[OpenID] Fwd: [OpenID Foundation] New Poll Opened

Allen Tom atom at yahoo-inc.com
Fri Mar 20 01:11:28 UTC 2009


The popup window will be REQUIRED to display the address bar. OPs will 
be strongly encouraged to educate their users to always pay attention to 
the URL of the address bar before entering their credentials.

In particular, I think MySpace does an excellent job on their home page:


      Always make sure you're visiting the real myspace.com!

   1. Check the URL in your browser.
   2. Make sure it begins with http://www.myspace.com/
   3. If ANY OTHER PAGE asks for your info, DON'T LOG IN!

Allen


SitG Admin wrote:
>> Phishing still is a major concern, however, we do not think that the 
>> popup window significantly changes the phishing scenarios compared to 
>> the existing full browser window UIs today.
>
> Are you speaking of full-size windows, here, or windows that have an 
> address bar in them? Pop-up windows that are missing this indication 
> of what site the user is at may reduce confusion by eliminating 
> distractions, but they also take away from the user's awareness of 
> what's going on.
>
> -Shade

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openid.net/pipermail/openid-general/attachments/20090319/ec21ed91/attachment-0002.htm>


More information about the general mailing list