Feed Sign in with OpenID OpenID

Simon Willison’s Weblog

Why an OAuth iframe is a Great Idea. Because users should a) learn to be phished and b) not even be given the option to avoid being phished if they know what they’re doing? No, no and thrice no. If you want to improve the experience, use a popup window so the user can still see the site they are signing in to in the background.

Tagged , , ,

1 comment

  1. Yep. I agree with you.

    Just so you know, there's frame-busting code in the login page to prevent that sort of thing anyway.

    I'm not really sure where he got the idea you could do that.

    jr conlin - 17th July 2009 04:02 - #

Comments are closed.
A django site