4 ms·
The problem(s) with OpenID http://idcorner.org/2007/08/22/the-problems-with-openid/ http://idcorner.org/2007/08/22/the-problems-with-openid/
by t0pj 18y ago
The problem(s) with OpenID
http://idcorner.org/2007/08/22/the-problems-with-openid/ http://idcorner.org/2007/08/22/the-problems-with-openid/
- wmf 18y agoThat's FUD to sell Credentica, and many of those problems cannot be fixed if you assume an unmodified Web browser.
- ajross 18y agoAnd yet they remain problems that are unsolved. The phishing one in particular (send the user to a fake login page that just facades the real one and steals the password) is a showstopper all by itself. So while it's true that (short of doing stuff like RSA & PKI in Javascript) you can't fix these problems with browsers as they exist today, that doesn't mean that a solution that ignores the problems is a good idea.
- sapphirecat 18y ago> (short of doing stuff like RSA & PKI in Javascript) The only thing that I can see which would actually help, without breaking the "install nothing" goal of OpenID or making the existing usage path any more difficult, is to build some sort of OpenIDRequest object into browsers. And you'd want to design an unspoofable credential request window to go with it.