> So, authenticate to your chosen IDP, and get assertions that you can
> hand off to any SP that recognizes your IDP.

How does one get a secure authentication with this IDP? How to signup?
What about strangers that you want offer a secure connection and yet be
able to recognize at later visits. That's why Eccentric uses DNSSEC and

> There are details of course... but it might be easier than developing
> an entirely new protocol that nobody yet supports.

The protocol solves problems that current protocol leave to the end
user: proper authenticating a site.

Quiz: who is the CA of your bank?

With regards, Guido Witmond.

