Is OpenID this easy to hack or am I missing something?

Posted by David on Server Fault See other posts from Server Fault or by David
Published on 2010-03-25T14:27:39Z Indexed on 2010/03/25 14:33 UTC
Read the original article Hit count: 350

Filed under:

For those Relying Parties (RP) that allow the user to specify the OpenID Provider (OP), it seems to me than anyone that knows are guesses your OpenID could

  1. Enter their own OP address.
  2. Have it validate them as owning your OpenID.
  3. Access your account on the RP.

The RP "could" take measures to prevent this by only allowing the OpenID to validated by the original OP, but...

  1. How do you know they do?
  2. You could never change your OP without also changing your OpenID.

© Server Fault or respective owner

Related posts about openid