Hacker News new | ask | show | jobs
by a3_nm 5509 days ago
Notice that you will have the same kind of trouble if you're using OpenID on your own domain and let it expire...

(An attacker could buy the domain name and set up a page at your OpenID URL which would delegate the OpenID to something under their control.)