[OpenID] Proxying (with OpenSocial) through experimental.openid.net to promote OpenID

SitG Admin sysadmin at shadowsinthegarden.com
Mon Aug 10 04:55:34 UTC 2009


>What don't you like?

The centralization. It would make the OIDF's servers an appealing 
target to those looking for Identity correlation.

I've thought about it some more, though. It seems to me that the 
opening here is only for OpenSocial sites where OpenID is impossible 
(even by delegation), and the OIDF wouldn't be seeing the user's 
activity from actual OP's, so attackers could only correlate 
Identities from experimental sites the user was playing with (unless 
they had logins with their own services, but that doesn't add much to 
the OIDF's potential database). Furthermore, experimental.openid.net 
really ought to be using SSL, so a savvy user could easily bounce 
their (encrypted) connection around a proxy or few before connecting, 
confusing even further the server's idea of who a user was (and, its 
ability to associate them with any other login). Relying on the 
average user to figure out proxies, though, seems a bit much. 
Challenging them to follow a tutorial would chill adoption, so 
perhaps just a warning (and maybe link to some stories explaining 
what might happen).

-Shade


More information about the general mailing list