@Sarah_Cecc Don’t music artists (or someone) get royalties every time their song is played on the radio? Is the argument that content is more like music?
I'm so looking forward to one of my favorite Identity conferences -> #Identiverse in Las Vegas May 28-31, 2024!
So much is happening in this space, you don't want to miss it! Use the code for 25% off https://t.co/zn68Re7Om7.
#CRAEvents#Networking#Identity#Identiverse2024
RFC9421 has officially been published, say hello to HTTP Message Signatures! Much thanks to everyone who contributed including my co-authors @annabellerings@manusporny
https://t.co/OmPARSZ8pV
Call for participation: demonstrate interoperability of your CAEP implementations at the @Gartner_inc Identity & Access Management Summit in London March 2024. Contact @zirotrust to participate with all details found here: https://t.co/nlIffvoW7Q #openid#sharedsignals#CAEP
The OpenID Foundation Shared Signals Framework (SSF) is an emerging and promising standard for sharing security signals between trusted parties. Learn more about the importance of the Shared Signals Framework: https://t.co/WyKodMIwFm #openid#sharedsignals
What’s New in the Shared Signals Framework? A new Implementer's Draft has been released for public review and here’s how it is different from the previous version: https://t.co/Pi9SWnvjPO #openid#sharedsignals
@nguyengiabk I see a couple of options for the AS… 1) logout the existing session and start a new registration flow, 2) tell the user they are already logged in and send them back to the RP, 3) ask the user what they want to do. There are of course security considerations for each option:)
Official links to "new" work within the OIDC working group:
Native SSO for Mobiles apps - https://t.co/d2QJ0JBPqx
* provides a back-channel way to share identity between apps write by the same company
Prompt=create - https://t.co/2uI4yBk3A3
* Extension to trigger registration
@nguyengiabk The specification says that it’s up to the AS how it wants to handle that situation. Section 4.1 says “Whether the AS creates a brand new identity or helps the user authenticate an identity they already have is out of scope for this specification.”
What did strike me this #iiw is the term micro-ceremonies. We need more focus on the user experience and how to optimize that and not just focus on the technical aspects.
Not original with me… Authentication is just part of the Authorization policy. Historically it has been easier to authenticate a user first as it is a requirement in most of the AuthZ policies. Instead of one big AuthN ceremony what we need are micro-ceremonies as part of AuthZ
Not sure what the scam here is but I’ve gotten the exact (word for word) message from two different “people” supposedly interested in purchasing my photographic work:-)
Dilemma: wait in the pre-check line so I don’t have to take off my shoes and pull out my electronics or go to normal security and probably breeze through:-)
I've been invited to be on a few more podcasts to talk about my new book Learning Digital Identity from O'Reilly Media. That's one of the perks of writing a book. People like to talk about it. I always enjoy talking about identity and especially how it's so vital to the quality of our lives in the digital world, so I'm grateful these groups found time to speak with me. https://t.co/IRueYdoWRe
The Foundation is pleased to announce that version 1.1 of the “Government-Issued Digital Credentials and the Privacy Landscape” whitepaper has been published incorporating changes requested by the OIDF and partner organizations that co-branded the paper: https://t.co/CuZo5GFVUm
Registration is now open for the OIDF hybrid workshop on Monday, October 9, 2023. Thank you to @Cisco for hosting us! All workshop details including a registration (required) link can be found here: https://t.co/iCSSr7zw3c