







archived 12 Sep 2024 15:19:57 UTC
Does OpenID need to be hard?
Prompted by posts by Randy Reddig and Tony Stubblebine and a conversation with Elliott Kember, I wanted to address, yet again, the big fat stinking elephant in the room: OpenID usability and the pa…

⠠⠵ avuko (@avuko@infosec.exchange)
@elena@aseachange.com @aral@mastodon.ar.al I couldn't resist, so I've wasted my precious time looking at "W Identity" today. Things are not right. It is basically a repurposed https://github.com/PeterWaher/IoTGateway Just look here: https://root.widentity.eu/Settings/Master.md It has a socks4(?) open on port 1080, some xmpp stuff on 5222 and 5269, another (seemingly broken) version of the website on 8088. The following pages are accessible without auth: (found by a simple "`egrep -LR 'Privilege:|Login:' * |grep md | grep Root`" through the source) ``` /Settings/PersonalData/LocalDatabase.md /Settings/PersonalData/LocalSensorsAndDevices.md /Settings/PersonalData/EventLogs.md /Settings/PersonalData/NetworkIdentity.md /Settings/PersonalData/WebPages.md /Settings/PersonalData/Backups.md /Settings/Master.md /Copyright.md /Starting.md [http response 307] /Login.md /Entities.md /Templates/Repeat.md /AdminDropdownComponent.md /Script.md /AdminDropdown.md /AlertPopup.md /Master.md /PromptPopup.md /ConfirmPopup.md /Markdown.md /Emojis.md /Smileys.md /Index.md /MarkdownEditor.md /ScriptColors.md /Master.md ``` Others pages also exist (no 404), but are only available after login. Which brings me to the biggest problem of all. This is an **ADMIN** interface. Nobody should **ever** put an admin interface to an identity management platform on the internet. #WSocial #Widentity
OWID Homepage
Research and data to make progress against the world’s largest problems

rip.so :: the digital graveyard
A memorial to the messengers, social networks, browsers and websites the internet forgot.

AI Might Be Our Best Shot At Taking Back The Open Web
I remember, pretty clearly, my excitement over the early World Wide Web. I had been on the internet for a year or two at that point, mostly using IRC, Usenet, and Gopher (along with email, naturall…

WebID - W3C Wiki
The W3C is still exploring better ways to do authentication, for example in the 2014 workshop on authentication. The WebID is a Community Group, and anyone can start a Community Group. A Community Group does not necessarily reflect the endorsement of the W3C, but we encourage grassroots communities to experiment with technology that may become a future standard.
The Cyber Resilience Act: A Five Alarm Fire
On October 21, 2016, CNN’s website was knocked offline. So was the BBC and Guardian’s. Amazon, Etsy and Shopify too, along with Quora, Reddit, and Twitter – among others. Huge swaths of the internet were taken down by a series of attacks on the DNS provider Dyn. These Distributed Denial of Service (DDoS) attacks were

Open Social Web ID - Erlend’s notes
Approaching a shared method of single sign-on for the entire open social web.
Exclusive-OpenAI agents hijacked German website in previously undisclosed AI breakout this spring
SAN FRANCISCO, Sept 4 : A swarm of rogue OpenAI agents hijacked a German website this spring and transformed it into a bulletin board for other AI agents, according to new research published Friday and two people familiar with the matter.OpenAI officials learned of the incident weeks ago but kept it under wra
The Internet is a Series of Webs
The fate of the open web is inextricable from the other ways our world is in crisis. What can we do about it?

What's verification on the open social web for? With @gui.do and @emily.space we put together a draft statement and roadmap for democratic account verification. For everyone, without IDs. The draft is here, please contribute and comment. Open until 31 May tangled.org/sherif.eurosky.social/atmosph…
Really feels like the open Internet is falling apart, with bsky as a rare bright spot.
Ashton Pittman
The New York Times is now blocking The Wayback Machine from accessing its articles. That means you'll no longer be able to view archived versions of NYT stories published in 2026 and beyond on archive.org. (All those posts you see tracking changes to NYT headlines and ledes? They relied on WBM).
@thisismissem.social @divy.zone and I recently went through an exploration of how the browser can help you login to websites with atproto accounts. We recently presented to the FedID CG and here is a sneak peek in case you couldn't join! This is early but we'd love your input before we go too far!
🦫 alert! We published the second episode of "Teach the Web new Tricks", featuring native support for @atproto.com ! Learn more how we improve user agency and privacy at webbeef.org/atproto.html : - Native at:// protocol support. - Log in your PDS and forget OAuth ! - Authorize 3rd parties
So many people do not get this. Atproto identity is the closest thing to original-flavor OpenID that has been done in years. It's not OpenID (it has problems OpenID didn't and solves problems OpenID had), but it's very much in that spirit.
hailey
i guess in a way this is the most widely used one, but also one that is severely underused in other ways. definitely identity. i've long been of the opinion that there are obviously cool things that come from public data and all the public pieces of the proto, but identity is higher impact.