« Mounting OSX Directories in Parallels | Main | FreeYourID.com »
Reputation for OpenID
I’m teaching a graduate class on reputation this semester. I did the same thing last year and the class project was building a reputation framework. The ideas surrounding reputation intrigue me, if you haven’t figured that out from reading this blog.
I’ve had various ideas for this semester’s project, but finally settled on the idea of reputation for OpenID. With OpenID gaining steam, there are concerns on user side about how to know whether to trust an OpenID provider. Even if you pick someone with obvious standing, like AOL, how do you know if the site you’ve been redirected to for authentication is really AOL or some clever phishing attack?
At the same time, relying parties have concerns about whether or not to trust a particular OpenID. Say someone shows up at your site with an OpenID from myopenit.net, should you trust that they’ve been properly authenticated?
People have proposed white lists and black lists to solve these problems, but I think a better solution is a reputation system that can tell you about OpenIDs. I believe the reputation framework we built last year can be put to this task.
Reputation systems work best when there are multiple users sharing their experience, but the system would be useful even for a single site. I’m concerned about how the system could be gamed (see Wired’s article on how this is happening now on Digg, del.icio.us, and other sites, for example). I believe that reputation can serve as a proxy for authorization, in some cases.
There are many unanswered questions, but that’s why we do this, after all. I’ll post periodic updates on how it’s going.
Posted by windley on March 6, 2007 9:22 PM





Comment from David Recordon at March 6, 2007 10:51 PM
Hey Phil,
I'll come and be a guest speaker if you want. :P
Comment from Greg at March 7, 2007 4:24 AM
Would it be interesting to be able to link an identity on Amazon, with an identity on eBay, with an identity on wikipedia, with an identity provided by an employer, or former college with a blog-posting-and-commenting identity?
(Given that all these sites may one day allow you to link your OpenID with your account on their service).
Is this a way to build a web of reputation?
Leave a comment
I encourage you to leave a comment below. Your email address will not be displayed on Technometria, but allows me to communicate with you directly. Your email address won't be displayed, but will be used to compute a MicroID for your comment.