<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: OpenID&#8217;s one big weakness</title>
	<atom:link href="http://arapehlivanian.com/openids-one-big-weakness/feed/" rel="self" type="application/rss+xml" />
	<link>http://arapehlivanian.com/openids-one-big-weakness/</link>
	<description>Web Standards, Web Culture, Web Everything.™</description>
	<lastBuildDate>Sun, 25 Sep 2011 04:23:30 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Will Norris</title>
		<link>http://arapehlivanian.com/openids-one-big-weakness/comment-page-1/#comment-8093</link>
		<dc:creator>Will Norris</dc:creator>
		<pubDate>Mon, 05 Mar 2007 23:26:34 +0000</pubDate>
		<guid isPermaLink="false">http://arapehlivanian.com/2007/03/02/openids-one-big-weakness/#comment-8093</guid>
		<description>There are a couple of solutions to this single point of failure.  One that has been discussed on a couple of blogs recently, would be for relying parties to enable you to tie multiple OpenIDs to a single account at the given service (like Magnolia and ClaimID currently do).  Of course this would require that you manually link those OpenIDs at each service, which is certainly less than idea.  

The other option is to do OpenID delegation using XRDS, which allows you to specify multiple delegates in a priority order (my XRDS for example -- http://willnorris.com/xrds.xml).  In my case, if MyOpenID is down for whatever reason, the relying party would automatically fail over to livejournal.  Of course there is still a single point of failure -- the server hosting my XRDS file (but we all know that DreamHost is rock solid.  *cough*).  

There is  a bit of discussion happening right now about how to represent the fact that multiple OpenIDs refer to the same person and should therefore be interchangeable.  If this can be achieved in some kind of decentralized way, it may be possible to eliminate the single point of failure.</description>
		<content:encoded><![CDATA[<p>There are a couple of solutions to this single point of failure.  One that has been discussed on a couple of blogs recently, would be for relying parties to enable you to tie multiple OpenIDs to a single account at the given service (like Magnolia and ClaimID currently do).  Of course this would require that you manually link those OpenIDs at each service, which is certainly less than idea.  </p>
<p>The other option is to do OpenID delegation using XRDS, which allows you to specify multiple delegates in a priority order (my XRDS for example &#8212; <a href="http://willnorris.com/xrds.xml" rel="nofollow">http://willnorris.com/xrds.xml</a>).  In my case, if MyOpenID is down for whatever reason, the relying party would automatically fail over to livejournal.  Of course there is still a single point of failure &#8212; the server hosting my XRDS file (but we all know that DreamHost is rock solid.  *cough*).  </p>
<p>There is  a bit of discussion happening right now about how to represent the fact that multiple OpenIDs refer to the same person and should therefore be interchangeable.  If this can be achieved in some kind of decentralized way, it may be possible to eliminate the single point of failure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ian Muir</title>
		<link>http://arapehlivanian.com/openids-one-big-weakness/comment-page-1/#comment-7940</link>
		<dc:creator>Ian Muir</dc:creator>
		<pubDate>Fri, 02 Mar 2007 22:47:15 +0000</pubDate>
		<guid isPermaLink="false">http://arapehlivanian.com/2007/03/02/openids-one-big-weakness/#comment-7940</guid>
		<description>I&#039;d have to say that this is the main reason I haven&#039;t implemented OpenID yet. 

I had a similar issue when I signed up with my OpenID. I tried voting in a Jyte poll and could not login because I had made an error in the sign up process. I&#039;d hardly like entire applications to go down if my OpenID server is not working.

Login failing for Jyte is an inconvience, if I start using OpenID to login to my email that&#039;s a major problem. So, I&#039;m not planning on implementing anything important until there&#039;s a better contingency plan.</description>
		<content:encoded><![CDATA[<p>I&#8217;d have to say that this is the main reason I haven&#8217;t implemented OpenID yet. </p>
<p>I had a similar issue when I signed up with my OpenID. I tried voting in a Jyte poll and could not login because I had made an error in the sign up process. I&#8217;d hardly like entire applications to go down if my OpenID server is not working.</p>
<p>Login failing for Jyte is an inconvience, if I start using OpenID to login to my email that&#8217;s a major problem. So, I&#8217;m not planning on implementing anything important until there&#8217;s a better contingency plan.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

