OAuth is not an Identity Protocol

Discussion among Don Thibeau, Dave Kearns, and Justin Richer
1
Don Thibeau @4thibeau

Open Idenity Standard Wins...European Identity & Cloud Award 2013: OAuth 2.0 - 70778 - KuppingerCole: http://t.co/jXfJpT8HAh

2013-05-16 16:07:22
Don Thibeau @4thibeau

Open Idenity Standard Wins...European Identity & Cloud Award 2013: OAuth 2.0 - 70778 - KuppingerCole: http://t.co/jXfJpT8HAh

2013-05-16 16:07:22
Justin Richer Ⓥ @justin__richer

@4thibeau Hey, OAuth is *NOT* an identity protocol! People thinking that it is one is one of the most common misconceptions I correct.

2013-05-17 09:37:47
Dave Kearns @dak3

Me too how can an "authorization protocol" not be an ID protocol? RT @4thibeau @zer0n1ne please educate me

2013-06-27 07:28:40
Justin Richer Ⓥ @justin__richer

@dak3 @4thibeau OAuth does authorization which has little to do with identity, identity requires authentication and profile data. (1/2)

2013-06-27 10:10:53
Justin Richer Ⓥ @justin__richer

@dak3 @4thibeau Also the talk I gave at MIT this past winter covers this as well at about 14m in: http://t.co/orDYU5LKjR (3/2)

2013-06-27 10:18:47
拡大
Dave Kearns @dak3

@zer0n1ne AuthZ and AuthN are two sides of the same ID coin see http://t.co/QOlH4i1Ujr @4thibeau

2013-06-27 12:12:51
Justin Richer Ⓥ @justin__richer

@dak3 @4thibeau That presumes authz is binary and total, which is a flawed assumption. AuthN is just one context in which AuthZ works.

2013-06-27 12:16:36
Justin Richer Ⓥ @justin__richer

@dak3 @4thibeau ...uh, yes, I did. Did you read mine? And my point was that AuthZ can happen in contexts other than AuthN.

2013-06-27 12:20:24