5 ms·
That little phishing problem is still unsolved, yes?
by steve 19y ago
That little phishing problem is still unsolved, yes?
- inklesspen 19y agoIn the sense that a rogue site can pretend to support openid, but actually present a copy of the openid provider's site, yes. People just have to be careful to check the domain name and SSL cert, just like everywhere else. Wordpress.com has an interesting way of handling this; when you use your wordpress.com openid, it doesn't let you log in from the page you get redirected to. You have to manually go to the front page by typing in the address, log in there, and then continue. It's annoying, but probably patches the hole.
- steve 19y agoThank god openid is here to make logging in so much easier!..