[OpenID] A selector for OpenID
SitG Admin
sysadmin at shadowsinthegarden.com
Mon Apr 21 03:37:28 UTC 2008
>I'm not sure what Larry's intentions really are, but for many it
>doesn't matter where it's hosted and therefore provides an excellent
>service.
Are we speaking of RP's or users here? It's easy to say "oh security
doesn't matter" when you're not the one who stands to lose out, but I
think that regardless of the confidence we (as Relying Parties) may
have, it's important to notify our users when something like this is
happening. Even though the privacy this abandons isn't (and shouldn't
be) part of the specs, OpenID can still lead the user to *expect*
such privacy, and going against the "spirit" of OpenID while
appearing to merely provide convenience for users looks like a recipe
for disaster. Not just in the form of backlash against sites that do
this, but against OpenID's reputation; sure, we can say "This isn't
part of OpenID and is not required to implement OpenID, so it doesn't
reflect poorly on OpenID itself.", but how much good will that be
when a 3rd-party ID Selector is popular enough to be considered *the*
OpenID Selector?
-Shade
More information about the general
mailing list