S. Sriram ssriram at
Sun Jul 17 12:16:28 PDT 2005


Say I had two identities, lets call them casual & formal

I go browsing with my casual identity,
I like something and want to 'buy'
The shopping cart requires  a separate and
distinct formal identity too

My consumer now checks both my casual & formal identity
before allowing the transaction to pass.

Both homepages need to be hijacked by the same rogue
server for me to be compromised.

OpenId does not need to change at all. The consumer only
needs to do double check and the individual needs to have
two ids.

S. Sriram

