[OpenID] Delegation leading to new accounts on websites

SitG Admin sysadmin at shadowsinthegarden.com
Mon Jul 13 04:08:32 UTC 2009


>The encoding scheme can be a OP internal deployment detail, since no 
>other party actively processes the local_id's; the URLs do not need 
>to be dereferenceable either.

So, to actively confuse any 3rd party that *tries* to process my 
local_id's, I can scramble the external_id:local_id mapping until 
each external_id is known to my OP as a string exactly identical to 
*another* external_id?

-Shade



More information about the general mailing list