[OpenID] OpenID consumers should make it clear if they are going to publish a user's OpenID

Dave Kearns dkearns at gmail.com
Tue May 15 01:40:17 UTC 2007


From: Johnny Bufu
>
> On 14-May-07, at 8:07 AM, Dave Kearns wrote:
>
> > What's the point of using different OpenID identifiers at different
> > sites?
>
> So that the sites (RPs) do not correlate your identities.
>

But the RPs have no knowledge of which other RPs anyone is going to, do
they? (Except, of course, for information passed outside the OpenID
transaction).

The OP would be able to do this correlation, of course, but unless I used
different OPs for each OpenID this is always going to be possible. So,
again, where's the benefit? Without some sort of simplified signon
capability there's little to no benefit to the user over simple
username/password combinations.

-dave




More information about the general mailing list