[OpenID board] W3C's Social Web XG Final Report

John Bradley jbradley at mac.com
Fri Oct 15 02:14:22 UTC 2010


That is a problem for all redirect protocols, and has nothing to do with openID directly.

Each Identity service provider has many options  to eliminate phishing attacks.  Many providers offer there customers those choices now.

John B.
On 2010-10-14, at 9:27 PM, Nat Sakimura wrote:

> Looks like we have to submit some kind of comment by this Friday. 
> 
> OpenID mentioned as "Phishing Heaven" is not good. 
> 
> Don, could you get in touch with them to fix those paragraphs? 
> 
> I will try to send my personal comments as well. 
> 
> Here is the problematic sentence: 
> 
> As a server-side solution, OpenID and successor technologies have the advantage of only relying on server-side HTTP redirects, and so in general works independent of browsers. Very seriously, OpenID 2.0 Authentication does not require relying parties to validate, and so has been described as phishing heaven, since it allows any OpenID-enabled site to redirect a user to a fake OpenID provider, that then steals the user's credentials. 
> 
> On Thu, Oct 14, 2010 at 10:57 AM, Nat Sakimura <sakimura at gmail.com> wrote:
> I just stumbled upon this document "Final Report - Social Web XG Wiki "
> 
> http://www.w3.org/2005/Incubator/socialweb/wiki/FinalReport#Identity
> 
> Perhaps we should locate a volunteer to help them write more
> accurately about OpenID?
> 
> --
> Nat Sakimura (=nat)
> http://www.sakimura.org/en/
> http://twitter.com/_nat_en
> 
> 
> 
> -- 
> Nat Sakimura (=nat)
> http://www.sakimura.org/en/
> http://twitter.com/_nat_en
> _______________________________________________
> board mailing list
> board at lists.openid.net
> http://lists.openid.net/mailman/listinfo/openid-board

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-board/attachments/20101014/0553162a/attachment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4767 bytes
Desc: not available
URL: <http://lists.openid.net/pipermail/openid-board/attachments/20101014/0553162a/attachment-0001.bin>


More information about the board mailing list