<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Comment Feed for Channel 9 - Identity and Access Control </title>
	<atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Blogs/Subscribe/Identity-and-Access-Control/RSS"></atom:link>
	<image>
		<url>http://media.ch9.ms/ch9/c43b/4342e22f-d6fd-4129-ab54-fddd3e98c43b/subscribeidentity_220.jpg</url>
		<title>Channel 9 - Identity and Access Control </title>
		<link></link>
	</image>
	<description>Today I woke up thinking that talking about Identity and Access Control and how your strategy around that affects you (web-) app&#39;s architecture without going too deeply into the security lingo that usually comes with it.&amp;nbsp;Here&#39;s the 40 minute result. I start&amp;nbsp;with HTTP&#39;s &amp;quot;native&amp;quot; authentication model RFC 2617 and how that&#39;s universally bad, with both Basic and Digest authentication having issues Digest being, ironically worse for the overall security strategy. Then I dive into why models that use tokens (or cookies) are better in terms of security and scalability and explore a range of variations amongst those. </description>
	<link></link>
	<language>en</language>
	<pubDate>Wed, 22 May 2013 01:47:08 GMT</pubDate>
	<lastBuildDate>Wed, 22 May 2013 01:47:08 GMT</lastBuildDate>
	<generator>Rev9</generator>
	<item>
		<title>Re: Identity and Access Control </title>
		<description>
			<![CDATA[<p>Clemens mentions a Firefox plug-in that helps steal session cookies over wifi, but he could not recall the name. I believe he was thinking of Firesheep: <a href="http://codebutler.com/firesheep/">http&#58;&#47;&#47;codebutler.com&#47;firesheep&#47;</a></p><p>posted by codingoutloud</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/Subscribe/Identity-and-Access-Control#c634909386214032612</link>
		<pubDate>Wed, 12 Dec 2012 19:50:21 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/Subscribe/Identity-and-Access-Control#c634909386214032612</guid>
		<dc:creator>codingoutloud</dc:creator>
	</item>
	<item>
		<title>Re: Identity and Access Control </title>
		<description>
			<![CDATA[<p>A great primer for those new to ACS and federated security.&nbsp; Thanks for publishing this.</p><p>&nbsp;</p><p>Kent</p><p>posted by kentweare</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/Subscribe/Identity-and-Access-Control#c634921449097236400</link>
		<pubDate>Wed, 26 Dec 2012 18:55:09 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/Subscribe/Identity-and-Access-Control#c634921449097236400</guid>
		<dc:creator>kentweare</dc:creator>
	</item>
	<item>
		<title>Re: Identity and Access Control </title>
		<description>
			<![CDATA[<p>This is really a great introduction into ACS and its feature-set on a conceptual base. What I miss the most, are some samples, or better some video demonstration, about WCF and best practices regarding service throttling on Azure. A video only about WCF being hosted in Worker Roles on Azure using ACS would also be great <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif?v=c9' alt='Smiley' /></p><p>Thank you.</p><p>&nbsp;</p><p>Ilija</p><p>&nbsp;</p><p>posted by ilija injac</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/Subscribe/Identity-and-Access-Control#c634934099693440558</link>
		<pubDate>Thu, 10 Jan 2013 10:19:29 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/Subscribe/Identity-and-Access-Control#c634934099693440558</guid>
		<dc:creator>ilija injac</dc:creator>
	</item>
</channel>
</rss>