The problem I have with OpenID is how anyone can put up a form that looks like yahoo/google’s form and direct users there and steel the passwords. This affects me as a user (though I can be careful about it), but it affects OpenID providers. What can be done to prevent this? Other than educating the users to look at the URL and all this. I mean a technical way to prevent this.
Share
This problem is called Trusted Path and there are few good solutions to it. Ka-Ping Yee’s thesis, linked in that wikipedia article includes a good treatment of it though.