Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×

Comment Re:Only then there would be a "paper trail" (Score 1) 333

Unless the attacker deletes the recovery emails before you get to them, you'd notice somebody requesting a bunch of password resets. Ditto for signup requests.

That is easy, Just bomb the e-mail account with pop3 request.

With open-id, if you have RMS's Magic URL, you can pretty much go hog-wild as him without ever being noticed. Anything that takes an Open ID URL is something you can sign up for and probably do your bidding un-noticed.

Why not have the OpenID provider log authentication requests? This would even be better than the current situation where you have no way of knowing if somebody is using one of your existing accounts

Slashdot Top Deals

"Religion is something left over from the infancy of our intelligence, it will fade away as we adopt reason and science as our guidelines." -- Bertrand Russell

Working...