Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

The Most Secure Implementation of OpenID

What is the most secure implementation of OpenID technology?

Is there someone out there who knows enough about security, cryptography and OpenID specifications? No rumors, just facts.

I would like to know all about insecurities of network communication process between OpenID provider and OpenID-enabled site during:

  • logging in
  • is user logged?
  • user's sensitive information interchange
  • logout

and what should we be aware of.

like image 279
Petr Urban Avatar asked Jan 23 '26 03:01

Petr Urban


2 Answers

Yeah, SAML is good. It has strong encryption between two endpoints. SAML 2.0 has a good binding protocol for messaging through HTTP or SOAP. It also covers identity assertions, so you can better authenticate that the user is who they say they are.

like image 123
Nicholas Avatar answered Jan 25 '26 19:01

Nicholas


We use SAML.

like image 41
Marcus Adams Avatar answered Jan 25 '26 19:01

Marcus Adams