IdP Phish


Good video below that explains about what the DataPortability.org thing is all about and also came across many essays that are not so enthralled with the idea, along with some nifty examples from Marcos how to land this big phish. Single sign on capability has long been in the minds of many but no one set of technologies or program has yet caught on with the general public.

For those that are not able to be their own IdP (Open ID Provider), it certainly raises a lot of privacy issues and really the thing is just a web based password management system that comes with any major browser already anyways. There doesn’t seem to be any constraints on IdP providers either other than their own morals, and human nature’s curiosity means for sure someone would want to take a gander at the server logs of the users.

I’ve set up my own IdP and identity over at http://www.markgroen.com/id and will use it to experiment with, but will be keeping my original myriad of identities as well and not jumping on board this wagon just yet.