On Mon, Dec 15, 2008 at 7:49 PM, Steven Livingstone-Perez <span dir="ltr"><<a href="mailto:weblivz@hotmail.com">weblivz@hotmail.com</a>></span> wrote:<br><div class="gmail_quote"><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
<div link="blue" vlink="purple" lang="EN-US">
<div>
<p>I am seriously seriously missing something here? I love the
UX on FB Connect but all I see are potential security holes.</p>
<p>IMHO OpenID should be build *<b>into</b>* the browsers if we
want to get this kind of inline authentication mechanism.</p>
<p></p></div></div></blockquote><div><br>+1, and then some. Popup windows asking for a password are very easy to phish, both when the user doesn't click into the address bar to see that the covered up URL isn't actually Facebook's (or whomever's site), and when the user doesn't click into the URL bar to notice that it's not actually a Facebook browser popup, but is instead a popup with an image that looks like a URL bar from Facebook, but is actually a popup window from some other site that's trying to steal your password.<br>
<br>I like MyOpenId's client cert login method -- I don't ever have to enter a password anymore, so I don't worry about it. That combined with sxipper, and I feel pretty good about most of my logins nowadays.<br>
<br></div></div><br>