[OpenID] openID better than all the profile - what if ...?

Mostafa Altahan mostafa at myeasyscripts.com
Mon Mar 5 15:11:51 UTC 2007


What if someone go and always trust some website, this means that this  
openID , when another person (or script) knows it, will be able to log  
into that website forever, without asking the original enduser of that  
openid?

if so then it will be festival ,more than party time :)



On Mon, 05 Mar 2007 15:15:18 +0200, Stephen Paul Weber  
<singpolyma at gmail.com> wrote:

> On 3/5/07, Mostafa Altahan <mostafa at myeasyscripts.com> wrote:
>> The point of writing openID url is simple and nothing so complicated
>> compared to  email, cause this way I can write with one hand one finger
>> and Enter ,then I can write or share or use any service provided by  
>> login,
>> without nasty http:// , @ or completing large forms of data.
>>
>> But, another issue that comes up is that when I use my openID to login  
>> to
>> some site, it redirects to my openID provider and I (login) trust this
>> site , then it automatically go back to the original site , but the  
>> login
>> is still not closed(I am not logged out from my IdP), this is not good I
>> think.
>>
>
> That is something specific to your IdP... some of them do log you out
> immediately, some don't, some can remember you forever.  That's not
> tied to the spec really.



-- 
Using Opera's revolutionary e-mail client: http://www.opera.com/mail/



More information about the general mailing list