> So, conclusion - if you want to be safe with OpenID - use your own
> domain as your identity. You may use own or third-party identity server,
> and it's safe. Please, correct me, if it's wrong.

It's wrong. Take openid.imperialviolet.org. People trust that server
when they put a link to it in the <head> of their page. Once they have
done that the person who controls that server (who happens to be me*)
can impersonate them.

Of course they can change their page to another identity server
(revoke the trust) but while you are using an identity server you are
trusting it not to be bad.

(* don't worry peeps - you are all far too boring to be worth my time
to do anything like that ;)


