4 Responses to “Making the browser OpenID-aware”


  1. 1 David Arno

    OpenID is far from perfect because it is a phisher’s dream come true. The whole point of OpenID is that it is open - ie, you, me and anyone else on the planet with their own website can be an OpenID provider. If the browser only accepts a few providers, then it breaks the open model. If it supports any open provider, then it will make spotting phishing attempts harder. So sorry Aral, but this idea is broken from start to finish.

    See this article for an explanation of OpenID’s phishing vulnerability.

  2. 2 Aaron Klemm

    The idea you’re describing is very important and should help OpenID uptake a lot. http://en.wikipedia.org/wiki/Windows_CardSpace is an existing potential solution. iirc, there is an implementation for the Mac and an open source equivalent for linux and others. Hopefully a fully usable solution comes out of that space with OpenID support.

    Cheers,

    ak

  3. 3 Jonathan

    Check out OpenID Seatbelt:

    https://pip.verisignlabs.com/seatbelt.do

    This is the plugin for Firefox that allows you to use OpenID while browsing.

Leave a Reply






Bad Behavior has blocked 0 access attempts in the last 7 days.