<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
	<channel>
		<title>gdp's Comments</title>
		<language>en-us</language>
		<link>https://www.intensedebate.com/users/516197</link>
		<description>Comments by drstarcat</description>
<item>
<title>drstarcat.com : How to Train a 6 Year-Old to Hate Brands</title>
<link>http://drstarcat.com/archives/156#IDComment30253954</link>
<description>Thanks Fred. I wonder if kids these days are so good at avoiding brands that they are just too disengaged to care?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Ultimately the question will be whether this sort of brand advertising (as opposed to the \&quot;thing\&quot; advertising that Google does) continues to drive sales the way it once did or if an ever increasing amount of advertising dollars go to intention-based advertising.�This�is�particularly�important�for�the�New�TV�because,�as�I&amp;#39;ll�be�arguing�in�my�next�post,�intention-based�advertising�is�nearly�impossible�for�video�(because�when�watching�a�video,�my�intention�is�to�be�entertained and not interrupted).    &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I&amp;#39;ll be interested to see how your kids (and the rest of us) react to Hulu�if�the�networks�try�to�cram�in�18�unskippable�ads�for�21�minutes of content. I think the networks might realize we&amp;#39;re more at war than they think. </description>
<pubDate>Mon, 10 Aug 2009 12:12:06 +0000</pubDate>
<guid>http://drstarcat.com/archives/156#IDComment30253954</guid>
</item><item>
<title>drstarcat.com : How to Train a 6 Year-Old to Hate Brands</title>
<link>http://drstarcat.com/archives/156#IDComment30176398</link>
<description>Thanks Doc. It&amp;#39;s always nice to have a comment that&amp;#39;s as (if not more) informative than the original post! </description>
<pubDate>Sun, 9 Aug 2009 20:02:08 +0000</pubDate>
<guid>http://drstarcat.com/archives/156#IDComment30176398</guid>
</item><item>
<title>drstarcat.com : How to Train a 6 Year-Old to Hate Brands</title>
<link>http://drstarcat.com/archives/156#IDComment29738122</link>
<description>I don&amp;#039;t buy the cultural issue.  It&amp;#039;s more fundamental than that.  I DO buy your personal (and to some degree society&amp;#039;s) ability to deal with this instinct in myriad, beautiful, and often counter-intuitive ways.  That&amp;#039;s what makes us great. </description>
<pubDate>Thu, 6 Aug 2009 16:21:06 +0000</pubDate>
<guid>http://drstarcat.com/archives/156#IDComment29738122</guid>
</item><item>
<title>drstarcat.com : Why an OAuth iframe is a Great Idea</title>
<link>http://drstarcat.com/archives/133#IDComment27481845</link>
<description>I know what the user SHOULD do. �I also know what the user WILL do. �And that&amp;#39;s my point. �I believe that users will be more likely to get successfully phished if they get comfortable entering their credentials into redirected sites than they will if they get used to entering their credentials into the sites they are giving access to.�&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;In the first scenario, your average user will think they can give their credentials to a \&quot;somewhat\&quot; dubious site that redirects them to a Netflix-like page because they&amp;#39;ll be convinced�it�IS�Netflix (regardless of the URL).��In�the�second�scenario,�they�will�at least give a second thought to typing their credentials, because it will at least \&quot;feel like\&quot; they giving their credentials to THAT site (whether they are in actuality or not).    &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Your second point is a VERY compelling one�though.��I&amp;#39;d�hate�to�have�my�guys�try�to�hack�something�together�that�doesn&amp;#39;t�work,�or�if�it�does,�is�something�Netflix�wouldn&amp;#39;t�be�happy�with.��Our�real�job�at�SetJam�is�to�make�online�TV�easy�and�that&amp;#39;s�what�we&amp;#39;d�like�to�spend�most�of�our�time�on.��I&amp;#39;d�reconsider�your�anti-framing�stance�however.��I�think�the�community�has�put�\&quot;should\&quot;�ahead�of�\&quot;will\&quot;�in�this�case,�and�that&amp;#39;s�a�recipe�for�disaster. </description>
<pubDate>Fri, 17 Jul 2009 01:51:09 +0000</pubDate>
<guid>http://drstarcat.com/archives/133#IDComment27481845</guid>
</item><item>
<title>drstarcat.com : Why an OAuth iframe is a Great Idea</title>
<link>http://drstarcat.com/archives/133#IDComment27467070</link>
<description>Btw... because of your suggestion, we&amp;#039;re going to do the following:  You need to let Netflix know that you want to use SetJam:  If you&amp;#039;ve already got a Netflix account &amp;lt;login here&amp;gt;.  If you don&amp;#039;t have a Netflix account, &amp;lt;start your 30 day free trial here&amp;gt;.  [smaller]  We won&amp;#039;t store your Netflix login information, if you&amp;#039;d prefer to enter your login information at Netflix, click here. </description>
<pubDate>Thu, 16 Jul 2009 21:36:12 +0000</pubDate>
<guid>http://drstarcat.com/archives/133#IDComment27467070</guid>
</item><item>
<title>drstarcat.com : Why an OAuth iframe is a Great Idea</title>
<link>http://drstarcat.com/archives/133#IDComment27466221</link>
<description>Wow Richard!� That is a very simple but smokin&amp;#39; good idea.� I was planning on putting a notification on the iframe stating that we wouldn&amp;#39;t be storing user credentials, but adding a \&quot;verify\&quot; link for the truly paranoid is a great idea.� Thanks! </description>
<pubDate>Thu, 16 Jul 2009 21:23:06 +0000</pubDate>
<guid>http://drstarcat.com/archives/133#IDComment27466221</guid>
</item><item>
<title>drstarcat.com : Why an OAuth iframe is a Great Idea</title>
<link>http://drstarcat.com/archives/133#IDComment27461628</link>
<description>For a fully secure implementation, this is probably where it has to belong.� This is exactly why iCards works this way.� They problem is that any time you&amp;#39;re relying on the browser, you&amp;#39;ve got to wait for the browser manufacturers to agree to and implement the standard.� And as we all know, that could take a decade (if it ever actually happened). </description>
<pubDate>Thu, 16 Jul 2009 20:22:08 +0000</pubDate>
<guid>http://drstarcat.com/archives/133#IDComment27461628</guid>
</item><item>
<title>drstarcat.com : Why an OAuth iframe is a Great Idea</title>
<link>http://drstarcat.com/archives/133#IDComment27461474</link>
<description>This is a great reply Simon.� As a technologist and member of the Identity community, I also greatly sympathize with it.� I&amp;#39;m still on the fence about this though.� In fact, I thought about writing a follow up post on why implementing OAuth in an iframe is actually better for security.� Here&amp;#39;s my reasoning, and it is only half warped by my desire to give my users an easy experience.&lt;br /&gt;&lt;br /&gt;If I (and the community) consistently redirect people to other sites, it is at least plausible that users would find this the \&quot;normal\&quot; way of doing things and look suspiciously at framed implementations (as they should).� But realistically speaking, what would the user find \&quot;normal\&quot;?� The answer--going to an entirely other site that LOOKS like their trusted site and typing in their credentials.� The thought that they will pay any attention to the URL is a total pipe dream.&lt;br /&gt;&lt;br /&gt;So where does this leave the user?� Perfectly setup for every phishing attack in the world!� On the other hand, with an iframe implementation, what does the user think--I&amp;#39;m trusting THIS site (the relying party) with my authentication credentials.� And this is EXACTLY the site the user should be making the security evaluation about.&lt;br /&gt;&lt;br /&gt;Now the community may argue that this defeats the purpose of OAuth and is no different than the user handing out their credentials to the relying party.� It&amp;#39;s not though--because I&amp;#39;m NOT storing the user&amp;#39;s credentials.� I&amp;#39;m not doing this because I, as the relying party, understand that this reduces MY risk exposure.� &lt;br /&gt;&lt;br /&gt;So my point is three-fold:&lt;br /&gt;Redirects may not be teaching users what you think and may actually be teaching them to erroniously believe that when a site looks like their trusted that it is actually is their IP.    By authenticating on the RP site, users are making the trust evaluation about the correct site.That all is not lost with this implementation because we&amp;#39;ve won half the battle by teaching TECHNOLOGISTS how to be an RP and the advantages on NOT storing user credentials. </description>
<pubDate>Thu, 16 Jul 2009 20:19:16 +0000</pubDate>
<guid>http://drstarcat.com/archives/133#IDComment27461474</guid>
</item><item>
<title>drstarcat.com : Why an OAuth iframe is a Great Idea</title>
<link>http://drstarcat.com/archives/133#IDComment27342725</link>
<description>Good point and something we saw discussed in the OAuth community about this.� Others have managed to pull it off, so hopefully the issues won&amp;#39;t be insurmountable.� Knowing my luck, we&amp;#39;ll waste some time on it and have to go back to the new window anyway! </description>
<pubDate>Wed, 15 Jul 2009 12:44:05 +0000</pubDate>
<guid>http://drstarcat.com/archives/133#IDComment27342725</guid>
</item><item>
<title>drstarcat.com : Why an OAuth iframe is a Great Idea</title>
<link>http://drstarcat.com/archives/133#IDComment27287420</link>
<description>Eh... We could, but I feel like the full redirect is even worse than  &lt;br /&gt;popping up another window.  If the claim holder sites didn&amp;#039;t make  &lt;br /&gt;their authentication pages so ugly it wouldn&amp;#039;t be so bad, but  &lt;br /&gt;typically they&amp;#039;re just a login box surrounded by a black background!&lt;br /&gt;&lt;br /&gt;rj&lt;br /&gt;&lt;br /&gt;Sent from my iPhone </description>
<pubDate>Tue, 14 Jul 2009 22:01:04 +0000</pubDate>
<guid>http://drstarcat.com/archives/133#IDComment27287420</guid>
</item><item>
<title>drstarcat.com : The Physics of Air Conditioners--Preventing bloodshed in the office</title>
<link>http://drstarcat.com/archives/106#IDComment26265005</link>
<description>Amen to that! </description>
<pubDate>Sat, 4 Jul 2009 01:37:04 +0000</pubDate>
<guid>http://drstarcat.com/archives/106#IDComment26265005</guid>
</item><item>
<title>drstarcat.com : The Physics of Air Conditioners--Preventing bloodshed in the office</title>
<link>http://drstarcat.com/archives/106#IDComment26184359</link>
<description>Duly noted.  Thank you! </description>
<pubDate>Fri, 3 Jul 2009 02:50:15 +0000</pubDate>
<guid>http://drstarcat.com/archives/106#IDComment26184359</guid>
</item><item>
<title>drstarcat.com : The Physics of Air Conditioners--Preventing bloodshed in the office</title>
<link>http://drstarcat.com/archives/106#IDComment26125081</link>
<description>Ha!  So wrong.  Office: Between 68-72.  I&amp;#039;m not religious about this, I just can&amp;#039;t STAND when it gets set to 50 degrees and after a few hours I realize that I&amp;#039;m shivering.  I don&amp;#039;t care about cool setting and probably prefer energy saver on (I never like the on/off thing with the fan) Home: 68/High Cool (to drown out the City noise), and ES off (to keep that white noise coming!) </description>
<pubDate>Thu, 2 Jul 2009 13:43:45 +0000</pubDate>
<guid>http://drstarcat.com/archives/106#IDComment26125081</guid>
</item>	</channel>
</rss>