<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Pomcor</title>
	<atom:link href="http://pomcor.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://pomcor.com</link>
	<description>Research in Web Technology</description>
	<lastBuildDate>Wed, 16 May 2012 21:43:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>Comment on Pros and Cons of U-Prove for NSTIC by Vadym F</title>
		<link>http://pomcor.com/2011/10/04/pros-and-cons-of-u-prove-for-nstic/#comment-104</link>
		<dc:creator>Vadym F</dc:creator>
		<pubDate>Wed, 16 May 2012 21:43:00 +0000</pubDate>
		<guid isPermaLink="false">http://pomcor.com/?p=321#comment-104</guid>
		<description>Regarding overhead of interval proof: it was suggested in the thesis to prove (0,1) bits of powers-of-2, while a better protocol was designed from Lagrange theorem. That is, representing any natural number with 4 squares. Well, one generally needs a group of an order not known to Prover to prove statements about integers.

It would be fair to note powers-of-2 approach is only reasonable with current U-Prove implementing groups of a known prime order q.
Overhead would go away with groups of a hidden order, if ever available in U-Prove.</description>
		<content:encoded><![CDATA[<p>Regarding overhead of interval proof: it was suggested in the thesis to prove (0,1) bits of powers-of-2, while a better protocol was designed from Lagrange theorem. That is, representing any natural number with 4 squares. Well, one generally needs a group of an order not known to Prover to prove statements about integers.</p>
<p>It would be fair to note powers-of-2 approach is only reasonable with current U-Prove implementing groups of a known prime order q.<br />
Overhead would go away with groups of a hidden order, if ever available in U-Prove.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pros and Cons of Idemix for NSTIC by Francisco Corella</title>
		<link>http://pomcor.com/2011/10/10/pros-and-cons-of-idemix-for-nstic/#comment-103</link>
		<dc:creator>Francisco Corella</dc:creator>
		<pubDate>Sun, 26 Feb 2012 22:50:00 +0000</pubDate>
		<guid isPermaLink="false">http://pomcor.com/?p=339#comment-103</guid>
		<description>This post was also discussed on the &lt;a href=&quot;http://lists.idcommons.net/lists/arc/community/&quot; rel=&quot;nofollow&quot;&gt;Identity Commons Mailing List&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>This post was also discussed on the <a href="http://lists.idcommons.net/lists/arc/community/" rel="nofollow">Identity Commons Mailing List</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Are Privacy-Enhancing Technologies Really Needed for NSTIC? by Francisco Corella</title>
		<link>http://pomcor.com/2011/10/13/are-privacy-enhancing-technologies-really-needed-for-nstic/#comment-102</link>
		<dc:creator>Francisco Corella</dc:creator>
		<pubDate>Sun, 26 Feb 2012 22:49:00 +0000</pubDate>
		<guid isPermaLink="false">http://pomcor.com/?p=350#comment-102</guid>
		<description>This post was discussed on the &lt;a href=&quot;http://lists.idcommons.net/lists/arc/community/&quot; rel=&quot;nofollow&quot;&gt;Identity Commons Mailing List&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>This post was discussed on the <a href="http://lists.idcommons.net/lists/arc/community/" rel="nofollow">Identity Commons Mailing List</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Deployment and Usability of Cryptographic Credentials by Francisco Corella</title>
		<link>http://pomcor.com/2011/10/16/deployment-and-usability-of-cryptographic-credentials/#comment-101</link>
		<dc:creator>Francisco Corella</dc:creator>
		<pubDate>Sun, 26 Feb 2012 22:49:00 +0000</pubDate>
		<guid isPermaLink="false">http://pomcor.com/?p=361#comment-101</guid>
		<description>This post was discussed on the &lt;a href=&quot;http://lists.idcommons.net/lists/arc/community/&quot; rel=&quot;nofollow&quot;&gt;Identity Commons Mailing List&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>This post was discussed on the <a href="http://lists.idcommons.net/lists/arc/community/" rel="nofollow">Identity Commons Mailing List</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Credential Sharing: A Pitfall of Anonymous Credentials by Francisco Corella</title>
		<link>http://pomcor.com/2011/12/19/credential-sharing-a-pitfall-of-anonymous-credentials/#comment-100</link>
		<dc:creator>Francisco Corella</dc:creator>
		<pubDate>Sun, 26 Feb 2012 22:39:00 +0000</pubDate>
		<guid isPermaLink="false">http://pomcor.com/?p=406#comment-100</guid>
		<description>This blog post was discussed in the  &lt;a href=&quot;http://lists.idcommons.net/lists/arc/community&quot; rel=&quot;nofollow&quot;&gt;Identity Commons Mailing List&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>This blog post was discussed in the  <a href="http://lists.idcommons.net/lists/arc/community" rel="nofollow">Identity Commons Mailing List</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on OpenID Providers Invited to Join in an NSTIC Pilot Proposal by Francisco Corella</title>
		<link>http://pomcor.com/2012/02/10/openid-providers-invited-to-join-in-an-nstic-pilot-proposal/#comment-99</link>
		<dc:creator>Francisco Corella</dc:creator>
		<pubDate>Sun, 26 Feb 2012 22:31:00 +0000</pubDate>
		<guid isPermaLink="false">http://pomcor.com/?p=449#comment-99</guid>
		<description>This blog post was discussed in the &lt;a href=&quot;http://lists.openid.net/pipermail/openid-general/&quot; rel=&quot;nofollow&quot;&gt;OpenID General Discussion Mailing List&lt;/a&gt; and the &lt;a href=&quot;http://lists.idcommons.net/lists/arc/community&quot; rel=&quot;nofollow&quot;&gt;Identity Commons Mailing List&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>This blog post was discussed in the <a href="http://lists.openid.net/pipermail/openid-general/" rel="nofollow">OpenID General Discussion Mailing List</a> and the <a href="http://lists.idcommons.net/lists/arc/community" rel="nofollow">Identity Commons Mailing List</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on One-Click OpenID: A Solution to the NASCAR Problem by Francisco Corella</title>
		<link>http://pomcor.com/2012/02/13/one-click-openid-a-solution-to-the-nascar-problem/#comment-98</link>
		<dc:creator>Francisco Corella</dc:creator>
		<pubDate>Sun, 26 Feb 2012 22:25:00 +0000</pubDate>
		<guid isPermaLink="false">http://pomcor.com/?p=456#comment-98</guid>
		<description>This blog post was also discussed in the &lt;a href=&quot;http://lists.openid.net/pipermail/openid-general/&quot; rel=&quot;nofollow&quot;&gt;OpenID General Discussion Mailing List&lt;/a&gt; and the &lt;a href=&quot;http://lists.idcommons.net/lists/arc/community&quot; rel=&quot;nofollow&quot;&gt;Identity Commons Mailing List&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>This blog post was also discussed in the <a href="http://lists.openid.net/pipermail/openid-general/" rel="nofollow">OpenID General Discussion Mailing List</a> and the <a href="http://lists.idcommons.net/lists/arc/community" rel="nofollow">Identity Commons Mailing List</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Do-Not-Track and Third-Party Login by Francisco Corella</title>
		<link>http://pomcor.com/2011/11/06/do-not-track-and-third-party-login/#comment-97</link>
		<dc:creator>Francisco Corella</dc:creator>
		<pubDate>Sun, 26 Feb 2012 22:20:00 +0000</pubDate>
		<guid isPermaLink="false">http://pomcor.com/?p=388#comment-97</guid>
		<description>This blog post was discussed on the &lt;a href=&quot;http://lists.idcommons.net/lists/info/community&quot; rel=&quot;nofollow&quot;&gt;Identity Commons Mailing List&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p>This blog post was discussed on the <a href="http://lists.idcommons.net/lists/info/community" rel="nofollow">Identity Commons Mailing List</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on One-Click OpenID: A Solution to the NASCAR Problem by Francisco Corella</title>
		<link>http://pomcor.com/2012/02/13/one-click-openid-a-solution-to-the-nascar-problem/#comment-95</link>
		<dc:creator>Francisco Corella</dc:creator>
		<pubDate>Tue, 14 Feb 2012 05:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://pomcor.com/?p=456#comment-95</guid>
		<description>If you read the whole paragraph you&#039;ll see we are in agreement.  In OAuth the relying party has to preregister with the identity provider.  That&#039;s a BAD thing, because the user cannot freely choose any identity provider.  Since the user cannot choose freely, the problem of how to communicate a free choice doesn&#039;t come up.  So an OAuth relying party just shows one or two buttons with the logos of the identity providers (social sites) that it supports.  And the user is redirected to the identity provider with a single click.  What I&#039;m proposing provides the same one-click simplicity in OpenID, without sacrificing the freedom of choice proviced by OpenID.

To summarize: I do like OpenID better than OAuth :-)
</description>
		<content:encoded><![CDATA[<p>If you read the whole paragraph you&#8217;ll see we are in agreement.  In OAuth the relying party has to preregister with the identity provider.  That&#8217;s a BAD thing, because the user cannot freely choose any identity provider.  Since the user cannot choose freely, the problem of how to communicate a free choice doesn&#8217;t come up.  So an OAuth relying party just shows one or two buttons with the logos of the identity providers (social sites) that it supports.  And the user is redirected to the identity provider with a single click.  What I&#8217;m proposing provides the same one-click simplicity in OpenID, without sacrificing the freedom of choice proviced by OpenID.</p>
<p>To summarize: I do like OpenID better than OAuth <img src='http://pomcor.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on One-Click OpenID: A Solution to the NASCAR Problem by Andrew Arnott</title>
		<link>http://pomcor.com/2012/02/13/one-click-openid-a-solution-to-the-nascar-problem/#comment-94</link>
		<dc:creator>Andrew Arnott</dc:creator>
		<pubDate>Tue, 14 Feb 2012 04:30:00 +0000</pubDate>
		<guid isPermaLink="false">http://pomcor.com/?p=456#comment-94</guid>
		<description>&quot;OpenID. Unfortunately, this feature comes with a difficult challenge: how to provide the relying party with the information it needs to interact with the identity provider.  OAuth does not have this problem because the relying party has to preregister with the identity provider, ...&quot;  Wait what?  I think you&#039;ve got it backwards.  OpenID doesn&#039;t have the problems that OAuth has, because OpenID has discovery of Providers built-in, whereas OAuth has no such discovery built in.  </description>
		<content:encoded><![CDATA[<p>&#8220;OpenID. Unfortunately, this feature comes with a difficult challenge: how to provide the relying party with the information it needs to interact with the identity provider.  OAuth does not have this problem because the relying party has to preregister with the identity provider, &#8230;&#8221;  Wait what?  I think you&#8217;ve got it backwards.  OpenID doesn&#8217;t have the problems that OAuth has, because OpenID has discovery of Providers built-in, whereas OAuth has no such discovery built in.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

