Oz, from Eran Hammer-Lahav (core contributor to OAuth)
github.com
github.com
funny. OAuth was initially invented in order to fix the problems of web applications having to store end-user credentials, so putting the web first.
For native apps, we've long have the problem solved by just doing BASIC auth.
OAuth was in-fact always problematic for native applications (embed web views, very easily mitm-able) and it always left a sour feeling in my mouth that it's more about controlling your API clients ecosystem than it is about increasing the security for the end-users (see twitter)
[1] For those who don't get the (admittedly poor) joke: http://code.google.com/p/go/issues/detail?id=9
No one can gain anything from this post except the knowledge that Eran is working on it, if that wasn't already clear from his past blog post.
Not to make this comment all whiny, do you guys think Eran stands a chance in making Oz become as popular as OAuth?
Do I think anybody else stands a chance of making something as popular as OAuth? No - as jklio pointed out, there are already alternatives that are likelier to catch on, not to mention OAuth 2.0 itself.
However, if anybody has a chance at adding a new contender to the mix, it's Eran.
Whether or not he will is another question - it'd be hard to judge either way until the project is further along.
The Mozilla Foundation's Persona[3] looks to be further along in terms of code and in terms of other people using it[4], differences with OpenID are partially described here[5]. Regardless of quality I think someone flying solo is going to have a hard time getting ahead of Persona at this point.
[1] http://hueniverse.com/2012/07/oauth-2-0-and-the-road-to-hell...
[2] http://hueniverse.com/2012/07/on-leaving-oauth/
[3] http://identity.mozilla.com/post/32395255498/announcing-the-...
[4] http://identity.mozilla.com/post/31008721633/application-and...
[5] http://identity.mozilla.com/post/7669886219/how-browserid-di...
edit: sigh, I put my mouth before my brain sometimes. I guess I accidentally criticized someone working in the open rather than an announcement of an undocumented web protocol.