Mobile app version of vmapp.org
Login or Join
Barnes591

: Should I run my own OpenID server? As I understand it, OpenID relies on a single trusted service, the OpenID provider. If you run this service on your own server you then have complete control,

@Barnes591

Posted in: #Openid

As I understand it, OpenID relies on a single trusted service, the OpenID provider. If you run this service on your own server you then have complete control, and you only have to trust yourself (and your ability to correctly configure and run a web service).

Would this be the most secure and effective way to manage your online identity?

10.02% popularity Vote Up Vote Down


Login to follow query

More posts by @Barnes591

2 Comments

Sorted by latest first Latest Oldest Best

 

@Bryan171

If you are looking for more control, you could do what I did. I use a sub-domain of personal domain that I own to point to myopenid. So if myopenid ever goes under, has problems, turns evil, etc, I can change providers without changing my openid url.

Edit: it is called OpenID Delegation

10% popularity Vote Up Vote Down


 

@Berumen354

This seems like overkill. There are a lot of sites offering OpenIDs. What aspects are you worried about? That the provider might themselves masquerade as you? That the provider might be hacked and have the user/password files copied and decrypted? If those are your anxieties and you want to relieve them by taking control, you can certainly go ahead. Your server is unlikely to be more secure than the best providers, but the obscurity of your server would likely make it less subject to hacking attempts.

10% popularity Vote Up Vote Down


Back to top | Use Dark Theme