I came across openID on Monday, today I've got a basic openid key provider and openid lock - and I was ever so pleased to be able to use my own generated key to open an account on a forum - and then .... oh my god ... I realised, that if I can generate a key, then any vladimere or putin, can generate a key which they can then use to unlock my openID lock and dump rotten spam on my website.
So, unless I'm very much mistaken, I'm going to have to adopt a "closed_id", lock which only opens if the brand of the key is one that is on my approved list of known reputable locksmiths.
PS. Nice comment form - and thanks to the guy(s) gal(s) that keep it going!
Authored by: Anonymous on Saturday, September 19 2009 @ 12:41 CEST