[OpenID] Why spoofing and OpenID look so much alike

SitG Admin sysadmin at shadowsinthegarden.com
Sun Sep 28 07:32:31 UTC 2008


I was writing a dialogue earlier today mapping out the conceptual and 
logical flow of OpenID, and in one of the paragraphs at the end 
(after the dialogue concluded), I praised OpenID (for *not* requiring 
users to enter their password at the Relying Parties' sites) and 
criticized 'integration' technologies that *do* ask for the user's 
password to different accounts but, in the process, teach the user to 
be phished. Reviewing this a few minutes ago, I realized that OpenID 
really does look a lot like phishing:

Phishing: the user sees a site that looks exactly like their regular 
login screen, but this isn't their login site.
OpenID: the user sees a site that looks exactly like their regular 
login screen, because it IS their login site.

I don't think this is anything new, I've seen creative solutions 
implemented already (secret images served only to 'known' users, for 
instance), but I haven't seen it stated this way before, so it may be 
worth noting.

Is there a spot at the openid.net wiki for such mappings?

-Shade



More information about the general mailing list