TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Account Association Security Threats for Google Single Sign-On

17 pointsby mikesunover 12 years ago

1 comment

stickfigureover 12 years ago
TL;DR: Be conscious of who you trust. OpenID AX attributes may give you an email address, but this creates two potential issues:<p>* Can you be sure that the attribute has not been tampered with in transit? Check the signature (or make sure your library is checking the signature).<p>* Can you trust the OpenID provider to give you a correct and verified email address? Maybe if that provider is Google. Anyone else, probably not.<p>I prefer Mozilla Persona's approach to this problem; your identity effectively <i>is</i> an email address. It's also trivial to integrate.
评论 #4545189 未加载