Claiming the blog on Technorati


Interesting security problem that Technorati is trying to solve: how do you prove that a blog belongs to you? (In general, how do you prove that a web page belongs to you?) This is an analog of the standard email validation problem. Only email is a “write-only” media– given the email address of a person you can only write to that address. URLs are generally speaking “read-only” in that you can only view the page contents, although the web also allows more interactive content where in principle the viewer could also submit input.

Technorati has 3 options:
1. OpenID. This is natural, because the protocol was motivated by the need for having authenticated comments across blogs and URLs are used as the identifier instead of email addresses. OpenID is supported by a number of significant players including LiveJournal and AOL, and has recently received a boost after MSFT announced a way to leverage CardSpace for stronger authentication. Downside: this only works if your blogging service implements the spec as identity provider.

2. Provide username/password. Technorati signs into your blog on your behalf. Another straightforward proof, only this one requires an awful degree of trust in Technorati: you have to hope they do not publish your credentials on the Internet or use them for posting 100 spam entries. (And you did not use the same password at your bank, did you?) More sophisticated authorization systems would have the notion of “delegation” where Technorati is temporarily granted access without credentials, and may even be restricted to read-only for example. On the web, identity management is very much a V1 concept, with the exception of Windows Live ID.

3. Creating a new post with special link provided by Technorati. This is email validation in reverse: instead of sending users an email containing a link with embedded identifier, URL validation requires the “prover” to put some content with unique ID on their page, the content being chosen by the “verifier.”
And that is the purpose this article serves.

Technorati Profile

cemp

12 thoughts on “Claiming the blog on Technorati

  1. Pingback: nathanmanley.net
  2. Pingback: Play
  3. Pingback: Felicidad CD5
  4. Pingback: With a K
  5. Pingback: Independent
  6. Pingback: Nazareth
  7. Pingback: Nenia C\'alladhan
  8. Pingback: Des'ree
  9. Pingback: volvo mpg

Leave a Reply

Please log in using one of these methods to post your comment:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s