[OAUTH-WG] Recap of two well known OAuth related attacks

2013-05-13 Thread Antonio Sanso
Hi *, I wrote a blog post showing two well known OAuth related attacks. I paste here the link for your consideration: http://intothesymmetry.blogspot.ch/2013/05/oauth-2-attacks-introducing-devil-wears.html Any comment is more than appreciated. Regards Antonio _

Re: [OAUTH-WG] Use of Version Control Systems for Draft Editing

2013-05-13 Thread Nat Sakimura
I am probably biased since I am the one who introduced ticket driven version control to OIDF but it proved to be very valuable especially for transparency purposes. Each changes are linked to the ticket so it is easy to see why that change was made. As to the comments v.s. mailing list relationshi

Re: [OAUTH-WG] Use of Version Control Systems for Draft Editing

2013-05-13 Thread Stephen Farrell
Hiya, On 05/13/2013 09:04 AM, Hannes Tschofenig wrote: > Hi all, > the OpenID Connect had gained some experience with using version control > systems > for editing specifications (and the use of issue trackers), see > http://openid.bitbucket.org/. Based on a recent discussion in the IETF (amon

[OAUTH-WG] Use of Version Control Systems for Draft Editing

2013-05-13 Thread Hannes Tschofenig
Hi all,    the OpenID Connect had gained some experience with using version control systems for editing specifications (and the use of issue trackers), see http://openid.bitbucket.org/. Based on a recent discussion in the IETF (among the working group chairs) I am wondering what your experience i