[OpenID] Password age and password reset
SitG Admin
sysadmin at shadowsinthegarden.com
Thu May 14 02:46:48 UTC 2009
>In what I am proposing the transfer is intermediated by the browser,
>so not covert.
A clever (and even marginally skilled) attacker will have all
redirects intercepted and waiting on their approval; if they can
learn of the RP's suspicion *and* block the OP from learning about
it, the transfer would be worse than useless: it would only serve to
annoy legitimate users.
-Shade
More information about the general
mailing list