Writers wanted - Previous experience not necessary, you only need an interest and we can help every step of the way. Please PM qubit or alexp999 for details.

Jump to content

Welcome to techngaming.com
Register now to gain access to all of our features. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more. This message will be removed once you have signed in.
Login to Account Create an Account
Photo

OAuth 2.0 standard editor quits, takes name off spec

- - - - -

  • Please log in to reply
No replies to this topic

#1
qubit

It's reasons like this that I don't want to store my information in the cloud. Check out the story for full details of this incompetence and vested interest.


The lead author and editor of the OAuth 2.0 network authorization standard has stepped down from his role, withdrawn his name from the specification, and quit the working group, describing the current version of the spec as "the biggest professional disappointment of my career."

Eran Hammer, who helped create the OAuth 1.0 spec, has been editing the evolving 2.0 spec for the last three years. He resigned from his role in June but only went public with his reasons in a blog post on Thursday.


"At the end, I reached the conclusion that OAuth 2.0 is a bad protocol," Hammer writes. "WS-* bad. It is bad enough that I no longer want to be associated with it."

.....................


Authorization tokens in OAuth 2.0 are inherently less secure than they were in OAuth 1.0, he says, as a direct result of a series of compromises that were made to address the demands of the enterprise community.

Even worse, Hammer says, the working group has been unable to reach a consensus on a long line of significant issues, resulting in a specification that fails to deliver on even its most basic goals and doesn't achieve anything more than OAuth 1.0 did.

"I honestly don't know what use cases OAuth 2.0 is trying to solve any more," Hammer says.


The Register

tng Poll v2: Will You Upgrade your PC to Haswell in 2013?

 

Here's a very useful video on herding cats. Practice this and you might just become as good as me!





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users