[OpenID] Why spoofing and OpenID look so much alike
SitG Admin
sysadmin at shadowsinthegarden.com
Sun Sep 28 07:32:31 UTC 2008
I was writing a dialogue earlier today mapping out the conceptual and
logical flow of OpenID, and in one of the paragraphs at the end
(after the dialogue concluded), I praised OpenID (for *not* requiring
users to enter their password at the Relying Parties' sites) and
criticized 'integration' technologies that *do* ask for the user's
password to different accounts but, in the process, teach the user to
be phished. Reviewing this a few minutes ago, I realized that OpenID
really does look a lot like phishing:
Phishing: the user sees a site that looks exactly like their regular
login screen, but this isn't their login site.
OpenID: the user sees a site that looks exactly like their regular
login screen, because it IS their login site.
I don't think this is anything new, I've seen creative solutions
implemented already (secret images served only to 'known' users, for
instance), but I haven't seen it stated this way before, so it may be
worth noting.
Is there a spot at the openid.net wiki for such mappings?
-Shade
More information about the general
mailing list