4 ms·
Why do you think a "properly implemented" OpenID site should allow the user to use any authentication provider? The relying party site is trusting the OpenID pr
by jancona 15y ago
Why do you think a "properly implemented" OpenID site should allow the user to use any authentication provider? The relying party site is trusting the OpenID provider to authenticate its users. Wouldn't sites with real security requirements want to vet providers before trusting them?
- js4all 15y agoExactly right. And all OpenID providers have different attribute exchange protocol extensions. If you use them, you can effectively allow only those you have tested.