Steven Osborn
"I would love to change the world, but they won't give me the source code".

Archive for the ‘Web’ Category

One Button to Rule them all.

Monday, March 31st, 2008

There have been quite a bit of talk about the current state of OpenID login screens that are becoming cluttered with provider specific buttons with no end in site. Scott Blomquist has some really interesting ideas for implementing a IdP independent button that would replace all of the existing buttons, while ...

OpenID Personas = Cruft

Thursday, March 20th, 2008

I use personas in the same way I think most people are using them in OpenID today. I don't think of them as identity containers, but as address bundles. I have one very creatively labeled "Work" and another labeled "Home". Hmm.... That sounds exactly like how I ...

I blog therefore I am.

Saturday, March 15th, 2008

I am now the official Steven Osborn of the internet. How did I accomplish the feat? Well, it wasn't by spending hours practicing to be an accomplished pianist or by becoming an experienced realtor. I certainly didn't take the time to become a doctor and I'm not ...

Miami Here I come

Thursday, February 14th, 2008

I'll be in Miami along with Kevin Fox, also from Vidoop, toward the end of the month for a couple of different events that should be a lot of fun. I'll be catching BarCamp on the 28th followed by FOWA - Future of Web Apps. I can't wait to ...

Using JanRain OpenID with Zend Framework

Monday, January 28th, 2008

Ok, I know Zend_OpenId is on the way, but for those of us who don't like to wait here's a way to get OpenID working with Zend Framework. Besides, JanRain's libraries tend to be pretty solid and up to date so you won't go wrong using this in place ...

What everyone’s Zend_View_Helper tutorials leave out.

Sunday, January 27th, 2008

There seems to be several Zend_View_Helper tutorials out there and all of them talk about what a view helper is and does, but I always left with one question: How do I make the helpers available to ALL of my views? Then I learned a bit about Zend_Controller_Action_HelperBroker This class can ...

OpenID: Trust and Liability

Wednesday, December 5th, 2007

My co-worker (Sam) and I lead a session at IIW called "OpenID Security and Privacy" and as the conversation evolved it occurred to me that even though these issues exist in OpenID today, the real hurdles are going to be trust and liability. There are many companies and ...

Coolest hardware authentication device ever from Yubico.

Tuesday, December 4th, 2007

I'm not typically a big fan of hardware tokens, but I discovered a neat little device at IIW that takes the cake when it comes to hardware based authentication. The YubiCard is a incredibly small device; requires no drivers at all and doesn't need a LCD screen. ...

Google Hax0rs

Sunday, November 25th, 2007

I noticed this interesting entry in my server's access log today. I certainly have phpMyAdmin running at that location, but you can't get the process list unless you login. 66.249.70.89 xxxxxxxxx.com - [21/Nov/2007:13:43:18 -0800] "GET /MyAdmin/server_processlist.php?lang=en-utf-8&convcharset=iso-8859-1&collation_connection=utf8_unicode_ci&token=a1bb5490499a10bb493edc160625e33b&kill=49481 HTTP/1.1" 404 345 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" You can do two things at ...

Yay, I’m a Anti-Phising Champion

Thursday, November 15th, 2007

I got an invitation to take the Paypal Anti-Phishing challenge. It's all of 5 questions long, but it's a neat way to educate user's about phising.