Does It Have to be This Hard?

July 28, 2012 14:05:54.517

Looks like we have another WS* style cluster-**** coming our way:

"The Register reports, 'Eran Hammer, who helped create the OAuth 1.0 spec, has been editing the evolving 2.0 spec for the last three years. He resigned from his role in June but only went public with his reasons in a blog post on Thursday. "At the end, I reached the conclusion that OAuth 2.0 is a bad protocol," Hammer writes. "WS-* bad. It is bad enough that I no longer want to be associated with it."'

Call me naive, but so long as you have https enabled, shouldn't username/passphrase work well? All of the attempts at "simplifying" that seem to be going in the wrong direction....

posted by James Robertson

