[OpenID] Password age and password reset

SitG Admin sysadmin at shadowsinthegarden.com
Thu May 14 02:46:48 UTC 2009


>In what I am proposing the transfer is intermediated by the browser,
>so not covert.

A clever (and even marginally skilled) attacker will have all 
redirects intercepted and waiting on their approval; if they can 
learn of the RP's suspicion *and* block the OP from learning about 
it, the transfer would be worse than useless: it would only serve to 
annoy legitimate users.

-Shade



More information about the general mailing list