Bitcoin Forum
April 26, 2024, 04:04:49 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: myopenid.com security flaw  (Read 1872 times)
alkor (OP)
Full Member
***
Offline Offline

Activity: 136
Merit: 100


View Profile
July 13, 2011, 12:08:15 AM
Last edit: March 09, 2013, 01:33:51 PM by alkor
 #1

Intersango relies on myopenid.com for user identification. However, it has been reported in the past that myopenid ids can vanish for no reason. It has been discussed here for example:

http://meta.stackoverflow.com/questions/88451/myopenid-account-mysteriously-vanished

Most disturbing of all, once your account is deleted it can be recreated by another person, and they can log into all the sites that rely on your id.
1714104289
Hero Member
*
Offline Offline

Posts: 1714104289

View Profile Personal Message (Offline)

Ignore
1714104289
Reply with quote  #2

1714104289
Report to moderator
1714104289
Hero Member
*
Offline Offline

Posts: 1714104289

View Profile Personal Message (Offline)

Ignore
1714104289
Reply with quote  #2

1714104289
Report to moderator
1714104289
Hero Member
*
Offline Offline

Posts: 1714104289

View Profile Personal Message (Offline)

Ignore
1714104289
Reply with quote  #2

1714104289
Report to moderator
Whoever mines the block which ends up containing your transaction will get its fee.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
Donald_Norman
Member
**
Offline Offline

Activity: 100
Merit: 10


View Profile
September 01, 2011, 12:05:33 PM
 #2

Hi,

I would like to point out that the title of the thread is a bit misleading. It is not an Intersango security flaw but one with myOpenID. I am not sure if myOpenID fixed the problem but as far as I know has never been an issue. Still the new version of Intersango does not rely on myOpenID
w1R903
Full Member
***
Offline Offline

Activity: 218
Merit: 100


View Profile
September 07, 2011, 06:08:09 PM
 #3

Please let's remember that myOpenID is only one of dozens of reputable Open ID providers.  If your site accepts OpenID, you might consider advising users to avoid myOpenID, but there's absolutely no reason to avoid OpenID altogether.  In fact, even if you don't trust any of the providers you find, with a little technical knowledge and a server, you can yourself become an OpenID provider (roll your own).

4096R/F5EA0017
joeyjoe
Full Member
***
Offline Offline

Activity: 224
Merit: 100


View Profile
September 22, 2011, 10:16:46 AM
 #4

haha thats nothing, earlier this week i explained and demonstrated how easy it is to steal btc from there.

Bitcoin PHP programmer for hire! (HTML / CSS / JQuery / AJAX / .NET).
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!