Mmm, [http://www.openidenabled.com OpenID] looks interesting, just enabled it within drupal as an openid consumer (rather than the server component – which i’ve just gone and created myself a openID account at [http://www.myopenid.com MyOpenID]).
Had to alter some of the default drupal roles around so that authenticated users don’t get lots of access that I don’t want to give them, but still – very interesting.
Question is, can drupal easily be an openid server too (and why not?) – but then again, why would you need it with it being distributed…
Now if only other people would understand this is what the interweb is about – of course the following would need to be thought about:-
# Trust – do you trust the openID server provider?
# Security – can you spoof the authentication token of someone else?
# Spam – is there anything to stop bots from flooding you?