#singpolymaaaronpk: well, sort of. Any redirection-based protocol (including but not limited to, OpenID) makes it so that you *expect* to see a particular page when logging in to any website, so if any website can spoof your normal login page, they've got you