[OpenID] allowing users to switch to opendid-only: pointless?

SitG Admin sysadmin at shadowsinthegarden.com
Sun Jun 7 03:54:14 UTC 2009


>What about phishing?

If the user intends to forget their password completely, using only 
their OP (which may offer non-password authentication measures, 
resistant to phishing), phishing would elicit an "What is my 
password? Gosh . . . I don't know!" from the user :)

-Shade



More information about the general mailing list