<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Authentication Requires Trust</title>
	<link>http://alphabeta.phoneboy.com/1174/authentication-requires-trust</link>
	<description>VoIP, Telecom, and Technology Made Simple</description>
	<pubDate>Wed, 19 Nov 2008 12:02:18 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: chobas.com&#8217;s blog &#187; I really don&#8217;t know what to title this one</title>
		<link>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-5734</link>
		<dc:creator>chobas.com&#8217;s blog &#187; I really don&#8217;t know what to title this one</dc:creator>
		<pubDate>Mon, 26 Feb 2007 05:09:09 +0000</pubDate>
		<guid>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-5734</guid>
		<description>[...] get it and how it&#8217;s the latest meme and the fashionable fad. And I was going to cite this&#8217;s guys post. But then he reneged on his stance and wrote this. There remains something that I don&#8217;t like [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] get it and how it&#8217;s the latest meme and the fashionable fad. And I was going to cite this&#8217;s guys post. But then he reneged on his stance and wrote this. There remains something that I don&#8217;t like [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: I Got BlueBoxed!</title>
		<link>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-1584</link>
		<dc:creator>I Got BlueBoxed!</dc:creator>
		<pubDate>Thu, 04 Jan 2007 01:04:17 +0000</pubDate>
		<guid>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-1584</guid>
		<description>[...] A recent post of mine got mentioned on the Blue Box VoIP Security Podcast (specifically on Episode #48)! Hm&#8230; I might have to listen to start listening to this podcast. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] A recent post of mine got mentioned on the Blue Box VoIP Security Podcast (specifically on Episode #48)! Hm&#8230; I might have to listen to start listening to this podcast. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blue Box: The VoIP Security Podcast</title>
		<link>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-1583</link>
		<dc:creator>Blue Box: The VoIP Security Podcast</dc:creator>
		<pubDate>Thu, 04 Jan 2007 00:20:52 +0000</pubDate>
		<guid>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-1583</guid>
		<description>&lt;strong&gt;Blue Box #48: The Crystal Ball Edition - Top VoIP Security issues of 2006 and predictions for 2007, Skype worm that wasn't, drive-by SPIT, OpenID, poking holes in firewalls, listener comments and more......&lt;/strong&gt;

Synopsis: The Crystal Ball Edition - Top VoIP Security issues of 2006 and predictions for 2007, Skype worm that wasn't, drive-by SPIT, OpenID for SIP authentication, poking holes in firewalls, listener comments and more... Welcome to Blue Box: The VoI...</description>
		<content:encoded><![CDATA[<p><strong>Blue Box #48: The Crystal Ball Edition - Top VoIP Security issues of 2006 and predictions for 2007, Skype worm that wasn&#8217;t, drive-by SPIT, OpenID, poking holes in firewalls, listener comments and more&#8230;&#8230;</strong></p>
<p>Synopsis: The Crystal Ball Edition - Top VoIP Security issues of 2006 and predictions for 2007, Skype worm that wasn&#8217;t, drive-by SPIT, OpenID for SIP authentication, poking holes in firewalls, listener comments and more&#8230; Welcome to Blue Box: The VoI&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OpenID身份验证系统的可信性 at iF20:天真。天眞的我们必然幸福。</title>
		<link>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-591</link>
		<dc:creator>OpenID身份验证系统的可信性 at iF20:天真。天眞的我们必然幸福。</dc:creator>
		<pubDate>Fri, 15 Dec 2006 16:06:11 +0000</pubDate>
		<guid>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-591</guid>
		<description>[...] 但是PhoneBoy对这种认证服务的随意性与自由化产生怀疑，他在文章&#8221;Authentication Requires Trust&#8220;里面提到如何保证这种认证服务的可信性问题。中国有句古话叫“王婆卖瓜，自卖自夸”，同样的对于自主架设的OpenID认证服务器也是如此。如何保证你的验证所提供的信息是真实的，OpenID的运行机制并没有对此做出验证。相反，在OpenID的运行机制说明中，关于信任问题是如何描述的： This is not a trust system. Trust requires identity first. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] 但是PhoneBoy对这种认证服务的随意性与自由化产生怀疑，他在文章&#8221;Authentication Requires Trust&#8220;里面提到如何保证这种认证服务的可信性问题。中国有句古话叫“王婆卖瓜，自卖自夸”，同样的对于自主架设的OpenID认证服务器也是如此。如何保证你的验证所提供的信息是真实的，OpenID的运行机制并没有对此做出验证。相反，在OpenID的运行机制说明中，关于信任问题是如何描述的： This is not a trust system. Trust requires identity first. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Telepocalypse</title>
		<link>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-445</link>
		<dc:creator>Telepocalypse</dc:creator>
		<pubDate>Thu, 14 Dec 2006 20:28:14 +0000</pubDate>
		<guid>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-445</guid>
		<description>&lt;strong&gt;Shut up, Martin!...&lt;/strong&gt;

There seems to be considerable public demand, so I&#8217;ll explain why no amount of technology is going to make an open voice network appear. I&#8217;ve written about open vs. closed networks before a bit. We don&#8217;t have a comprehensive theory......</description>
		<content:encoded><![CDATA[<p><strong>Shut up, Martin!&#8230;</strong></p>
<p>There seems to be considerable public demand, so I&#8217;ll explain why no amount of technology is going to make an open voice network appear. I&#8217;ve written about open vs. closed networks before a bit. We don&#8217;t have a comprehensive theory&#8230;&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The PhoneBoy Blog &#187; Eating My Words on OpenID</title>
		<link>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-439</link>
		<dc:creator>The PhoneBoy Blog &#187; Eating My Words on OpenID</dc:creator>
		<pubDate>Thu, 14 Dec 2006 19:39:57 +0000</pubDate>
		<guid>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-439</guid>
		<description>[...] Between a private email from Aswath and other posts on OpenID, I have reconsidered my opinion on this. It may not be such a bad thing after all. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Between a private email from Aswath and other posts on OpenID, I have reconsidered my opinion on this. It may not be such a bad thing after all. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blog by Kveton &#187; OpenID + VoIP == Good?</title>
		<link>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-436</link>
		<dc:creator>Blog by Kveton &#187; OpenID + VoIP == Good?</dc:creator>
		<pubDate>Thu, 14 Dec 2006 17:32:08 +0000</pubDate>
		<guid>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-436</guid>
		<description>[...] I happened upon a discussion about using OpenID for authenticating VoIP clients to one another that was sparked by this post posted by Martin Geddes. That was followed up by Aswath with a post describing how you could use OpenID to help assert your identity with VoIP calls. This was followed up by Phoneboy (not his real name, I *think* - heh) leading to a discussion about OpenID and its lack of trust. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] I happened upon a discussion about using OpenID for authenticating VoIP clients to one another that was sparked by this post posted by Martin Geddes. That was followed up by Aswath with a post describing how you could use OpenID to help assert your identity with VoIP calls. This was followed up by Phoneboy (not his real name, I *think* - heh) leading to a discussion about OpenID and its lack of trust. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OpenID: A possible identity mechanism for VoIP? -- Alec Saunders .LOG</title>
		<link>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-430</link>
		<dc:creator>OpenID: A possible identity mechanism for VoIP? -- Alec Saunders .LOG</dc:creator>
		<pubDate>Thu, 14 Dec 2006 13:59:40 +0000</pubDate>
		<guid>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-430</guid>
		<description>[...] Holes?  Well, as Phoneboy pointed out, there is no trusted authority required in the spec.  But, according to the website, Verisign can provide that.  Moreover, because it&#8217;s open and distributed, why couldn&#8217;t your employer, the local police station, your phone company or your church vouch for you? [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Holes?  Well, as Phoneboy pointed out, there is no trusted authority required in the spec.  But, according to the website, Verisign can provide that.  Moreover, because it&#8217;s open and distributed, why couldn&#8217;t your employer, the local police station, your phone company or your church vouch for you? [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Authentication &#124; directory-financial.info</title>
		<link>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-19921</link>
		<dc:creator>Authentication &#124; directory-financial.info</dc:creator>
		<pubDate>Wed, 31 Dec 1969 16:00:00 +0000</pubDate>
		<guid>http://alphabeta.phoneboy.com/1174/authentication-requires-trust#comment-19921</guid>
		<description>&lt;!--%kramer-pre%--&gt; Required ( The ISA Server requires authorization to fulfill the request. Access to the Web Proxy service is denied. )." i know that since we have a proxy server in our ...  Related:  • ISA • server • authentication • failed • error     Authentication Requires Trust   While that?s fine and dandy from a lack of vendor lock-in point of view, from an authentication point of view, it?s horrible. What?s worse, is that there is no trust built into the model. Even the How This Works page at OpenID says it! &lt;!--%kramer-post%--&gt;</description>
		<content:encoded><![CDATA[<p><a href="http://www.technorati.com/cosmos/search.html?url="class="technorati-balloon"  onclick="javascript:urchinTracker ('/outbound/comment/www.technorati.com');"><img src="http://static.technorati.com/images/bubble_h17.gif" class="technorati-balloon" alt="links from Technorati" style="border:0;" /></a> Required ( The ISA Server requires authorization to fulfill the request. Access to the Web Proxy service is denied. ).&#8221; i know that since we have a proxy server in our &#8230;  Related:  • ISA • server • authentication • failed • error     Authentication Requires Trust   While that?s fine and dandy from a lack of vendor lock-in point of view, from an authentication point of view, it?s horrible. What?s worse, is that there is no trust built into the model. Even the How This Works page at OpenID says it!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
