<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from rtf -->
<style>.EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; }</style>
</head>
<body>
<font face="Arial, sans-serif" size="2">
<div>I’ve spent the weekend reading up on OpenID. Very cool, I’m interetested. I’ve got a couple of questions regarding security of the approach:</div>
<div> </div>
<div>Has a systematic analysis of threats to OpenID been made and published? </div>
<div> </div>
<div>Does OpenID require that SSL be used by the consumer site when fetching the identifier URL? If not, wouldn’t that leave the entire sequence of operations vulnerable to DNS spoofing, etc? </div>
<div> </div>
<div>Burt Harris</div>
<div>Microsoft Live Meeting</div>
<div><font face="Times New Roman, serif" size="3"> </font></div>
</font>
</body>
</html>