Topic: "OpenID for Bright-Shadows" (page 1 of 1)

1
Author Post
moose
groupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
Hi,

do you know OpenID?
It is a decentralised method for authentification (see linkwiki).

Would you like to introduce OpenID to Bright-Shadows (see linkopenidselector for the UI and linklightopenid for the server-part or linkjanrain for a complete solution which is free, if it isn't used to often -> linkpricing)

I would really like to see OpenID in Bright-Shadows, as I don't want to use the same password for Challenge-Sites as for other services and I forget passwords which I don't use often.

Cheers,
Martin
private message EMail Website
Towley
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
A centralized login maybe means multi-pwnage?
private message Website
moose
groupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
I've proposed this now also in the linkwechall forum, so I guess we should discuss it there.
Edited by moose on 25.06.2011 22:58:52
private message EMail Website
sniperkid
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
Sounds like the way a few companies were thinking of going, Blizzard being one that introduced Battle.NET accounts to keep numerous WoW/SC etc accounts. Good idea if you have multiples....but if someone else gets in, then you've lost everything! Blizzard (and others) got around this by getting people to purchase Authenticators which is tied to accounts (http://www.vasco.com/products/digipass/digipass_go_range/digipass_go6.aspx or similiar). Still not 100% secure but with the "random" digits going off an internal clock its quite impossible to get in.
private message Website
aceldama
groupmastergroupmastergroupmastergroupmaster
@sniperkid: unless it's on a windows pc. the random number generators aren't exactly random. google it. ;) basically it uses the time as the first "seed" and all subsequent numbers are derived from the last result (which is used for the next seed). quite interesteing stuff. granted you have to spoof the target pc into somehow giving you the next number, but if you get it then, well, you can overtake the original pc making it's account void. (note: just a thought) also, i've been so swamped with other projects i have not managed to get around to the recaptcha programming yet. did you manage in the end?
private message
sniperkid
groupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmastergroupmaster
the site i was using to test it on seems to have died out (got DDoS'd) but i've been overwhelmed with work lately, hoping to have some free time in a few weeks :)

private message Website

Topic: "OpenID for Bright-Shadows" (page 1 of 1)

1