<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Technosailor.com &#187; oauth</title>
	<atom:link href="http://technosailor.com/tag/oauth/feed/" rel="self" type="application/rss+xml" />
	<link>http://technosailor.com</link>
	<description>Business and Technology with Common Sense</description>
	<lastBuildDate>Wed, 08 Feb 2012 17:54:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4-alpha-19888</generator>
		<item>
		<title>Twitter Phishing: Protecting Yourself</title>
		<link>http://technosailor.com/2009/01/05/twitter-phishing-protecting-yourself/</link>
		<comments>http://technosailor.com/2009/01/05/twitter-phishing-protecting-yourself/#comments</comments>
		<pubDate>Mon, 05 Jan 2009 16:34:40 +0000</pubDate>
		<dc:creator>Aaron</dc:creator>
				<category><![CDATA[Aaron Brazell]]></category>
		<category><![CDATA[chris pirillo]]></category>
		<category><![CDATA[oauth]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[Twitter.com]]></category>

		<guid isPermaLink="false">http://technosailor.com/?p=7210</guid>
		<description><![CDATA[A funny thing happened on the way to the forum. Or at least, a funny thing happened over the weekend with regards to Twitter, spam and phishing (from Chris Pirillo). I really had no plans to outline my thoughts on &#8230; <a href="http://technosailor.com/2009/01/05/twitter-phishing-protecting-yourself/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>A funny thing happened on the way to the forum. Or at least, a funny thing happened over the weekend with regards to Twitter, spam and phishing (from <a href="http://chris.pirillo.com/2009/01/03/phishing-scam-spreading-on-twitter/">Chris Pirillo</a>). I really had no plans to outline my thoughts on the scam, because <a href="http://venturebeat.com/2009/01/03/warning-someone-is-phishing-on-twitter/">it is</a> <a href="http://blog.twitter.com/2009/01/gone-phishing.html">already being</a> <a href="http://www.chrisbrogan.com/log-into-twitter-and-change-your-password/">covered</a> <em>ad nauseum</em>. However, I feel like I have to anyway.</p>
<p>The scam operates like any typical Windows worm and begins with a DM from a victimized Twitter follower. That direct message contains a link to a malicious (and unnamed) domain that screams &#8220;password stealing&#8221;. Nevertheless, gullible Twitter users click on the link and enter a page that looks an awful lot like the Twitter.com login screen (okay, it looks identical). The user enters login information thinking they are logging into Twitter and, in the blink of the eye, a malicious site has access to your Twitter account information.</p>
<p><img src="http://technosailor.com/files/215693116_8e4a24d11c_m.jpg" alt="215693116_8e4a24d11c_m" class="alignleft size-full wp-image-7211 frame" height="240" width="189"><strong>This is a very important concept to get. The user inadvertently gives Twitter account login information to a malicious site. I will rail more on this concept in a bit. Keep it in your mind.</strong></p>
<p>The malicious site then proceeds to send DMs with the infectious link on behalf of the user. I have gotten seven of these in the past 24 hours.</p>
<p>Folks, Twitter is like email. You can be infected by the innocence of friends, Please be careful. You really don&#8217;t want a malicious sites having access to confidential business ideas, your common and unchanging password that you use everywhere, or intoxicatingly passionate messages to your lover. Be wary of this scam and tread lightly. If you get a message like this, contact the sender and advise them to <a href="http://twitter.com/account/password">change their password</a> immediately. Unlike email worms, you cannot be affected by merely <em>looking</em> at the DM &#8211; only by clicking the link.</p>
<p>There are several problems here, as there are with most internet security problems. One is the technical problem (site can login and perform actions on your behalf). The other is a psychological problem (Twitter users giving away their username and password to untested, unvetted and untrusted third parties).</p>
<p>Twitter promises that they are working on a solution to the technical problem and that it will look like some form of OAuth, an authentication protocol similar to <a href="http://openid.org/">OpenID</a> for application to application authentication. <a href="http://oauth.net/">OAuth</a>, when instituted, promises to provide a passwordless trust and authentication framework that should solve the problem that requires third party Twitter apps to request a users login information. However, for all their promises and the urgency that is increasing among developers, Twitter does not seem to be in a hurry to provide this protocol.</p>
<p>Additionally, computer users have been relentlessly brainwashed by anti-virus companies, corporate computing policies and other persistent reminders, to adhere to basic security practices. Don&#8217;t open attachments from unknown users. Run anti-virus. Use hard to guess passwords and change them often. And so on. And so forth. Folks, these concepts are basic life-guiding principles and apply on the web too. Don&#8217;t give away your username and password to anyone. Ever. Unless they are vetted and trusted by you and you understand what the ramifications are.</p>
<p>In the absence of an OAuth-style technical release from Twitter, and the lack of consistent user discipline, it is my recommendation that Twitter users no longer provide third party apps with their login information, regardless of how compelling the app is. It is not safe and it is an unwise security practice that flies in the face of everything you have been learning for years when it comes to your own personal computing practices. Twitter apps are defined as anything Twitter related that is not directly on the twitter.com domain.</p>
<p>Maybe Twitter will get serious about their security here.</p>
<p><em>Photo Credit: <a href="http://flickr.com/photos/dinobirdo/215693116/">dinobirdo</a></em></p>
]]></content:encoded>
			<wfw:commentRss>http://technosailor.com/2009/01/05/twitter-phishing-protecting-yourself/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:thumbnail url="http://technosailor.com/files/215693116_8e4a24d11c_m.jpg" />
		<media:content url="http://technosailor.com/files/215693116_8e4a24d11c_m.jpg" medium="image">
			<media:title type="html">215693116_8e4a24d11c_m</media:title>
		</media:content>
	</item>
		<item>
		<title>The Xbox Experience: A Great Improvement That Still Lacks</title>
		<link>http://technosailor.com/2008/11/24/the-xbox-experience-a-great-improvement-that-still-lacks/</link>
		<comments>http://technosailor.com/2008/11/24/the-xbox-experience-a-great-improvement-that-still-lacks/#comments</comments>
		<pubDate>Mon, 24 Nov 2008 17:23:24 +0000</pubDate>
		<dc:creator>Aaron</dc:creator>
				<category><![CDATA[Aaron Brazell]]></category>
		<category><![CDATA[api]]></category>
		<category><![CDATA[bizspark]]></category>
		<category><![CDATA[developers]]></category>
		<category><![CDATA[exchange server]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[netflix]]></category>
		<category><![CDATA[oauth]]></category>
		<category><![CDATA[open social]]></category>
		<category><![CDATA[openaim]]></category>
		<category><![CDATA[sharepoint]]></category>
		<category><![CDATA[social network]]></category>
		<category><![CDATA[xbox]]></category>
		<category><![CDATA[xbox 360]]></category>
		<category><![CDATA[xbox experience]]></category>

		<guid isPermaLink="false">http://technosailor.com/?p=5230</guid>
		<description><![CDATA[Microsoft is clearly getting hipper with their offerings. The company that has been notoriously committed to offline products, like their Windows operating System and productivity suite, Microsoft Office, to the detriment of their online offerings seems to definitely be moving &#8230; <a href="http://technosailor.com/2008/11/24/the-xbox-experience-a-great-improvement-that-still-lacks/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Microsoft is clearly getting hipper with their offerings. The company that has been notoriously committed to offline products, like their Windows operating System and productivity suite, Microsoft Office, to the detriment of their online offerings seems to definitely be moving into the internet space more. They are, in fact, trying to own the online space now which is a significant internal company departure from the past.</p>
<p>As recently as yesterday, speculation was that the ill-branded <a href="http://www.live.com/">Live! Search</a> could be <a href="http://www.techcrunch.com/2008/11/23/microsoft-to-rebrand-search-will-it-be-kumo/">rebranded in a much more internet friendly way</a>. Kumo.com anyone? Their IM client&#8230; well, no one uses it.</p>
<p><a href="http://technosailor.com/files/xbox-360-logo.jpg"><img class="frame alignleft size-full wp-image-5231" src="http://technosailor.com/files/xbox-360-logo.jpg" alt="xbox-360-logo" width="200" height="135" /></a>Of course, they have jumped headfirst into the incubation industry by launching <a href="http://www.microsoft.com/bizspark/">BizSpark</a>, which seeks to provide promising young companies with technical resources, such as their server offerings, and human and business resources to help these investment companies, mostly web based startups, become viable.</p>
<p>Naturally, one of the odd players in the Microsoft ecosystem has been the Xbox 360 platform. It is a killer gaming platform (I am an avid Xbox Gamer) and their online gameplay over Xbox Live is second to none. It has always lacked any kind of cohesion for an online service though. Especially in 2008, where Facebook and Twitter rule the day and it is rare to find someone who is <em>not</em> on some kind of social networking platform.</p>
<p>So a few months ago, when word leaked out about a complete overhaul to the Xbox Live experience, there were many of us who were excited about a modernization with significant incorporation of social networking elements. With the launch the other day, some of that has been delivered.</p>
<p>The Xbox Experience, as it&#8217;s called, is a significantly streamlined dashboard making it extremely easy to access common items, such as the Xbox Marketplace. Incorporation of online video giant, also dabbling in the social networking space, <a href="http://netflix.com">Netflix</a> makes the Experience worlds better. It is possible to watch Netflix &#8220;Instant Play&#8221; queue items directly via your Xbox Dashboard. Sweet, if the video quality was better. Putting this aside, the mashup is a great step in making the Xbox an entertainment hub.</p>
<p>However, significant issues remain. A &#8220;big bling&#8221; element to the new <a href="http://www.xbox.com/en-US/live/nxe/">Xbox Experience</a>, is the new avatars. Going through a wizard the first time I logged in, reminded me a bit of creating your Tiger Woods 2008 character. Though this is fine in creating a personalized environment, I find no purpose for an avatar except to snap a proverbial photo and making that photo your &#8220;avatar photo&#8221;. I would much rather designate an actual graphic or picture as my avatar, in much of the same way most social networks allow you to.</p>
<p>The storyline falls apart more when you login to manage your Xbox Live account from the web and discover they have not incorporated any further way of getting at your data. Microsoft would do well to develop robust APIs that would allow players to get an XML or JSON feed of achievements, gamerscores, last/currently played games as well as other social network elements.</p>
<p>Why not provide a much more efficient &#8220;friends&#8221; method that would allow players to have wish lists, friend challenges, friend groups, as well as a unique element I call &#8220;tip sharing&#8221;. Tip sharing would be a forum element where a friend could share intel about a game (say <em>Fallout 3</em>) and I could &#8220;download&#8221; that tip into my Xbox Live user account. When I reach the Farrugut West Metro station in <em>Fallout 3</em> and my friend has discovered something, the game could feed me that intel from a friend.</p>
<p>Another social element would be the concept of a &#8220;lifeline&#8221; where, if I&#8217;m stuck during a game, I could get immediate assistance (in-game or otherwise) from my friends through screen sharing, instant message (kill Live! Messenger and use <a href="http://dev.aol.com/aim">OpenAIM</a>, please) or other &#8220;helper&#8221; element.</p>
<p>Let&#8217;s make it really social and make it possible for gamers to find other gamers in their area and schedule times together (if you have to, use a modified, online, lite version of <a href="http://www.microsoft.com/sharepoint/default.mspx">Sharepoint</a> or <a href="http://www.microsoft.com/exchange/default.mspx">Exchange Server</a> to make this happen).</p>
<p>Of course, a natural tie together, via <a href="http://www.opensocial.org/">OpenSocial</a>, with other social networks, possible use of <a href="http://oauth.net/">OAuth</a> for data access and login, status messaging and comment, and other &#8220;social elements&#8221; would really flesh the Xbox Experience as <em>useful</em> in 2008.</p>
<p>What are your thoughts on the Xbox Experience?</p>
]]></content:encoded>
			<wfw:commentRss>http://technosailor.com/2008/11/24/the-xbox-experience-a-great-improvement-that-still-lacks/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:thumbnail url="http://technosailor.com/files/xbox-360-logo.jpg" />
		<media:content url="http://technosailor.com/files/xbox-360-logo.jpg" medium="image">
			<media:title type="html">xbox-360-logo</media:title>
		</media:content>
	</item>
		<item>
		<title>Facebook se enfrenta a OpenSocial</title>
		<link>http://technosailor.com/2007/12/16/facebook-se-enfrenta-a-opensocial/</link>
		<comments>http://technosailor.com/2007/12/16/facebook-se-enfrenta-a-opensocial/#comments</comments>
		<pubDate>Sun, 16 Dec 2007 12:18:19 +0000</pubDate>
		<dc:creator>Aaron</dc:creator>
				<category><![CDATA[guest blogging]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[microformats]]></category>
		<category><![CDATA[networks-sociales]]></category>
		<category><![CDATA[oauth]]></category>
		<category><![CDATA[openfacebook]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[opensocial]]></category>
		<category><![CDATA[platformarchitecture]]></category>
		<category><![CDATA[social-networks]]></category>
		<category><![CDATA[socnets]]></category>
		<category><![CDATA[true-network-portability]]></category>
		<category><![CDATA[xfn]]></category>

		<guid isPermaLink="false">http://technosailor.com/2007/12/16/facebook-se-enfrenta-a-opensocial/</guid>
		<description><![CDATA[Facebook ha decidido ofrecer su plataforma de programaciÃ³n al resto de los networks sociales, picÃ¡ndole adelante a Google y su esperado OpenSocial. Google OpenSocial surgiÃ³ como una respuesta a la Plataforma Facebook, ofreciéndole al resto de los networks sociales la &#8230; <a href="http://technosailor.com/2007/12/16/facebook-se-enfrenta-a-opensocial/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://facebook.com" title="Facebook">Facebook</a> ha decidido ofrecer su plataforma de programaciÃ³n al resto de los networks sociales, <strong>picÃ¡ndole adelante</strong> a <a href="http://google.com/" title="Google">Google</a> y su esperado <a href="http://code.google.com/apis/opensocial/" title="OpenSocial">OpenSocial</a>.</p>
<p>Google OpenSocial surgiÃ³ como una respuesta a la <a href="http://wiki.developers.facebook.com/index.php/Main_Page" title="Wiki de Desarrollo de Facebook">Plataforma Facebook</a>, ofreciéndole al resto de los networks sociales la oportunidad de crear aplicaciones que pudieran inter-operar entre los distintos sitios. Pero OpenSocial todavÃ­a no estÃ¡ listo y aÃºn falta mucho por definir sobre su funcionamiento.</p>
<p>Facebook responde ahora con <a href="http://wiki.developers.facebook.com/index.php/PlatformArchitecture" title="Facebook PlatformArchitecture">PlatformArchitecture</a>, permitiéndole a cualquier website <strong>aprovechar el lenguaje de programaciÃ³n de Facebook</strong>. De este modo, cualquier website podrÃ¡ ofrecer a sus usuarios gran cantidad de aplicaciones que ya existen para Facebook.</p>
<p>Estas iniciativas permiten que usuarios de networks sociales utilicen servicios ofrecidos por otros websites (<a href="http://www.ilike.com/" title="iLike">iLike</a>, por ejemplo) y que compartan experiencias con miembros de su mismo network social (<a href="http://www.facebook.com/apps/application.php?id=2341504841&amp;ref=s" title="Facebook Zombies">Zombie</a>, <a href="http://www.facebook.com/apps/application.php?id=2424357634" title="Facebook MyAquarium">Acuario</a>, etc).</p>
<p>Lo que falta es una herramienta que permita a los usuarios de un network social interactuar con los usuarios de otro network social. <a href="http://openid.net/" title="OpenID">OpenID</a>, <a href="http://oauth.net/" title="OAuth">OAuth</a> y <a href="http://gmpg.org/xfn/" title="XFN">XFN</a> son tres iniciativas encaminadas a lograr esto, pero que necesitan ser simplificadas (Â¿con deNerd-a-tex?) para poder ser entendidas y utilizadas por el grueso de la poblaciÃ³n.</p>
<p>Si te interesa saber mÃ¡s sobre estas tres iniciativas, <strong>déjanos un comentario</strong> aquÃ­ en la pÃ¡gina y desarrollaremos el tema en una columna futura.</p>
]]></content:encoded>
			<wfw:commentRss>http://technosailor.com/2007/12/16/facebook-se-enfrenta-a-opensocial/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
	</item>
	</channel>
</rss>

