Microsoft Joins the OpenID Foundation
wertigon writes "Windows Live ID just became yet another OpenID-provider. While the cynical me wonders how long it'll be before Microsoft transforms OpenID to something proprietary, they have undoubtedly put even more weight behind the OpenID initiative. So, how long before I can use my OpenID to post on Slashdot?" Patches are always welcome, wertigon ;)
Wikipedia:
It might be okay for joe-shmoe consumer, but there are still common-sense issues standing in the way.
First and foremost is the dead-simple notion, "You mean I'm going to trust a single source for EVERY password for every site I go to? No thanks! I've had my identity stolen already."
If I was in charge of the Right Brigade, I would change the nexus from some server-in-the-sky to your PC storing/providing authentication. I know that's crazy-talk, being responsible for your own identity and everything. Just call me old-fashioned.
http://www.maxineudall.com/2010/02/should-economists-be-sued-for-malpractice.html
This is something the user wants?
I certainly have no interest in having people be able to associate my account on suicidegirls to my facebook account to my msn messenger account...
(i don't really have a suicidegirls acc, i'm just using that as an example)
MABASPLOOM!
"This move" is a fundamental problem with OpenID, not Microsoft specific. Everyone wants to be a provider; no one wants to be a consumer. (Or in slashdot terms, everyone wants to top, no one wants to bottom).
Do you even lift?
These aren't the 'roids you're looking for.
This won't solve the problem but the OpenID Community Wiki has a page documenting different ways in which phishing might occur, a well as a collection of recommendations.
Probably in the long term, assuming OpenID becomes popular, it might come down to browser makers to specifically recognise OpenID, and do things like let the user specify who their OpenID provider is so that it can make it really obvious when the user's logging into the correct place. eg. If the browser doesn't start flashing its borders bright pink when the user visits their claimid.com login page, the user might suspect that they're giving their credentials to the wrong website.