OpenID phishing risks - BE CAREFUL!
It is a great shame that things like these do happen, but it is VITAL that you know about the risks you face whenever you adopt or use a new technology.
OpenID is great. It makes your life simpler and a lot easy in that you don’t have to remember thousands of username and password combinations. Unfortunately, its great for malicious phishers too!
So what is phishing? Here is what Wikipedia says about it:
“In computing, phishing is a criminal activity using social engineering techniques.[1] Phishers attempt to fraudulently acquire sensitive information, such as usernames, passwords and credit card details, by masquerading as a trustworthy entity in an electronic communication.”
So how do you run at risk falling prey to phishers using OpenID? Here is how:
Mr Phisher sets up a beautiful, intriguing web site that uses OpenID for registeration and authentication. You unsuspectingly likes the site and log in using your OpenID to see all the wonderful pics and videos that is only available to members…
So Mr Phisher takes your OpenID URL you’ve entered, lets say http://claimid.com/koos, and writes some scripts that checks what OpenID server your use. In this case he sees that you are using ClaimID. He then redirects you to his FAKE ClaimID server that sports a log in page that looks like the ClaimID server’s log in page. He might even go through LOTS of trouble and register a domain like http://claimid.net to make it even more difficult for you to spot that this is a phishing attempt.
You land on his fake ClaimID login page and you don’t look at the URL or the page too closely and you enter your username and password. BOOM! You’ve been caught, hook, line and sinker! Mr Phisher now has your login details for your real ClaimID account. He can now get ALL your personal details. He can see which sites you use your ClaimID on. He can access those sites and others as you. Lord knows what he want to do with your identity, but he has got it and he can misuse it to his liking… (and we’ve seen what a Dark Web this web can be!).
So let this be a warning. Be careful! Don’t trust anybody. Look carefully before you use your OpenID. Look at the login page and make SURE that it is your OpenID server you are logging into and not a rogue one.
I’m sure Dominique White can shed a lot more light on this for us and make you crap your best set of underpants. BE CAREFUL!
technorati tags:openid, openid-phishing, openid-security, phishing, security-risk
Blogged with Flock
4 Comments to "OpenID phishing risks - BE CAREFUL!"
Spit it out!
Semantic Web Stii
Recent Posts
- Astalavista Wordpress!
- Lifestreaming and Twitter is making us lazy
- Days with my father
- Friday morning fail by a stripper
- Got Springleap!
- Afrigator vs Regator
- Don’t pirate music/movies! You might be forced to use Windows if you do…
- Pike > Python?
- Using Twhirl for FriendFeed
- Being anti-social SUCKS!
My Posse
- Jayx’s bloggy
- Gogo’s blog
- Go2 South Africa
- Stumble Upon
- Dave Duarte
- Wikipedia
- zlythern
- Max Kaizen
- Tresblue
- Mike Stopforth
- RafiQ
- Muti.co.za
- Employmint
- Danette’s Bloggy!
- Thinking Machine
- White African
- kiefpiet.co.za
- Skuff’s World
- Goozeberry
- Crossloop blog
- Crossloop
- Aquila Online
- Charl van Niekerk
- Derek Allard
- Code Igniter
- Carls
- Justin Hartman
- blik.co.za
- Stefano Sessa
- Uno de Waal
- Amplitude!
- bLaugh
- Tyler Reed
- Chris Rawlinson
- Stormhoek!
- 3am
- Mike Solomon
- Mobile Q and A
- Eric Edelstein
- Marc Forrest
- Imel Rautenbach
- Absolutewillie
- Vincent Maher
- Colin Daniels
- Groogle!
- Chilibean
- Paul Jacobson
- Ayelet
- Python Guru Neil
- Rails Guru Nic
- Beverley Merriman
- Miguel
- Nic Harrywhatshisname
- Chris iMod
- Geekrebel!
- Steven McD
- Belinda sweetheart!
- Henre Rossouw
- JPGeek
- Foxinni
- Adii
- Charl Norman
- Bandwidthblog
- Jason Bagley
- Simon Botes
- Auric Silverwing
- Mark Forrester
- Saul Kropman
- Fred Roed
- Sass Schultz
- Gregor Rohrig
- Catherine Lückhoff
- Toastmasters
- SAA
- Minnaar Pieters
Filed in
- Afrigator (26)
- ajax (9)
- API (2)
- Apple stuff (10)
- Blogging (25)
- browsers (5)
- Business (28)
- Code Igniter (8)
- firefox (8)
- flock (14)
- Funnies (73)
- GeekDinner! (18)
- General and sometimes Rants (49)
- Go2SA (2)
- ideas 2.0 (14)
- javascript (12)
- Kick-ass Tools (30)
- Linux (5)
- Marketing (25)
- moo.ajax (4)
- mootools (6)
- Open Source (10)
- Programming (33)
- C# (1)
- PHP (13)
- Python (9)
- Ruby (on Rails) (9)
- RSS (5)
- Semantic Web (32)
- Social Web (57)
- Software Development (15)
- South Africa (33)
- Tagging (6)
- Techie stuff (22)
- Tshirts (3)
- Tutorials (42)
- Blogging (17)
- Flocking (6)
- muti.co.za (13)
- Web 2.0 (73)
- web development (20)
Past Stuff
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- October 2006
- September 2006

















Phishing is a *major* problem for OpenID users. Right now a bunch of services are popping up around OpenID, which is great, but as users mature into this technology they’ll start to learn how to shop around.
The real winners will be the services that will manage to build security layers on top of OpenID. Maybe we’ll see some new anti-phishing patterns being born as a result.
To be honest I know very little about Open ID. I imagine one possible solution could be some sort of browser extension where you could hardcode your open ID provider. The extension would essentially proxy the authentication (or at least the requests) and ensure the correct open ID server was used.
Who wants to write a firefox extension?
OpenID Phishing Primer
The prospect of someone spoofing my claimID page is a scary one!