27 messages in net.openid.general[OpenID] An OpenID "mobile" Hint?
FromSent OnAttachments
David RecordonJun 4, 2008 2:08 pm 
Hans GranqvistJun 4, 2008 2:34 pm 
David RecordonJun 4, 2008 4:50 pm 
Johannes ErnstJun 4, 2008 9:49 pm 
Nat SakimuraJun 4, 2008 11:51 pm 
Martin AtkinsJun 5, 2008 12:02 am 
Kick WillemseJun 5, 2008 3:49 am 
Steven Livingstone-PerezJun 5, 2008 4:06 am 
SitG AdminJun 5, 2008 8:31 am 
Johannes ErnstJun 5, 2008 9:15 am.gif, .gif
David RecordonJun 5, 2008 9:50 am 
David RecordonJun 5, 2008 9:51 am 
Martin AtkinsJun 5, 2008 10:35 am 
SitG AdminJun 5, 2008 12:42 pm 
Martin AtkinsJun 5, 2008 1:34 pm 
SitG AdminJun 5, 2008 3:58 pm 
Nat SakimuraJun 5, 2008 6:59 pm 
Nat SakimuraJun 5, 2008 7:06 pm 
Nat SakimuraJun 5, 2008 8:36 pm 
Martin AtkinsJun 6, 2008 12:06 am 
Johannes ErnstJun 6, 2008 3:08 pm 
Warren JamisonJun 6, 2008 6:05 pm 
Carsten PötterJun 6, 2008 8:47 pm 
Brandon RamirezJun 7, 2008 10:28 am 
Brandon RamirezJun 7, 2008 10:33 am 
SitG AdminJun 7, 2008 9:22 pm 
Tan, WilliamJun 16, 2008 10:57 am 
Actions with this message:
Paste this link in email or IM:
Paste this link in email or IM:
Atom feed for this thread
Paste this URL into your reader:
Subject:[OpenID] An OpenID "mobile" Hint?Actions...
From:Nat Sakimura (saki@gmail.com)
Date:Jun 5, 2008 6:59:26 pm
List:net.openid.general

It is not as bad as you may think.

The http header is assigned by the carrier's gateway, and all the communication after that can be HTTPS. Carriers also publish the IP addresses and more of their gateways. Using all these information, you should be in a pretty good state.

(This is off topic, though, I think..., so I will stop here.)

=nat

On Fri, Jun 6, 2008 at 12:32 AM, SitG Admin <sysadmin at shadowsinthegarden.com> wrote:

For many WAP phones and its variations, there is an associated identifier for each phone that identifies the hardware. When possible, it would be worthwile to use those as a part of credentials.

As a part of, yes - but how easy would it be to spoof that hardware key?

-Shade