John Bradley Profile
John Bradley

@ve7jtb

Followers
3K
Following
1K
Statuses
3K

Identity stuff OpenID Foundation Board

iPhone: 29.986570,-95.352829
Joined March 2007
Don't wanna be here? Send us removal request.
@ve7jtb
John Bradley
7 months
RT @openid: Fourth Implementer’s Draft of OpenID Federation Approved @RolandHedberg @selfissued @giusdemarc @dzhuv
0
4
0
@ve7jtb
John Bradley
7 months
Enjoying Vancouver before IETF
0
0
1
@ve7jtb
John Bradley
8 months
RT @arekfurt: This is one hell of a read. It should be said that susceptibility to Golden SAML attacks isn't a security vulnerability in A…
0
32
0
@ve7jtb
John Bradley
11 months
I guess I finally made it big in New York. Next time I want Tokyo or Berlin.
Tweet media one
1
1
35
@ve7jtb
John Bradley
11 months
Thanks, to the people putting this together for including me. Honored to be on the same list as @vibronet, the others are OK as well:)
0
0
12
@ve7jtb
John Bradley
1 year
RT @selfissued: Continued refinement: OpenID Federation draft 33 published @openid @RolandHedberg @giusdemarc @dzhu
0
3
0
@ve7jtb
John Bradley
1 year
RT @selfissued: OpenID Federation editors + Leif in Copenhagen
Tweet media one
0
3
0
@ve7jtb
John Bradley
1 year
RT @selfissued: Ten Years of OpenID Connect and Looking to the Future #OpenID #OpenIDConnect #TenYearsOfOpenIDConne
0
8
0
@ve7jtb
John Bradley
1 year
My son made a christmas cookie of me.
0
0
5
@ve7jtb
John Bradley
1 year
Voting in the constituional referendum
Tweet media one
0
0
2
@ve7jtb
John Bradley
1 year
RT @selfissued: On the journey to an Implementer's Draft: OpenID Federation draft 31 published @openid @RolandHedbe
0
4
0
@ve7jtb
John Bradley
1 year
@RickByers @samuelgoto Yes currently PRF is used however we want to eventually move to doing ECDH and signing directly on the authenticator via a webAuthn/CTAP extension. For the initial pilot we are limited by what current keys and platforms support.
0
0
1
@ve7jtb
John Bradley
1 year
@RickByers @samuelgoto Part of the idea is to use hierarchical deterministic keys to reduce the number of times the wallet needs to interact with the authenticator. I can give you a pointer to our current draft if you are interested.
0
0
3
@ve7jtb
John Bradley
1 year
Congratulations.
@vibronet
Vittorio
1 year
Today the OAuth step up authentication challenge protocol becomes RFC9470. We now have an interoperable way for resource servers to tell clients when the authentication with which the current access token was obtained in insufficient and (crucially) allows the RS to express what requirements would be acceptable… and a way for clients to use that info to influence the next authentication ceremony with the authorization server. Both are obtained with ultrasimple primitives easily added to existing SDKs, achieving sophisticated runtime behaviors without the need for complex eventing systems. One unexpected benefit of this document is clarity we didn't know we needed. The discussion made clear that we all have different ideas and expectations about what step up authentication really means. The non normative sections of RFC9470 capture the salient point and outcomes of that discussion, hopefully facilitating communications and preempting common errors. On a personal note. This will be the last spec I drive from idea to RFC in my life, and I couldn't have had a better coauthor than @__b_c . From his world class competence to his encyclopedic knowledge of this space, but above all through his genuine desire for the best outcomes for everyone, Brian is just incredible and a joy to work with. Thank you for this wonderful last ride, dear friend.
0
0
4
@ve7jtb
John Bradley
1 year
Thanks everyone who contributed to the specification.
@selfissued
Mike Jones
1 year
OAuth 2.0 Demonstrating Proof of Possession (DPoP) is now RFC 9449 #IETF #OAuth #PoP #DPoP @__b_c @dfett42 @ve7jtb @tlodderstedt @dwaite @vibronet
0
0
5
@ve7jtb
John Bradley
2 years
I'm at Salón Primeclass Pacífico in Pudahuel, Metropolitana de Santiago
0
0
0
@ve7jtb
John Bradley
2 years
RT @selfissued: OAuth DPoP specification is in the hands of the RFC Editor #IETF #OAuth #PoP #DPoP @__b_c @dfett42
0
6
0
@ve7jtb
John Bradley
2 years
RT @vibronet: The @FIDOAlliance superstars @n3rd1ty & @ve7jtb run into each other in Yokohama and immediately start exchanging fishing stor…
0
1
0
@ve7jtb
John Bradley
2 years
RT @vibronet: Traditional 360° of the traditional #oauth dinner at #IETF, #IETF116 in particular :) Some random tags - @_nat_en @tlodders
0
1
0