan Wiki (tried to get a page on
the API wiki but it seems to be read-only):

https://twitter.pbwiki.com/oauth-desktop-discussion

Put some initial thoughts on there but please feel free to modify
layout, content, etc. as you wish.

Aral

On Feb 17, 11:58 pm, Alex Payne <a...@twitter.com> wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
atebits  
View profile  
 More options Feb 18, 6:48 pm
From: atebits <loren.brich...@gmail.com>
Date: Wed, 18 Feb 2009 15:48:29 -0800 (PST)
Local: Wed, Feb 18 2009 6:48 pm
Subject: Re: oAuth and desktop apps
Thanks for setting up that wiki, I just added a link to some thoughts
I had on the matter (dup'd here: http://blog.atebits.com/2009/02/fixing-oauth/
)

On Feb 18, 1:39 am, Aral Balkan <aralbal...@gmail.com> wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Cameron Kaiser  
View profile  
 More options Feb 18, 7:27 pm
From: Cameron Kaiser <spec...@floodgap.com>
Date: Wed, 18 Feb 2009 16:27:03 -0800 (PST)
Local: Wed, Feb 18 2009 7:27 pm
Subject: Re: oAuth and desktop apps

> Thanks for setting up that wiki, I just added a link to some thoughts

I'm putting some of my thoughts on there too. Hopefully others will join in.

--
------------------------------------ personal: http://www.cameronkaiser.com/ --
  Cameron Kaiser * Floodgap Systems * www.floodgap.com * ckai...@floodgap.com
-- Of course, what I really want is total world domination. -- Linus Torvalds -


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Blaine Cook  
View profile  
 More options Feb 19, 7:39 am
From: Blaine Cook <bla...@twitter.com>
Date: Thu, 19 Feb 2009 04:39:46 -0800 (PST)
Local: Thurs, Feb 19 2009 7:39 am
Subject: Re: oAuth and desktop apps
Please feel free to bring this discussion to the OAuth list, either at
the IETF (where we are currently fielding last-call for the IETF
charter) at https://www.ietf.org/mailman/listinfo/oauth or the OAuth
users' group, http://groups.google.com/group/oauth/

I'd also recommend checking out some very successful desktop
applications that use OAuth or OAuth-like flows, including Netflix on
the XBox, iMovie's YouTube integration, and any desktop Flickr
uploaders. In particular, engaging the developers of those
applications and the developers at NetFlix, YouTube, and Flickr, may
produce insights from running production services of this type. All
the relevant parties are on the OAuth lists, but may need some coaxing
to comment. ;-)

cheers,

b.

On Feb 19, 12:27 am, Cameron Kaiser <spec...@floodgap.com> wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Chris Messina  
View profile  
 More options Feb 20, 12:39 am
From: Chris Messina <chris.mess...@gmail.com>
Date: Thu, 19 Feb 2009 21:39:33 -0800 (PST)
Local: Fri, Feb 20 2009 12:39 am
Subject: Re: oAuth and desktop apps
To add to Blaine's comments, we would love to see folks with general
ideas or thoughts about improving OAuth's user experience contribute
to the existing OAuth wiki: http://wiki.oauth.net (also a PBWiki) or
sharing your thoughts on the OAuth mailing list(s).

The iMovie to YouTube flow that Blaine alluded to can be seen here:

http://flickr.com/photos/factoryjoe/sets/72157601300877805/

This slidedeck gives an overview of OAuth and demonstrates the Fire
Eagle flow:

http://www.slideshare.net/factoryjoe/oauth-ftw-presentation

Here's how Pownce dealt with this on the iPhone:

http://factoryjoe.com/blog/2008/07/11/oauth-for-the-iphone-pownceapp/

Looking forward to your feedback!

Chris

On Feb 19, 4:39 am, Blaine Cook <bla...@twitter.com> wrote:


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google