4 ms·
It's a step in the right direction. But I'm still wanting to use my own domain for my openid. The common attacks on open id (phishing, man in the middle when au
by wizard_2 17y ago
It's a step in the right direction. But I'm still wanting to use my own domain for my openid. The common attacks on open id (phishing, man in the middle when authenticating, etc) aren't mitigated by limiting the number of providers. I'd rather they come up with a security standard for openID providers then white list a few.