#DanC_at the PyData conference, I learned that compressed CSV is the best known way to get bulk data from back-end to front-end. Quicker to decode than JSON, evidently.
#DanC_"There is very little actual indieweb ActivityStreams support" really? bummer.
#snarfedit also supports the other direction, ie if you post a reply/like/retweet/etc as mf2 html or json, it can publish that into the silos using their APIs
#aaronpkfeel free to make it more prominent on that page
#snarfedaaronpk: yeah, i meant revise the "very little…support" language
#aaronpkthe problem has little to do with OAuth, mostly has to do with matching up accounts from various OAuth providers
#GWGTantek, the administration of that is a pain though
#tantek_GWG nope. I have a bookmark on my mobile browser to create a new email forward. Easy.
#aaronpki create new email forwarding address all the time, so much so that i'm about to make a little web interface for it so that I don't have to edit my mysql DB of email forwarding rules with my osx gui
#tantek_And lastly I saw something resembling this attack yesterday when someone created a FB account with my gmail which has never been used on FB before.
#tantek_I was able to stop it by clicking the "I did not create a FB account" link in the confirmation email.
#GWGI can alias easily, I just can't remember them.
#aaronpkbasically the way providers can prevent this attack is requiring users to be signed in when connecting other OAuth providers
#tantek_But not before receiving ~20 "so and so is now your friend" emails
#aaronpkand OAuth providers can be responsible by not returning email addresses in ID responses if the email address is "unconfirmed"
#tantek_Which OAuth providers have been doing that (returning unverifued emails)?
#aaronpklinkedin, amazon, according to that article
#tantek_regardless, a good reason not to use email as an identifier fof users
#aaronpkunfortunately this isn't even covered in the OAuth 2.0 spec because OAuth is not an identity mechanism, so doesn't even say what to do about returning identity information
#tantek_Aaronpk that sounds worthy of you blogging as a correction to that article.
#colintedford.comedited /User:Colintedford.com (-56) "Rename "Todo" & "Eventually" and flatten "Todo" to bring them in line w/ "Working on" & "Itches" framing (except calling "Itches" "Wants" for greater clarity & to avoid feeling itchy whenever I edit my user page). Also, I'm Gen 2." (view diff)