OpenID (42)

31 Name: #!/usr/bin/anonymous : 2008-01-04 08:08 ID:GXNArZT5

I'm not sure this settles all the security concerns raised in this thread, but is a really neat thing.

You get a client-side SSL certificate for your browser, and securely identifies you using that. There is no password.

The OpenIDs it provides are still http://, not https://, though, so it seems vulnerable to's DNS being hijacked. I wonder why that is; maybe most OpenID consumers out there don't understand HTTPS? If the OpenIDs were, then would this not be totally secure?

This thread has been closed. You cannot post in this thread any longer.