Salta al contenuto
0
  • Home
  • Piero Bosio
  • Blog
  • Mondo
  • Fediverso
  • News
  • Categorie
  • Old Web Site
  • Recenti
  • Popolare
  • Tag
  • Utenti
  • Home
  • Piero Bosio
  • Blog
  • Mondo
  • Fediverso
  • News
  • Categorie
  • Old Web Site
  • Recenti
  • Popolare
  • Tag
  • Utenti
Skin
  • Chiaro
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Scuro
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Predefinito (Nessuna skin)
  • Nessuna skin
Collassa

Piero Bosio Social Web Site Personale Logo Fediverso

Social Forum federato con il resto del mondo. Non contano le istanze, contano le persone
  1. Home
  2. Categorie
  3. Fediverse
  4. Working to Decentralize FedCM

Working to Decentralize FedCM

Pianificato Fissato Bloccato Spostato Fediverse
fediverse
11 Post 6 Autori 80 Visualizzazioni
  • Da Vecchi a Nuovi
  • Da Nuovi a Vecchi
  • Più Voti
Rispondi
  • Risposta alla discussione
Effettua l'accesso per rispondere
Questa discussione è stata eliminata. Solo gli utenti con diritti di gestione possono vederla.
  • erlend_sh@lemmy.world
    erlend_sh@lemmy.world
    erlend_sh@lemmy.world
    scritto su ultima modifica di
    #1

    FedCM for the indieweb: https://blog.erlend.sh/indie-social-sign-in-could-go-mainstream

    povoq@slrpnk.net 1 Risposta Ultima Risposta
    0
    • erlend_sh@lemmy.world erlend_sh@lemmy.world

      FedCM for the indieweb: https://blog.erlend.sh/indie-social-sign-in-could-go-mainstream

      povoq@slrpnk.net
      povoq@slrpnk.net
      povoq@slrpnk.net
      scritto su ultima modifica di
      #2

      Sounds good, but this FedCM seems to be basically a reinvention of Oauth2/OIDC. Even if it brings some minor improvements (credentials storage in the browser or so?), it seems dead on arrival given that there doesn't seem to be a strong dissatisfaction with how OIDC works. Or am I missing something?

      erlend_sh@lemmy.world thisismissem@hachyderm.io julian@activitypub.space 3 Risposte Ultima Risposta
      0
      • povoq@slrpnk.net povoq@slrpnk.net

        Sounds good, but this FedCM seems to be basically a reinvention of Oauth2/OIDC. Even if it brings some minor improvements (credentials storage in the browser or so?), it seems dead on arrival given that there doesn't seem to be a strong dissatisfaction with how OIDC works. Or am I missing something?

        erlend_sh@lemmy.world
        erlend_sh@lemmy.world
        erlend_sh@lemmy.world
        scritto su ultima modifica di
        #3

        What you’re missing is that OIDC is innately centralized and FedCM, in particular thanks to this work, isn’t.

        This is all building on or complementing the same underlying OAuth standards, like the CIMD spec that Emelia originally intended for adoption into Mastodon/ActivityPub to set the stage for decentralized OAuth, but it was never brought in. The AT protocol on the other hand adopted it into their decentralized oauth-atproto standard, which is on track to become a protocol-agnostic oauth-dweb standard.

        Anyone who cares about decentralized software should be dissatisfied with how OIDC works. If you wanna use your primary fediverse account to log into other fedi apps, this work is for you.

        povoq@slrpnk.net psycotica0@lemmy.ca 2 Risposte Ultima Risposta
        0
        • povoq@slrpnk.net povoq@slrpnk.net

          Sounds good, but this FedCM seems to be basically a reinvention of Oauth2/OIDC. Even if it brings some minor improvements (credentials storage in the browser or so?), it seems dead on arrival given that there doesn't seem to be a strong dissatisfaction with how OIDC works. Or am I missing something?

          thisismissem@hachyderm.io
          thisismissem@hachyderm.io
          thisismissem@hachyderm.io
          scritto su ultima modifica di
          #4

          @poVoq @fediverse there's also a proposal (from google) for IdP Initiated FedCM, instead of relying party initiated

          1 Risposta Ultima Risposta
          0
          • erlend_sh@lemmy.world erlend_sh@lemmy.world

            What you’re missing is that OIDC is innately centralized and FedCM, in particular thanks to this work, isn’t.

            This is all building on or complementing the same underlying OAuth standards, like the CIMD spec that Emelia originally intended for adoption into Mastodon/ActivityPub to set the stage for decentralized OAuth, but it was never brought in. The AT protocol on the other hand adopted it into their decentralized oauth-atproto standard, which is on track to become a protocol-agnostic oauth-dweb standard.

            Anyone who cares about decentralized software should be dissatisfied with how OIDC works. If you wanna use your primary fediverse account to log into other fedi apps, this work is for you.

            povoq@slrpnk.net
            povoq@slrpnk.net
            povoq@slrpnk.net
            scritto su ultima modifica di
            #5

            OIDC isn't "innately centralized", thats just how the majority of people use it. And the same will be likely true for FedCM.

            1 Risposta Ultima Risposta
            0
            • erlend_sh@lemmy.world erlend_sh@lemmy.world

              What you’re missing is that OIDC is innately centralized and FedCM, in particular thanks to this work, isn’t.

              This is all building on or complementing the same underlying OAuth standards, like the CIMD spec that Emelia originally intended for adoption into Mastodon/ActivityPub to set the stage for decentralized OAuth, but it was never brought in. The AT protocol on the other hand adopted it into their decentralized oauth-atproto standard, which is on track to become a protocol-agnostic oauth-dweb standard.

              Anyone who cares about decentralized software should be dissatisfied with how OIDC works. If you wanna use your primary fediverse account to log into other fedi apps, this work is for you.

              psycotica0@lemmy.ca
              psycotica0@lemmy.ca
              psycotica0@lemmy.ca
              scritto su ultima modifica di
              #6

              OIDC is innately centralized

              Huh, that's not my understanding. I was there when it first came out, and the whole point was to allow you to use any URI of your choice as an authenticator. Let's see what the first line of Wikipedia has to say:

              OpenID is an open standard and decentralized authentication protocol

              Huh. 🤔

              erlend_sh@lemmy.world povoq@slrpnk.net 2 Risposte Ultima Risposta
              0
              • psycotica0@lemmy.ca psycotica0@lemmy.ca

                OIDC is innately centralized

                Huh, that's not my understanding. I was there when it first came out, and the whole point was to allow you to use any URI of your choice as an authenticator. Let's see what the first line of Wikipedia has to say:

                OpenID is an open standard and decentralized authentication protocol

                Huh. 🤔

                erlend_sh@lemmy.world
                erlend_sh@lemmy.world
                erlend_sh@lemmy.world
                scritto su ultima modifica di
                #7

                See what CIMD solves for. “Innately centralized” was probably a poor choice of words, but OIDC not a good fit for an open social web with decentralized identities and a plethora of small identity providers that cannot be known upfront.

                moonpiedumplings@programming.dev 1 Risposta Ultima Risposta
                0
                • psycotica0@lemmy.ca psycotica0@lemmy.ca

                  OIDC is innately centralized

                  Huh, that's not my understanding. I was there when it first came out, and the whole point was to allow you to use any URI of your choice as an authenticator. Let's see what the first line of Wikipedia has to say:

                  OpenID is an open standard and decentralized authentication protocol

                  Huh. 🤔

                  povoq@slrpnk.net
                  povoq@slrpnk.net
                  povoq@slrpnk.net
                  scritto su ultima modifica di
                  #8

                  You might be confusing the old OpenID with OIDC (short for Open ID Connect), which is based on Oauth2, an entirely different technology.

                  OpenID was definitely more decentralized compared to how OIDC is commonly used these days, but OIDC has various little know options to do similar things.

                  1 Risposta Ultima Risposta
                  0
                  • erlend_sh@lemmy.world erlend_sh@lemmy.world

                    See what CIMD solves for. “Innately centralized” was probably a poor choice of words, but OIDC not a good fit for an open social web with decentralized identities and a plethora of small identity providers that cannot be known upfront.

                    moonpiedumplings@programming.dev
                    moonpiedumplings@programming.dev
                    moonpiedumplings@programming.dev
                    scritto su ultima modifica di
                    #9

                    Forgejo has a feature (that people usually disable) where you can bring your own openid connect url and use it to auth. So if I have my own OIDC provider I am self hosting, I can just use that to log in.

                    Most people only use OIDC for google and microsoft and whatnot but it's very possible. I don't realkly see what FedCM offers that OIDC doesn't or can't, or why we shouldn't be adding features to the existing and popular OIDC instead.

                    erlend_sh@lemmy.world 1 Risposta Ultima Risposta
                    0
                    • moonpiedumplings@programming.dev moonpiedumplings@programming.dev

                      Forgejo has a feature (that people usually disable) where you can bring your own openid connect url and use it to auth. So if I have my own OIDC provider I am self hosting, I can just use that to log in.

                      Most people only use OIDC for google and microsoft and whatnot but it's very possible. I don't realkly see what FedCM offers that OIDC doesn't or can't, or why we shouldn't be adding features to the existing and popular OIDC instead.

                      erlend_sh@lemmy.world
                      erlend_sh@lemmy.world
                      erlend_sh@lemmy.world
                      scritto su ultima modifica di
                      #10

                      This requires manually enabling every additional provider. This doesn’t work if some individuals or smaller collectives wanna run their own identity providers, numbering in the thousands.

                      1 Risposta Ultima Risposta
                      0
                      • povoq@slrpnk.net povoq@slrpnk.net

                        Sounds good, but this FedCM seems to be basically a reinvention of Oauth2/OIDC. Even if it brings some minor improvements (credentials storage in the browser or so?), it seems dead on arrival given that there doesn't seem to be a strong dissatisfaction with how OIDC works. Or am I missing something?

                        julian@activitypub.space
                        julian@activitypub.space
                        julian@activitypub.space
                        scritto su ultima modifica di
                        #11

                        @thisismissem@hachyderm.io replied but it didn't make it over to Lemmy.

                        > @poVoq @fediverse there's also a proposal (from google) for IdP Initiated FedCM, instead of relying party initiated

                        1 Risposta Ultima Risposta
                        0

                        Ciao! Sembra che tu sia interessato a questa conversazione, ma non hai ancora un account.

                        Stanco di dover scorrere gli stessi post a ogni visita? Quando registri un account, tornerai sempre esattamente dove eri rimasto e potrai scegliere di essere avvisato delle nuove risposte (tramite email o notifica push). Potrai anche salvare segnalibri e votare i post per mostrare il tuo apprezzamento agli altri membri della comunità.

                        Con il tuo contributo, questo post potrebbe essere ancora migliore 💗

                        Registrati Accedi
                        Rispondi
                        • Risposta alla discussione
                        Effettua l'accesso per rispondere
                        • Da Vecchi a Nuovi
                        • Da Nuovi a Vecchi
                        • Più Voti


                        Feed RSS
                        Working to Decentralize FedCM
                        @pierobosio@soc.bosio.info
                        NodeBB Contributors
                        • Accedi

                        • Accedi o registrati per effettuare la ricerca.
                        • Primo post
                          Ultimo post