all messages for Guix-related lists mirrored at yhetil.org
 help / color / mirror / code / Atom feed
From: Felix Lechner via <help-guix@gnu.org>
To: Peter Polidoro <peter@polidoro.io>
Cc: Joshua Branson <jbranso@dismail.de>, help-guix@gnu.org
Subject: Re: mbsync with XOAUTH2 SASL mechanism
Date: Sun, 13 Nov 2022 14:00:52 -0800	[thread overview]
Message-ID: <CAFHYt55+Xs_Ee4GThbAh=0Hqmxzm_xDaDzS_sedDQnxK26+K4g@mail.gmail.com> (raw)
In-Reply-To: <10E9DE33-3EE1-45F9-A408-9D1C11CBEC46@polidoro.io>

Hi Peter,

On Sun, Nov 13, 2022 at 11:05 AM Peter Polidoro <peter@polidoro.io> wrote:
>
> I do not know if OAuth2 refers to something proprietary

While I cannot help much with your issue, the "Open Authentication"
standard is open--although too complex even for some insiders:

Eran Hammer resigned from his role of lead author for the OAuth 2.0
project, withdrew from the IETF working group, and removed his name
from the specification in July 2012. Hammer cited a conflict between
web and enterprise cultures as his reason for leaving, noting that
IETF is a community that is "all about enterprise use cases" and "not
capable of simple". "What is now offered is a blueprint for an
authorization protocol", he noted, "that is the enterprise way",
providing a "whole new frontier to sell consulting services and
integration solutions". In comparing OAuth 2.0 with OAuth 1.0,
Hammer points out that it has become "more complex, less
interoperable, less useful, more incomplete, and most importantly,
less secure". He explains how architectural changes for 2.0 unbound
tokens from clients, removed all signatures and cryptography at a
protocol level and added expiring tokens (because tokens could not be
revoked) while complicating the processing of authorization. Numerous
items were left unspecified or unlimited in the specification because
"as has been the nature of this working group, no issue is too small
to get stuck on or leave open for each implementation to decide."
(internal quotes removed) [1]

Kind regards
Felix Lechner

[1] https://en.wikipedia.org/wiki/OAuth


  reply	other threads:[~2022-11-13 22:02 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-11-01 15:13 mbsync with XOAUTH2 SASL mechanism Peter Polidoro
2022-11-13 18:27 ` Joshua Branson
2022-11-13 19:04   ` Peter Polidoro
2022-11-13 22:00     ` Felix Lechner via [this message]
2022-11-14 23:05   ` Tobias Geerinckx-Rice
2022-11-15 15:43   ` jbranso
2023-01-24 10:04 ` Giovanni Biscuolo
2023-01-24 12:41   ` Peter Polidoro
2023-01-25 17:51     ` Timo Wilken
2023-01-26 10:19       ` Giovanni Biscuolo
2023-01-26 18:15         ` Timo Wilken
2023-01-26 10:13   ` Giovanni Biscuolo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='CAFHYt55+Xs_Ee4GThbAh=0Hqmxzm_xDaDzS_sedDQnxK26+K4g@mail.gmail.com' \
    --to=help-guix@gnu.org \
    --cc=felix.lechner@lease-up.com \
    --cc=jbranso@dismail.de \
    --cc=peter@polidoro.io \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
Code repositories for project(s) associated with this external index

	https://git.savannah.gnu.org/cgit/guix.git

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.