« January 2008 | Main | March 2008 »

February 2008

February 26, 2008

OpenID and the need for Cardspace

Kim Cameron created a great illustration about OpenID and how the need for additional authentication will lead to Cardspace. I am in total agreement that OpenID needs a Cardspace type of authentication to reduce the Phishing thread. Take a look at Kim's presentation and pass this around as more folks need realize the need to combine secure authentication with OpenID.
...

Posted on Sunday 24 February 2008

Presents the relationship between OpenID and CardSpace
blog it

February 18, 2008

Cautious approach to OpenID

There has been a lot of discussion and acceptance of OpenID recently almost to the point of hype, however I am a little skeptical about OpenID and wanted to point out why. OpenID has been defined as a single sign-on service for your digital identity, and certainly has some of these capabilities, however I question how secure it is and will probably stay away from OpenID for now. At the same time I am really interested in the Identify space and the progress being made by the OpenID folks, so I thought I would outline OpenID, give some nice examples of where to find more information, and at the same time point out some of my security concerns with OpenID.

Here is Wikipedia's Definition of OpenID:

OpenID is a decentralized single sign-on system. Using OpenID-enabled sites, web users do not need to remember traditional authentication tokens such as username and password. Instead, they only need to be previously registered on a website with an OpenID "identity provider" (IdP). Since OpenID is decentralized, any website can employ OpenID software as a way for users to sign in; OpenID solves the problem without relying on any centralized website to confirm digital identity.

As most folks know, Yahoo has opened it's doors to OpenID, but has it really opened it's doors or just allowed it's users to take advantage of other OpenID sites. Either way, Yahoo does have a nice introduction and overview of OpenID for new users ....

Are you tired of creating a new account on every website you use? Do you avoid new websites because they come with yet another username and password? Do you paste stickies with password hints all over your computer monitor?

OpenID is an open technology standard that solves all of these problems. The OpenID technology will allow you to use your Yahoo! account to sign in to hundreds of websites! And this list is growing every day...

Once you enable your Yahoo! account for OpenID access, you can simply tell any OpenID enabled website that you are a Yahoo! user. You will be sent to Yahoo! to verify your Yahoo! ID and password and then signed in to the website. Its that easy!

So Still not convinced Take our handy-dandy OpenID tour to learn more or visit the OpenID homepage

So OpenID is really a URL based sign-on service which allow folks to login to sites that support OpenID, and there are many sites that support OpenID. However, OpenID is relying on your URL, HTTP and your Browser for security and therefore is open to phishing attacks and man-in-the-middle attacks. What is needed is another form of authentication like a smart card or the use of an SSL cert to ensure that your authentication is going to and returning from your OpenID provider and has not been compromised. A good example of this would be Trustbearer Labs. They are a OpenID Provider and increase security by expanding your credentials thru the use of USB devices, smart cards and biometric tokens that provide that extra level of security to ensure that your URL has not been compromised. This is a great option, however this could be too complicated for the majority of folks and who will continue to use OpenID as is.

Now, I want to assure you that the Security and Phishing problems associated with OpenID have been publicized, however with the growing adoption of OpenID, most of the information published in the last 3 to 6 months has been positive, focusing on adoption and not the security concerns. Here are a three posts that shed a different darker light on OpenID. The first is from Stefan Brands and the Identity Corner blog called The Problems with OpenID, Stefan points out the phishing problems and documents posts from others highlighting their concerns. The second post is from Scott Kveton who highlights the need for a third level of authentication like Info Cards and an Identify Manager in a post called OpenID and Phishing, and the third and most recent post is from Marshall Kirkpatrick from ReadWriteWeb called The Troubles with OpenID 2.0. Marshall questions the motives of the big players and points out that most of the big players allow their users to access other OpenID sites with their credentials, but do they allow other OpenID sites to access their applications with credentials from other OpenID sites? A good example of this is

Can a Yahoo user log into a Goggle Blogger account with their Yahoo credentials and visa versa ?

Now, after all this negative talk, I want to let you know that I am open and excited about OpenID, Identify Management and new forms of authentication. I do think that this is just the beginning for Identity and Authentication. We are on the road toward hardening and improving our authentication technologies and OpenID is just the start.

Technorati :
Del.icio.us :
Buzznet :

February 09, 2008

Technology and Management Topics

I know my posts have dropped off lately, however other factors from family to work and the Patriots have consumed my time in the last month. It is not for a lack of topics to write about as I have been digging into a couple of technologies, and pulling together thoughts on others. I have been reading a lot about OpenID and single sign-on and have a number of thoughts and strategies surrounding OpenID and it's impact both inside and outside the Enterprise. Cloud Computing is another technology that is starting to get some hype, and in many ways it may be useful to the Enterprise but not in the manner that is being talked about now.

I am also still very interested in Enterprise 2.0 and SOA from both a deployment perspective and a support perspective. And finally, Management. I am always looking to learn how I can improve as a manager and recently came across a new Management Blog that looks interesting. The blog is called Damn Good Manager and is worth checking out and contributing if so inclined.




Technorati :