Is OpenID this easy to hack or am I missing something?
- by David
For those Relying Parties (RP) that allow the user to specify the OpenID Provider (OP), it seems to me than anyone that knows are guesses your OpenID could
Enter their own OP address.
Have it validate them as owning your OpenID.
Access your account on the RP.
The RP "could" take measures to prevent this by only allowing the OpenID to validated by the original OP, but...
How do you know they do?
You could never change your OP without also changing your OpenID.