[OpenID] A selector for OpenID

SitG Admin sysadmin at shadowsinthegarden.com
Mon Apr 21 03:37:28 UTC 2008


>I'm not sure what Larry's intentions really are, but for many it 
>doesn't matter where it's hosted and therefore provides an excellent 
>service.

Are we speaking of RP's or users here? It's easy to say "oh security 
doesn't matter" when you're not the one who stands to lose out, but I 
think that regardless of the confidence we (as Relying Parties) may 
have, it's important to notify our users when something like this is 
happening. Even though the privacy this abandons isn't (and shouldn't 
be) part of the specs, OpenID can still lead the user to *expect* 
such privacy, and going against the "spirit" of OpenID while 
appearing to merely provide convenience for users looks like a recipe 
for disaster. Not just in the form of backlash against sites that do 
this, but against OpenID's reputation; sure, we can say "This isn't 
part of OpenID and is not required to implement OpenID, so it doesn't 
reflect poorly on OpenID itself.", but how much good will that be 
when a 3rd-party ID Selector is popular enough to be considered *the* 
OpenID Selector?

-Shade



More information about the general mailing list