[OpenID] 2-Headed OpenID Auth for Increased Security?

SitG Admin sysadmin at shadowsinthegarden.com
Thu Dec 4 23:43:04 UTC 2008


>I know it's a weak example, but hopefully you get the point.

Indeed. You could require each XRDS file to name other URI's that 
could legally be used with it, and require RP's to reject any set of 
URI's where any of the XRDS file did not name every other URI?

-Shade



More information about the general mailing list