Hacker News new | ask | show | jobs
by jlam 6654 days ago
The weakness of the above argument: Why would site-owners install an untrusted Clickpass widget spread around the net but not from Clickpass itself?

I can see how some users might fail to recognize a Clickpass or OpenID url and give their login credentials to a fraudulent site, but no worse than password management, OpenID requires folks be on guard against phishing.

1 comments

It's the same problem as current passwords, but with higher consequences for those who don't use the same userid and password across sites.