<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: OpenID security CSS overlays</title>
	<atom:link href="http://www.thespanner.co.uk/2007/09/28/openid-security-css-overlays/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2007/09/28/openid-security-css-overlays/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Tue, 14 Oct 2008 01:42:13 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/28/openid-security-css-overlays/#comment-820</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 13 Nov 2007 11:30:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/28/openid-security-css-overlays/#comment-820</guid>
		<description>@Joseph

Yeah good point but I also think the information is a security problem, for example the attacker hacks the OpenID account and now has their username and password as well as known IP addresses of the user.</description>
		<content:encoded><![CDATA[<p>@Joseph</p>
<p>Yeah good point but I also think the information is a security problem, for example the attacker hacks the OpenID account and now has their username and password as well as known IP addresses of the user.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joseph Wilk</title>
		<link>http://www.thespanner.co.uk/2007/09/28/openid-security-css-overlays/#comment-819</link>
		<dc:creator>Joseph Wilk</dc:creator>
		<pubDate>Tue, 13 Nov 2007 10:43:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/28/openid-security-css-overlays/#comment-819</guid>
		<description>Thanks for the informative information. I've have found this site very usual in my integration of OpenID.

I thought I would contribute something I have learnt about Verisign.

I have noticed that Verisign allows users to delete the records of logging in history. 

Hence if someone where to break an OpenID login they could cover there tracks and hide any signs of an attempted breach.

Looking at MyOpenID they have the history read-only.</description>
		<content:encoded><![CDATA[<p>Thanks for the informative information. I&#8217;ve have found this site very usual in my integration of OpenID.</p>
<p>I thought I would contribute something I have learnt about Verisign.</p>
<p>I have noticed that Verisign allows users to delete the records of logging in history. </p>
<p>Hence if someone where to break an OpenID login they could cover there tracks and hide any signs of an attempted breach.</p>
<p>Looking at MyOpenID they have the history read-only.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2007/09/28/openid-security-css-overlays/#comment-710</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Tue, 16 Oct 2007 20:33:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/2007/09/28/openid-security-css-overlays/#comment-710</guid>
		<description>The POC requires the following details:-
username : openidtester
password : openidtester

You need to login to the Verisign service before executing the POC.

*NOTE* The trusted sites should be deleted in your Verisign account for the POC to display correctly. I would make this easier but I don't currently have time to modify the poc.</description>
		<content:encoded><![CDATA[<p>The POC requires the following details:-<br />
username : openidtester<br />
password : openidtester</p>
<p>You need to login to the Verisign service before executing the POC.</p>
<p>*NOTE* The trusted sites should be deleted in your Verisign account for the POC to display correctly. I would make this easier but I don&#8217;t currently have time to modify the poc.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
