UMA Twitter chat 14 Mar 2012

User-Managed Access lets users gain more control over online sharing and lets websites outsource user privacy and sharing preferences!

  1. The intro...
  2. Web apps now outsource authn, payments. Why not user sharing/#privacy prefs? Learn more @ Mar 14 #umachat tinyurl.com/umachat
  3. I'll be doing the #umachat in 1.5hrs. If I get too noisy for your taste, try Muuter.com to mute me temporarily. Clever tool!
  4. RT @xmlgrrl: Welcome to world's first #pi day #umachat! Let us have it: What are your questions, concerns, puzzles about User-Managed Access? #umachat
  5. Security of OAuth tokens vs. "secret URLs":
  6. One question we've gotten: are OAuth tokens really safer than "secret URLs" for managing access to sensitive data e.g. health? #umachat
  7. @xmlgrrl Yes, because OAuth tokens have a built in rotation mechanism. #umachat
  8. @zer0n1ne Agreed. Unguessable refreshable secrets, and teaching clients *how* to refresh them, makes #OAuth tokens a great mech. #umachat
  9. Business (non-"user-centric") use cases for UMA:
  10. Followup items from this section: UMA branding question, collection of business use cases.
  11. How can we get the user out of UMA? The provisioning, permissions, and verification components are useful outside of the base case #umachat
  12. @zer0n1ne Business use cases are popping up for UMA that don't rely on free-agent users. "Authz *party*" can work for "authz user". #umachat
  13. @zer0n1ne While many of the current flows use a 3-legged OAuth token, I don't see the user being required. #umachat
  14. @gffletch The problem is in the name more than the technology, "User managed access" #umachat
  15. Is it time for expanded branding? UMA V1 has stuck to its user-centric knitting in order to focus. But org-centric not precluded. #umachat
  16. Maybe "UMA" can just become a pronounceable protocol name, with its history exclusively in "user-managed" but not exclusive? #umachat
  17. @xmlgrrl I for one would miss the opportunity to think of Uma Thurman in a work context should name change #umachat
  18. @paulmadsen I lobbied for the name Lenina (is.gd/MRPqmo) for SMART AM "UMA/j" impl. :-) #umachat

Did you find this story interesting? Be the first to or comment.

Liked!

Eve Maler

XMLgrrl, aka Carbgrrl, aka The SAML Lady, aka UMAnitarian, aka Forrester IAM analyst, aka barbershop chorusgrrl, aka Mud Junket's den mother

Total views
145

Storify

@Storify