<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Guillaume&#039;s blog &#187; twauth</title>
	<atom:link href="http://lebleu.org/blog/tags/twauth/feed/" rel="self" type="application/rss+xml" />
	<link>http://lebleu.org/blog</link>
	<description>Thoughts on the future of money</description>
	<lastBuildDate>Tue, 16 Jun 2015 08:19:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=4.1.42</generator>
	<item>
		<title>twauth: mobile authentication with OpenID and Twitter</title>
		<link>http://lebleu.org/blog/2008/05/13/twauth-mobile-authentication-with-openid-and-twitter/</link>
		<comments>http://lebleu.org/blog/2008/05/13/twauth-mobile-authentication-with-openid-and-twitter/#comments</comments>
		<pubDate>Wed, 14 May 2008 03:59:59 +0000</pubDate>
		<dc:creator><![CDATA[Guillaume Lebleu]]></dc:creator>
				<category><![CDATA[authentication]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[openid]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[twauth]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://lebleu.org/blog/2008/05/13/twauth-mobile-authentication-with-openid-and-twitter/</guid>
		<description><![CDATA[I stumbled upon Ian McKellar&#8216;s twauth prototype: a Twitter and OpenID based mobile authentication solution. The idea behind twauth is to address the usability issues of current mobile OpenID-based authentication workflows. The particular issue that Ian&#8217;s twauth addresses it the effort place on the user to enter alphanumeric passwords. Twauth addresses this issue by replacing the alphanumeric password entry &#8230; <a href="http://lebleu.org/blog/2008/05/13/twauth-mobile-authentication-with-openid-and-twitter/" class="more-link">Continue reading <span class="screen-reader-text">twauth: mobile authentication with OpenID and Twitter</span></a>]]></description>
				<content:encoded><![CDATA[<p>I stumbled upon <a href="http://ian.mckellar.org/">Ian McKellar</a>&#8216;s <a href="http://ianloic.com/2008/01/13/a-simpler-mobile-openid-workflow/">twauth</a> prototype: a Twitter and OpenID based mobile authentication solution.</p>
<p>The idea behind twauth is to address the <a href="http://factoryjoe.com/blog/2008/01/13/the-openid-mobile-experience/">usability issues of current mobile OpenID-based authentication workflows</a>.</p>
<p>The particular issue that Ian&#8217;s twauth addresses it the effort place on the user to enter alphanumeric passwords.</p>
<p>Twauth addresses this issue by replacing the alphanumeric password entry by a digits-only 5-digit one-time code sent to the mobile phone via Twitter/SMS, that the user then enters on the openid authentication page.</p>
<p>Here are some screenshots of the complete workflow:</p>
<p>1. Entering the twauth mobile OpenID URL at the mobile ma.gnolia.com (m.gnolia.com) <code>http://twauth.ianloic.com/twitteruserid</code>:</p>
<p><a href="http://farm4.static.flickr.com/3040/2490552555_94b696138e.jpg?v=0" rel="lightbox"><img src="http://farm4.static.flickr.com/3040/2490552555_94b696138e_m.jpg" onmouseout="undefined" onmouseover="undefined" title="undefined" alt="Ma.gnolia.com mobile login page" height="240" width="159" /></a></p>
<p>2. Instructing the OpenID server to send a direct (private) Twitter message with a 5-digit code (ignore the garbage):</p>
<p><a href="http://farm3.static.flickr.com/2177/2491369176_7b95bdb010.jpg?v=0" rel="lightbox"><img src="http://farm3.static.flickr.com/2177/2491369176_7b95bdb010_m.jpg" onmouseout="undefined" onmouseover="undefined" title="undefined" alt="Direct message selection" height="240" width="158" /></a></p>
<p>3. The mobile phone that is linked to the Twitter account linked with the twauth OpenID URL is sent a message with a 5-digit code (18010 &#8211; screenshot not available)</p>
<p>4. User enters the one-time 5-digit code:</p>
<p><a href="http://farm4.static.flickr.com/3112/2491369212_124bbeb5d4.jpg?v=0" rel="lightbox"><img src="http://farm4.static.flickr.com/3112/2491369212_124bbeb5d4_m.jpg" onmouseout="undefined" onmouseover="undefined" title="undefined" alt="Entering the one-time 5-digit code" height="240" width="159" /></a></p>
<p>5. You are authentic!</p>
<p><a href="http://farm3.static.flickr.com/2181/2491369286_8aac2e91c8.jpg?v=0" rel="lightbox"><img src="http://farm3.static.flickr.com/2181/2491369286_8aac2e91c8_m.jpg" onmouseout="undefined" onmouseover="undefined" title="undefined" alt="You are authentic" height="240" width="159" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://lebleu.org/blog/2008/05/13/twauth-mobile-authentication-with-openid-and-twitter/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
