nanog mailing list archives

Re: LinkedIn password database compromised


From: Owen DeLong <owen () delong com>
Date: Thu, 7 Jun 2012 13:00:38 -0700


On Jun 7, 2012, at 10:03 AM, Randy Bush wrote:

hi etaoin,

I still don't want single sign on.  Not anywhere.

i believe that 'single sign on' is a bad deal and dangerous for all, not
just we geeks.  essentially it means that the 'identiry provider' owns
your identity.  i love that they call themselves 'identity providers'
when it is MY fracking identity and they are reselling it.

If single sign-on is done right, then YOU are the identity provider and YOU
own your identity. It does, however, potentially enable cross-site tracking.


Owen



Current thread: