On the subject of online identity management and security, Tim Bray continues his ongoing Federation Conversation series with yesterday’s article on identity providers as a single point of failure.

I especially love this quote from Tim’s Google colleague, Eric Sachs:

If you’re typing a password into something, unless they have 100+ full-time engineers working on security and abuse and fraud, you should be nervous.

Read on for more from Tim Bray on hacking, software, and identity security.