4 ms·
Except the phishing aspects make it worse for inexperienced users, since an arbitrary website can redirect to a page that asks for a potentially more sensitive
by whopa 17y ago
Except the phishing aspects make it worse for inexperienced users, since an arbitrary website can redirect to a page that asks for a potentially more sensitive username/password, and that's actually considered normal flow.
I don't understand how anyone can promote OpenID in good conscience with this glaring hole in the design. You simply can't rely on user education.
- kogir 17y agoI've been saying this the whole time and nobody seems to view it as a serious problem. Sure, there are users who will use the same username and password on every site, and there's no hope for them. However, there is a class of users who might think with openid they can use the same credentials for their bank as they do for facebook, but not know to check for valid ssl certificates and nefarious proxying. Can someone who doesn't believe the phishing potential is real please tell me why? What am I missing?
- kniwor 17y agoGood openid providers like wordpress train their users not to expect a login page on anything a authenticating website redirects them to.
- whopa 17y agoAnd as I said in my original comment, you can't rely on user education. If we've learned anything about the psychology of phishing, it's that.