![John Bradley Profile](https://pbs.twimg.com/profile_images/1012753502836322305/ESMSObpD_x96.jpg)
John Bradley
@ve7jtb
Followers
3K
Following
1K
Statuses
3K
Identity stuff OpenID Foundation Board
iPhone: 29.986570,-95.352829
Joined March 2007
RT @openid: Fourth Implementer’s Draft of OpenID Federation Approved @RolandHedberg @selfissued @giusdemarc @dzhuv…
0
4
0
RT @selfissued: Continued refinement: OpenID Federation draft 33 published @openid @RolandHedberg @giusdemarc @dzhu…
0
3
0
RT @selfissued: Ten Years of OpenID Connect and Looking to the Future #OpenID #OpenIDConnect #TenYearsOfOpenIDConne…
0
8
0
RT @selfissued: On the journey to an Implementer's Draft: OpenID Federation draft 31 published @openid @RolandHedbe…
0
4
0
@RickByers @samuelgoto Yes currently PRF is used however we want to eventually move to doing ECDH and signing directly on the authenticator via a webAuthn/CTAP extension. For the initial pilot we are limited by what current keys and platforms support.
0
0
1
@RickByers @samuelgoto Part of the idea is to use hierarchical deterministic keys to reduce the number of times the wallet needs to interact with the authenticator. I can give you a pointer to our current draft if you are interested.
0
0
3
Congratulations.
Today the OAuth step up authentication challenge protocol becomes RFC9470. We now have an interoperable way for resource servers to tell clients when the authentication with which the current access token was obtained in insufficient and (crucially) allows the RS to express what requirements would be acceptable… and a way for clients to use that info to influence the next authentication ceremony with the authorization server. Both are obtained with ultrasimple primitives easily added to existing SDKs, achieving sophisticated runtime behaviors without the need for complex eventing systems. One unexpected benefit of this document is clarity we didn't know we needed. The discussion made clear that we all have different ideas and expectations about what step up authentication really means. The non normative sections of RFC9470 capture the salient point and outcomes of that discussion, hopefully facilitating communications and preempting common errors. On a personal note. This will be the last spec I drive from idea to RFC in my life, and I couldn't have had a better coauthor than @__b_c . From his world class competence to his encyclopedic knowledge of this space, but above all through his genuine desire for the best outcomes for everyone, Brian is just incredible and a joy to work with. Thank you for this wonderful last ride, dear friend.
0
0
4
RT @vibronet: The @FIDOAlliance superstars @n3rd1ty & @ve7jtb run into each other in Yokohama and immediately start exchanging fishing stor…
0
1
0