The document analyzes a single sign-on (SSO) mechanism proposed by Chang and Lee, demonstrating that it is insecure due to vulnerabilities like credential recovery and impersonation attacks. It highlights the failures in their security arguments, emphasizing the risks posed to both users and service providers. The paper proposes improvements to the scheme and refers to the necessity for formal studies on authentication soundness.