<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
	<channel>
		<title>gdp's Comments</title>
		<language>en-us</language>
		<link>https://www.intensedebate.com/users/607241</link>
		<description>Comments by simonwillison</description>
<item>
<title>materialsdave.com : Social conferencing with Lanyrd</title>
<link>http://materialsdave.com/social-conferencing-with-lanyrd#IDComment106534913</link>
<description>Thanks for trying out Lanyrd. We&amp;#039;re using Twitter rather than Facebook or LinkedIn mainly because Twitter has the best support for &amp;quot;follow&amp;quot; relationships. I don&amp;#039;t necessarily want to hear about conferences attended by my co-workers (LinkedIn) and personal friends (Facebook) - I want to go to the same conferences as the people I respect, who may have no idea who I am. I can follow someone on Twitter without them needing to follow me back. </description>
<pubDate>Thu, 28 Oct 2010 08:25:59 +0000</pubDate>
<guid>http://materialsdave.com/social-conferencing-with-lanyrd#IDComment106534913</guid>
</item><item>
<title>Joe Gregorio | BitWorking : 140 characters isn\&#039;t enough | BitWorking | Joe Gregorio</title>
<link>http://bitworking.org/news/2010/09/140-chars#IDComment101900484</link>
<description>Deleting your Twitter account would play havoc with your Lanyrd profile &lt;a href=&quot;http://lanyrd.com/people/jcgregorio/&quot; target=&quot;_blank&quot;&gt;http://lanyrd.com/people/jcgregorio/&lt;/a&gt; - I should probably figure out a way of dealing with that... :/ </description>
<pubDate>Sat, 2 Oct 2010 00:17:08 +0000</pubDate>
<guid>http://bitworking.org/news/2010/09/140-chars#IDComment101900484</guid>
</item><item>
<title>drstarcat.com : Why an OAuth iframe is a Great Idea</title>
<link>http://drstarcat.com/archives/133#IDComment27476369</link>
<description>You&amp;#039;re right that redirects alone aren&amp;#039;t the answer - OpenID has suffered from this same phishing problem for years, any time you have an untrusted site that&amp;#039;s meant to redirect you to a trusted one there&amp;#039;s potential for trouble.  In the long-run, the solution lies with the browsers. My browser should understand OAuth (and OpenID) and provide un-spoofable chrome confirming that I&amp;#039;m on the correct site.  That&amp;#039;s another argument for sticking with the redirect though - if sites are using the redirect, browsers can start adding their own level of protection and it will Just Work with existing OAuth deployments. </description>
<pubDate>Fri, 17 Jul 2009 00:11:30 +0000</pubDate>
<guid>http://drstarcat.com/archives/133#IDComment27476369</guid>
</item><item>
<title>drstarcat.com : Why an OAuth iframe is a Great Idea</title>
<link>http://drstarcat.com/archives/133#IDComment27456229</link>
<description>Posted a bit more about this here: &lt;a href=&quot;http://simonwillison.net/2009/Jul/16/responsibility/&quot; target=&quot;_blank&quot;&gt;http://simonwillison.net/2009/Jul/16/responsibili...&lt;/a&gt; - including a call for OAuth providers to add frame-busting JavaScript to their authorisation pages. </description>
<pubDate>Thu, 16 Jul 2009 19:07:14 +0000</pubDate>
<guid>http://drstarcat.com/archives/133#IDComment27456229</guid>
</item>	</channel>
</rss>