Phishing attacks?
Uh, how is it a tempting target for phishing attacks, exactly?
The whole POINT of OpenID is that it means phishing attacks are pretty much impossible: unless the phisher goes to the trouble of creating several different fake login pages and detecting the domain of the URI you enter on the target site (then redirecting you to the correct fake, hoping that you don't notice it IS a fake), then it can't happen—and even then it only works if you use one of the well-known OpenID providers (Verisign, AOL, Yahoo, for example). If you run your *own* OpenID server (or use a corporate one), any phishing attempt is dead in the water from the outset.


