[OpenID] Proxying (with OpenSocial) through experimental.openid.net to promote OpenID
SitG Admin
sysadmin at shadowsinthegarden.com
Mon Aug 10 04:55:34 UTC 2009
>What don't you like?
The centralization. It would make the OIDF's servers an appealing
target to those looking for Identity correlation.
I've thought about it some more, though. It seems to me that the
opening here is only for OpenSocial sites where OpenID is impossible
(even by delegation), and the OIDF wouldn't be seeing the user's
activity from actual OP's, so attackers could only correlate
Identities from experimental sites the user was playing with (unless
they had logins with their own services, but that doesn't add much to
the OIDF's potential database). Furthermore, experimental.openid.net
really ought to be using SSL, so a savvy user could easily bounce
their (encrypted) connection around a proxy or few before connecting,
confusing even further the server's idea of who a user was (and, its
ability to associate them with any other login). Relying on the
average user to figure out proxies, though, seems a bit much.
Challenging them to follow a tutorial would chill adoption, so
perhaps just a warning (and maybe link to some stories explaining
what might happen).
-Shade
More information about the general
mailing list