What is the most secure implementation of OpenID technology?
Is there someone out there who knows enough about security, cryptography and OpenID specifications? No rumors, just facts.
I would like to know all about insecurities of network communication process between OpenID provider and OpenID-enabled site during:
- logging in
- is user logged?
- user's sensitive information interchange
- logout
and what should we be aware of.