Skip to content.

TalkBMC

Sections
You are here: Home » Blog Archive » Jeff Bohren » The Identity Management Expert » bad model

Comment

Above in this comment thread: Black Hats on OpenID » Strong Auth to OpenId IDPs

bad model

Posted by Mike Jones at 2008-06-08 12:11
I think most of the handwringing about OpenID can be avoided if you just think of OpenID for what it is: identity that you yourself provide through your own web site.

Does it bother you that you yourself know who you authenticated with? Doesn't bother me.

Are there nebulous man-in-the-middle attacks possible? Not if you don't want to.

The fact that many people will outsource OpenID to other providers doesn't change this; if you hand over your identity to a third party that runs it poorly, then that's not a problem with the OpenID standard.
 
 

Powered by Plone

This site conforms to the following standards: