Hacker News new | ask | show | jobs
by lionhearted 5627 days ago
I was always worried it'd be trivially easy to phish OpenID... I never even signed up for one.
1 comments

not really. Consider for example yahoo's implementation: when I get redirected to Y! for login, I have my personal login seal on the page that grants me that I am actually talking to yahoo and not some scam site.
What about man in the middle?(Go to yahoo get your image and display it for you.) Heck even pass your credentials through to yahoo to verify that you gave me the correct credentials.
I believe that falls out of the definition of "trivially easy to phish"