Hacker News new | ask | show | jobs
by mivok 5686 days ago
Actually, it seems to me the bigger problem is that some providers just decide to change who they say you are, and those providers (Google) just happen to be the biggest because you're telling users 'just use your google login here'. They don't know anything about openID. Sure, users having multiple OpenIDs is an issue when they forget which they used, but even if this was solved, the other issue seems to be much worse.
1 comments

A provider changing their URL: totally agree, huge problem. But that's on the same scale as your email provider changing their URL. Problematic and rare. And it's something nothing can adequately deal with - your "forgot password" links won't work if your email changes domain names. It's also an abnormality that can't be securely accounted for, because otherwise MITMs could just hijack requests and send it to their own servers with no complaints.